ALL >> Computers >> View Article
Certification Authority Alerts Users On Fraudulent Ssl Certificates
Recently, Comodo Group, Inc., one of the leading certification authorities warned against nine fraudulent Secure Sockets Layer (SSL) certificates issued by a Registration Authority. The registration authority reportedly suffered a security breach incident, which led to the disclosure of a user account. The compromised user account was used by the attacker to create new authentication credentials, placing and receiving order for certifications. The fraudulent certificates affect login.live.com, mail.google.com, google.com, login.yahoo.com (3 fraudulent certificates), login.skype.com, addons.mozilla.org and global trustee.
Cybercriminals could use sophisticated techniques to lure users to visit websites using fraudulent certificates. As the sites appear legitimate to the users, they may enter the authentication details on the website, which could be extracted by the attackers. The fraudulent certificates could also be used to trick users to download files containing malware on their computer systems. The malware could be designed to extract confidential personal or business information. Attackers could use the fake certificates ...
... to spoof content or launch phishing attacks. Cyber education is crucial to combat growing security threats. Training sessions, seminars, online degree and e-learning programs could help in enlightening employees on Internet security issues and improve the IT security practices in organizations.
Computer forensics experts are investigating the case and the registration authority has been suspended pending investigation. The fraudulent certificates have been revoked. The certification authority has reported to the respective government authorities, browser vendors and domain owners regarding the issue of fraudulent SSL certificates.
Security breaches could be prevented by evaluating the IT infrastructure at frequent intervals through IT professionals qualified in penetration testing, security audit, masters of security science to identify and mitigate security flaws.
United States Computer Emergency Readiness Team (US-CERT) has also cautioned users against the fraudulent certificates Major browser vendors have updated their browsers to identify and block the fraudulent certificates. Mozilla has updated Firefox 3.5, 3.6 and 4.0 to block these certificates. Microsoft has released updates for Windows to address the issue. Internet users must install and regularly update anti-virus software in their computer systems. Regular adherence to security advisories and updates from developers would also help in preventing malicious attacks. Distance learning and online university degree programs could enable IT professionals to update their skill sets to combat the growing IT security threats. IT administrators must keep track of the software updates and patch releases to secure the organizational networks and computer systems from intrusions and unauthorized access.
Add Comment
Computers Articles
1. Cpd Accredited Typing Certificate Uk - Speed Test & Online CertificationAuthor: Kowser
2. Safe Connection With Mickey Mouse Cables- An Ultimate Guide
Author: Jennifer Truong
3. Develop A Widget For Ios App
Author: goodcoders
4. Develop An App From Scratch In 13 Steps
Author: goodcoders
5. The Best Antivirus Software For 2025
Author: Jasbeer SIngh
6. How To Develop An App From Scratch In 13 Steps
Author: goodcoders
7. 7 Steps To Create A Safe Mobile App
Author: goodcoders
8. Why Do Businesses Need Vendor Management Software?
Author: Kiran
9. React Native App Development By Alvi Software
Author: Alvi Software
10. Custome
Author: Owner
11. Few Good Insights To Follow With Pc Gaming In Australia!
Author: Jack Williams
12. Transform Your Online Store With Australia's Leading Ecommerce Developers
Author: themerchantbuddy
13. How To Choose The Right Technology For Your mobile App?
Author: goodcoders
14. The Rise Of User Centered Web Design
Author: goodcoders
15. Reasons Why Laravel Perfect For Web Development?
Author: goodcoders