
{"id":502,"date":"2011-08-31T23:47:38","date_gmt":"2011-08-31T23:47:38","guid":{"rendered":"http:\/\/tech-no.104.210.61.21.xip.io\/?p=502"},"modified":"2011-09-01T17:55:05","modified_gmt":"2011-09-01T17:55:05","slug":"google-com-cert-posted-online-by-hackers-iran-possibly","status":"publish","type":"post","link":"https:\/\/tech-no.org\/?p=502","title":{"rendered":"*.google.com cert posted online by hackers! IRAN possibly?"},"content":{"rendered":"<p><a href=\"http:\/\/tech-no.104.210.61.21.xip.io\/wp-content\/uploads\/sites\/4\/2011\/08\/sad-droid.jpg\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-505\" title=\"sad droid\" src=\"http:\/\/tech-no.104.210.61.21.xip.io\/wp-content\/uploads\/sites\/4\/2011\/08\/sad-droid.jpg\" alt=\"\" width=\"207\" height=\"244\" srcset=\"https:\/\/tech-no.org\/wp-content\/uploads\/sites\/4\/2011\/08\/sad-droid.jpg 207w, https:\/\/tech-no.org\/wp-content\/uploads\/sites\/4\/2011\/08\/sad-droid-127x150.jpg 127w\" sizes=\"(max-width: 207px) 100vw, 207px\" \/><\/a><\/p>\n<p>see for yourself<\/p>\n<p><a title=\"http:\/\/pastebin.com\/ff7Yg663\" href=\"http:\/\/pastebin.com\/ff7Yg663\" target=\"_blank\">http:\/\/pastebin.com\/ff7Yg663<\/a><\/p>\n<p>also read here<\/p>\n<p><a title=\"http:\/\/pastebin.com\/SwCZqskV\" href=\"http:\/\/pastebin.com\/SwCZqskV\" target=\"_blank\">http:\/\/pastebin.com\/SwCZqskV<\/a><\/p>\n<p>If you are a mozilla Firefox user and wish to delete the cert, please see this post<\/p>\n<p><a title=\"http:\/\/support.mozilla.com\/en-US\/kb\/deleting-diginotar-ca-cert\" href=\"http:\/\/support.mozilla.com\/en-US\/kb\/deleting-diginotar-ca-cert\" target=\"_blank\">http:\/\/support.mozilla.com\/en-US\/kb\/deleting-diginotar-ca-cert<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>this is the first known thread that mentioned the posting.<\/p>\n<p><a title=\"http:\/\/www.google.co.uk\/support\/forum\/p\/gmail\/thread?tid=2da6158b094b225a&amp;hl=en\" href=\"http:\/\/www.google.co.uk\/support\/forum\/p\/gmail\/thread?tid=2da6158b094b225a&amp;hl=en\" target=\"_blank\">http:\/\/www.google.co.uk\/support\/forum\/p\/gmail\/thread?tid=2da6158b094b225a&amp;hl=en<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Microsoft also posted a prompt response<\/p>\n<h3>Microsoft Releases Security Advisory 2607712<\/h3>\n<p><a title=\"http:\/\/blogs.technet.com\/b\/msrc\/archive\/2011\/08\/29\/microsoft-releases-security-advisory-2607712.aspx\" href=\"http:\/\/blogs.technet.com\/b\/msrc\/archive\/2011\/08\/29\/microsoft-releases-security-advisory-2607712.aspx\" target=\"_blank\">http:\/\/blogs.technet.com\/b\/msrc\/archive\/2011\/08\/29\/microsoft-releases-security-advisory-2607712.aspx<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Google responded in the following statement<\/p>\n<blockquote><p>Today we received reports of attempted SSL man-in-the-middle (MITM) attacks against Google users, whereby someone tried to get between them and encrypted Google services. The people affected were primarily located in Iran. The attacker used a fraudulent SSL certificate issued by DigiNotar, a root certificate authority that should not issue certificates for Google (and has since revoked it).<\/p><\/blockquote>\n<p>obviously it goes without saying, this is huge&#8230; somehow i missed this with my hectic work schedule. if you are like me and use an andoid<\/p>\n<p>ok, so it looks like the CA, DigiNotar somehow issued this and others without permission from Google.<\/p>\n<h3><a href=\"http:\/\/securitywatch.pcmag.com\/apple\/287205-ssl-certificate-scandal-exposes-bug-in-mac-os-x\">SSL Certificate Scandal Exposes Bug in Mac OS X<\/a><\/h3>\n<p><a title=\"http:\/\/securitywatch.pcmag.com\/apple\/287205-ssl-certificate-scandal-exposes-bug-in-mac-os-x\" href=\"http:\/\/securitywatch.pcmag.com\/apple\/287205-ssl-certificate-scandal-exposes-bug-in-mac-os-x\" target=\"_blank\">http:\/\/securitywatch.pcmag.com\/apple\/287205-ssl-certificate-scandal-exposes-bug-in-mac-os-x<\/a><\/p>\n<blockquote><p>But you can configure your software to remove trust for particular certificates yourself. This is what user Seth Bromberger tried to do by removing trust of all DigiNotar certificates on his Mac using the Keychain software. Afterwards he tested by surfing to DigiNotar&#8217;s site and should have received warnings, but he didn&#8217;t.<\/p>\n<p>The problem turns out to be that if a site uses an EV-SSL (Extended Validation SSL) certificate, Keychain will ignore the fact that the user has marked it as untrusted.<\/p>\n<p>&nbsp;<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>see for yourself http:\/\/pastebin.com\/ff7Yg663 also read here http:\/\/pastebin.com\/SwCZqskV If you are a mozilla Firefox user and wish to delete the cert, please see this post http:\/\/support.mozilla.com\/en-US\/kb\/deleting-diginotar-ca-cert &nbsp; this is the first known thread that mentioned the posting. http:\/\/www.google.co.uk\/support\/forum\/p\/gmail\/thread?tid=2da6158b094b225a&amp;hl=en &nbsp; Microsoft also posted a prompt response Microsoft Releases Security Advisory 2607712 http:\/\/blogs.technet.com\/b\/msrc\/archive\/2011\/08\/29\/microsoft-releases-security-advisory-2607712.aspx &nbsp; Google responded in &hellip;<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[5],"tags":[],"_links":{"self":[{"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/posts\/502"}],"collection":[{"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/tech-no.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=502"}],"version-history":[{"count":4,"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/posts\/502\/revisions"}],"predecessor-version":[{"id":504,"href":"https:\/\/tech-no.org\/index.php?rest_route=\/wp\/v2\/posts\/502\/revisions\/504"}],"wp:attachment":[{"href":"https:\/\/tech-no.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=502"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tech-no.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=502"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tech-no.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=502"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}