Feeds

Claimed DigiNotar hacker: I have access to four more CAs

Iranian 'Comodohacker' says he can still issue bogus certs

Intelligent flash storage arrays

The digital miscreant known as ComodoHacker has claimed responsibility for the high-profile DigiNotar digital certificate authority hack.

Soon after the Comodo forged certificates hack an Iranian using the handle Comodohacker posted a series of messages via Pastebin account providing evidence that he carried out the attack. The account, which has been dormant since March, sprung back to life on Tuesday with claims that the individual or individuals behind it hacked DigiNotar as well, net security firm F-Secure reports.

The hacker boasted he still has access to four other (unnamed) "high-profile" CAs and retains the ability to issue new rogue certificates, including code signing certificates. The hacker (active on Twitter under the username ichsunx2) claimed that the domain administrator password of the DigiNotar network was Pr0d@dm1n.

Compromises against both Comodo affiliates and DigiNotar allowed hackers to generate bogus SSL certificates. The certificates create a means to mount convincing man-in-the-middle or phishing attacks. Evidence suggests that a rogue certificate issued in July under the name of Google as the result of the DigiNotar hack was used to spy on Iranian internet users.

The still-unfolding DigiNotar saga further underlines the fragility in the net's foundation of trust first highlighted by the Comodo hack. ®

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.