All the latest UK technology news, reviews and analysis

Comodo Hacker posts fraudulent Mozilla SSL certificate online

by Phil Muncaster

29 Mar 2011

Be the first to comment

  • Tweet this

The self-styled 'Comodo Hacker' has revealed more information about the SSL certificate attack which emerged last week, and uploaded one of the certificates in question in an attempt to convince doubters that they carried out the original hack.

The theft of the nine SSL certficates actually occurred on 15 March but came to light last week when certificate authority Comodo revealed in a blog post that hackers had broken into an affiliate and requested nine SSL certficates for fake sites.

At least one of them was issued by Comodo before the attack was detected and terminated.

Although Comodo publicly argued that it suspected Iranian government involvement in the attack, a lone Iranian hacker calling themselves 'Comodo Hacker' then claimed responsibility.

Now the same hacker has posted the Mozilla add-on certificate and private key to the web, along with a scathing attack on those who still don't believe that the individual was solely responsible for the attack.

The hacker revealed that they had been studying encryption algorithms for six years, and claimed to be programming for AVR and ARM processors.

The Comodo Hacker also revealed that they installed a keylogger on the server of Comodo reseller InstantSSL.it in order to monitor administrator behaviour.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

36%

0%

10%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Flash Developer- actionscript, AJAX, JSON

Flash Developer- Actionscript 3.0, AJAX, JSON, computer...

Business Analyst, Risk platform, Equity Derivs, Investment Bank

Business Analyst - Risk platform - Equity Derivatives...

Java Developer - Algorithmic Trading - Global Trading Business

Java Developer - Algorithmic Trading - Global Trading...

Junior Treasury Project Manager, Tier One Investment Bank

Junior Middle Office Project Manager, Treasury, IB...

To send to more than one email address, simply separate each address with a comma.