| 

Microsoft revises its certificate management

  • Post author: Omid Farhang
  • Post published: June 14, 2012
  • Reading Time: 2 min
  • Word Count: 218 words

The H-Online: In response to the Flame worst-case scenario, Microsoft has now integrated a custom block list feature for its certificate store under Windows. The feature was deployed as part of this month’s Patch Tuesday. The Flame worm had spread via Windows Update feature by manipulating the certificates that were intended to protect Windows updates from tampering. As described in a Microsoft Security Response Center (MSRC) blog post, the latest modification automatically causes compromised certificates to be regarded as untrusted. To achieve this, the certificate store checks a Microsoft-maintained list on a daily basis for certificates that are no longer trustworthy. Certificate Authorities are required to inform the company of any revoked certificates, which will then be added to the list. According to a Windows PKI blog post, this method is considerably faster than the deployment of Certificate Revocation Lists (CRLs). ...

Continue Reading Microsoft revises its certificate management

Microsoft revokes certificates used to sign the Flame trojan

  • Post author: Omid Farhang
  • Post published: June 4, 2012
  • Reading Time: 1 min
  • Word Count: 114 words

Avira TechBlog Wrote: Microsoft released Security Advisory 2718704 which revokes some certificated which apparently were used to sign the trojan Flame__. In a blog post, Microsoft explains how they discovered that some components of the malware have been signed by certificates that allow software to appear as if it was produced by Microsoft. The certificates issued by the Terminal Services licensing certification authority, which are intended to only be used for license server verification, were also used to sign code and make it look like as if it was originated from Microsoft. ...

Continue Reading Microsoft revokes certificates used to sign the Flame trojan

Avira receives AV-Test.org certificate

  • Post author: Omid Farhang
  • Post published: April 27, 2011
  • Reading Time: 1 min
  • Word Count: 83 words

Avira TechBlog: Great news – our Avira Premium Security Suite received the next AV-Test.org certificate, this time for the first quarter of 2011! So far the suite thus achieved all available AV-Test.org certificates since the beginning of the certification process. The certificate approves the tested products a good quality in detection, repair and usability. This means that users of the Avira Premium Security Suite can be assured to be well protected from the threats they face when using their computers on the Internet! ...

Continue Reading Avira receives AV-Test.org certificate

Fake Certificate in Malware – with Message

  • Post author: Omid Farhang
  • Post published: April 11, 2011
  • Reading Time: 1 min
  • Word Count: 131 words

Avira TechBlog: The malware authors every now and then send us virus researchers some messages. For example in the compiled binary itself, or as debug output. Now we found a Zbot Trojan variant which tries to evade detection by carrying a digital certificate and therewith looking more legitimate. And this certificate is registered to “DetectMe! 🙂 ”, also adding random data behind the certificate. We see hints like these regularly – malware authors proposing names for their malicious creations or suggesting a place where a signature based detection would be suitable. Of course, such hints are ignored by us for detection but make us smile for a short time. ...

Continue Reading Fake Certificate in Malware – with Message