Comodohacker: I can issue fake Windows updates

Status
Not open for further replies.

win7holic

New Member
Thread author
Apr 20, 2011
2,079
Following his recent attack against Dutch security company DigiNotar, the hacker known as Comodohacker is now threatening to exploit Microsoft's Windows Update service.

In another message posted on Pastebin last week touting his cyberattacks, the infamous hacker claims that he's able to issue phony Windows updates despite Microsoft's assertion to the contrary.

read more
 

iPanik

New Member
Feb 28, 2011
530
that would be... interesting.
I am pretty sure i have gotten that certificate update, but i think i will double check just in case.
 

Linuxfever

New Member
Jan 11, 2011
131
Yes, he can exploit the Windows Update system and I can fly. :shy:
Microsoft said that Windows Update has the Microsoft root CA certificate hard-coded into it. If Windows Update finds out that the SSL certificate of update.microsoft.com is signed by any other CA (even legitimate ones like Thawte or others) other than Microsoft Internet Authority, it will fail. Plus, each of the Windows Update setup files are signed by Microsoft own certificate too, and if Windows Update encounters a update file signed by other legitimate CA that isn't Microsoft, the update will fail too.
The Comodohacker must have access to Microsoft private SSL keys (Microsoft Internet Authority) and also managed to hack into Microsoft servers to sign those Windows Update updates with the compromised certificate in order to deliver fake updates.
 

WinAndLinuxTutorials

Level 4
Verified
Honorary Member
Aug 23, 2011
2,291
Linuxfever said:
Yes, he can exploit the Windows Update system and I can fly. :shy:
Microsoft said that Windows Update has the Microsoft root CA certificate hard-coded into it. If Windows Update finds out that the SSL certificate of update.microsoft.com is signed by any other CA (even legitimate ones like Thawte or others) other than Microsoft Internet Authority, it will fail. Plus, each of the Windows Update setup files are signed by Microsoft own certificate too, and if Windows Update encounters a update file signed by other legitimate CA that isn't Microsoft, the update will fail too.
The Comodohacker must have access to Microsoft private SSL keys (Microsoft Internet Authority) and also managed to hack into Microsoft servers to sign those Windows Update updates with the compromised certificate in order to deliver fake updates.

I think you are right.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Good explanation, surely that hacker will make some plan B if the current plan will be fail.
 

moonshine

Level 7
Verified
Apr 19, 2011
1,264
This just the beginning of what hackers will bring in for the future, Those who aren't careful usually ends up screwed.
 

Jack

Administrator
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
+1 Linuxfever!

The message posted on Pastebin is not very new, in the same message this guys said that it has breached the certificate authority GlobalSign...long story short.....the guys from GlobalSign verified that claim and discovered it was FAKE.....so this guy has 0 credibility.
Most likely he is doing all this do divert the attention from the fact that someone was spying Iranian citizen with fake Gmail certificates.

Interesting read : http://news.softpedia.com/news/ComodoHacker-Denies-That-the-Iranian-Government-is-Funding-Him-221498.shtml
 

Malware1991

New Member
Sep 13, 2011
7
How would it be possible to know if the Updates are fake? (If he somehow manages to achieve what he says he can do?)
 
I

illumination

Malware1991 said:
How would it be possible to know if the Updates are fake? (If he somehow manages to achieve what he says he can do?)

If you manually install updates through microsoft, you will have no worries, as i highly doubt the intended hacker would manage to gain access through their update servers..
Otherwise, if he "could" manage to obtain Microsoft private SSL keys, the fake updates would mostly likely pop up as an automatic update that would seem to come out of no where.. He would have to be real slick, do this on the second tuesday of the month.. And he would have to construct the update to almost exact specs to fool most.. Would be a heck of a task, highly doubt he is capable, but one never knows..
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top