Iran implicated in Microsoft and Google attacks
By Tom Brewster,
Iran has been implicated in attacks aimed at sites run by tech giants including Microsoft and Google.
Last week, hackers acquired fraudulent SSL certificates to potentially spoof popular services like Hotmail and Gmail, in order to trick web users into handing over valuable information.
The certificates fraudulently issued by root certificate authority Comodo were for popular sites including login.live.com, mail.google.com, www.google.com, login.skype.com and login.yahoo.com.
On 15 March, a total of nine digital certificates were issued by Comodo, after an attacker obtained the username and password of a trusted partner and registration authority based in Southern Europe.
All the fraudulent certificates have now been revoked, but users could have been duped into handing over information to the perpetrators.
According to Comodo’s report, attacks appear to have been limited, with only one yahoo.com certificate seen live on the web. Furthermore, Microsoft said in an advisory it had not seen any “active attacks.”
Microsoft warned, however, the certificates could have been used to “spoof content, perform phishing attacks, or perform man-in-the-middle attacks.”
All affected domain owners have been informed, as have relevant Government authorities.
The Iran link
Comodo linked Iran to the attacks, as founder Melih Abdulhayoglu suggested they were “state driven/funded.”
“The IP address of the initial attack was recorded and has been determined to be assigned to an ISP in Iran,” explained Dr Phillip Hallam-Baker, Comodo vice president and principal scientist, in a blog post.
“A web survey revealed one of the certificates deployed on another IP address assigned to an Iranian ISP. The server in question stopped responding to requests shortly after the certificate was revoked.”
However, the attackers may simply have tried to “lay a false trail,” Hallam-Baker said.
“It does not escape notice that the domains targeted would be of greatest use to a Government attempting surveillance of internet use by dissident groups,” he added.
“The attack comes at a time when many countries in North Africa and the Gulf region are facing popular protests and many commentators have identified the internet and in particular social networking sites as a major organising tool for the protests.”
As for businesses, they should ensure they have up-to-date certificate revocation data and appropriate browser settings, said Fraser Howard, principle threat researcher at Sophos.
“From a more long term perspective, let’s hope this incident makes industry players audit, not only their own security systems and policies, but those of their trusted partners as well to protect browsers in the future,” Howard added.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Public Sector Analysis & Insight
The Digital Economy Act: Is it doomed to never happen?
As a further delay hits part of the implementation of the Digital Economy Act, is this just a small hiccup, or is the Act being rendered toothless already? Simon Brew takes a look.
- Does the government want to snoop on your data?
- Q&A: Rajeeb Dey, CEO Enternships
- Government IT: Apples for the mandarins
- Striving to solve the security skills crisis
- 2011: The year in news
- Are the cookie laws crumbling already?
- UK rural broadband: too little, and too late
- How the Data Protection Act's death will punish the UK economy
- Education: glad to be a geek
Latest Public Sector Reviews
HTC Flyer review: First Look
- HP TouchPad review: First Look
- RIM BlackBerry PlayBook review - First Look
- MWC 2011: Acer Iconia A100 and A500 reviews – first look videos
- MWC 2011: HP TouchPad review - first look video
- MWC 2011: RIM BlackBerry PlayBook review - first look video
- MWC 2011: HP Pre3 review - first look video
- MWC 2011: Motorola Pro review - first look video
- MWC 2011: HTC Flyer tablet review - first look video
- MWC 2011: Samsung Galaxy Tab 10.1 review – first look video
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Public Sector
Q&A: David Elton, PA Consulting Group
CIOs are increasingly influential, but have to juggle "dual roles", study finds.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






PROFESSOR
If they cant act like sensible people, Simple thing to do is just to "turn off the internet in Iran"
By PROFESSOR on Thursday Mar 24