Technology Sectors

Market Sectors

Authentication firm compromised by alleged Iranian hackers

Melih Abdulhayoglu

A company that issues certificates used by web browsers to assure the authenticity of Internet sites was breached by what it believes to be Iranian hackers.

Comodo revealed the breach March 23, although the actual infraction took place on March 15.

According to an incident report posted at the company's website, a Registration Authority based in Southern Europe had one of its accounts breached. Registration Authorities, or RAs, are like subcontractors with whom a Certificate Authority, like Comodo, allow to issue certificates in its behalf.

After compromising the RA account, the attackers issued nine fraudulent certificates. All the certificates were revoked shortly after the discovery of the breach, the report said. Only one was actually seen "live" on the Internet. When its creator tried to use the certificate, it received a "revoked" response.

No other RAs were compromised, the report noted. Neither was Comodo's CA infrastructure nor its "root" keys violated.

Several IP addresses were used in the attack, but the primary one was located in Iran.

"The attacker was well prepared and knew in advance what he was to try to achieve.," the report explained. "He seemed to have a list of targets that he knew he wanted to obtain certificates for, was able quickly to generate the CSRs for these certificates and submit the orders to our system so that the certificates would be produced and made available to him."

Although an Iranian address was used in the attack and also used when an attempt was made to use the live certificate, those addresses could have been used as proxies for hackers elsewhere. However, other evidence points to a state-sponsored attack from that Middle Eastern nation, according to Comodo CEO Melih Abdulhayoglu.

For example, the domains for the certificates did not include any financial websites, which would be a tipoff that the attackers had criminal intentions. "I don't see a Citibank, for example," Abdulhayoglu told Government Security News. "I see purely communication-related domains, like email communication or Skype-like communication."

"It was a clinical execution," he said. "We did not see any telltale signs of cyber criminals in this."

Moreover, Iran is the sole nation where root keys aren't embedded into browsers. Root keys are provided by Certificate Authorities to browser makers who embed them into their software. Once the browser recognizes a root key as trusted, any digital certificate issued by the root key's CA will automatically be trusted as authentic.

"What they [the attackers] are trying to do is read people's emails," Abdulhayoglu asserted.

To do that, though, a digital certificate alone is inadequate, he explained. "You also have to have access to the DNS infrastructure so you can redirect people's traffic to a fraudulent website," he said.

"Getting a certificate is meaningless," he maintained. "The attacker must have had access to the DNS infrastructure. That points to a state-based attack."

 

Upcoming Events

Event Details Dates of Event
SANS Austin 2013 May 19 - 24
DoD VA Healthcare Training Forum May 20 - 23
Transport and Logistics of Hazardous Material May 27 - 28
Southwest Microwave Seminar May 28 - 28
Border Management Southwest Summit May 29 - 31
Cyber Security Conference & Expo May 30 - 30
Mobile Device Security Summit 2013 May 30 - Jun 6
Security Analytics Summit 2013 May 30 - Jun 6
Cyber Security Conference & Expo May 30 - 30
Southwest Microwave Seminar May 30 - 30
SANS Malaysia @ MCMC 2013 Jun 3 - 8
2013 SIA Government Summit Jun 4 - 5
Southwest Microwave Seminar Jun 4 - 4
NCT: CBRNe Israel, 4 - 6 June 2013, Tel Aviv Jun 4 - 6
SEL Modern Solutions Power Systems Conference Jun 5 - 7
Mission Command Jun 10 - 12
Cyber Securty Brainstorm Jun 11 - 11
EDGE Summit 2013 Jun 11 - 11
IPv6 Summit 2013 Jun 14 - 16
SANSFIRE 2013 Jun 15 - 22
Oak Ridge National Laboratory's 2nd Biosurveillance Symposium Jun 17
Biodetection Technologies 2013 Jun 18 - 19
Southwest Microwave Seminar Jun 18 - 18
Cyber Defense and Network Security Summit Jun 24 - 26
Vanguard Security & Compliance 2013 Jun 24 - 27
SANS Canberra 2013 Jul 1 - 13
Border Management & Technologies Summit Jul 2 - 5
SANS Rocky Mountain 2013 Jul 15 - 20
SANS Mumbai 2013 Jul 22 - 27
SANS San Francisco 2013 Jul 29 - Aug 3
SANS Boston 2013 Aug 5 - 10
Cyber Security for Government Aug 12 - 14
SANS Thailand 2013 Aug 19 - 31
SANS Virginia Beach 2013 Aug 19 - 30
Maritime Security 2013 West Aug 19 - 21
930gov: Strategic Buying at Year-End Showcase Aug 21 - 21