Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Fixes and Improvements

July 4th, 2012, 08:55 GMT · By

20% of Global 2000 Firms Exposed to Flame-Style Malware Breaches, Venafi Finds

SHARE:

Adjust text size:

Certificate-signing algorithms used by companies
Enlarge picture
Enterprise key and certificate management solutions provider Venafi has performed an analysis of 450 of the companies present in the Forbes Global 2000 annual ranking. The results of the scans revealed that, on average, around 20% of these firms are susceptible to attacks that leverage malware such as Flame, Duqu or Stuxnet.

As the company’s CEO highlighted on numerous occasions, the poor management of digital security certificates makes many organizations a tempting target for cybercriminals.

The main problem is that many companies still rely on the outdated MD5 signing algorithm for the certificates they utilize to facilitate secure and trusted communications between their systems and human users.

Identifying vulnerable certificates is no easy task, but now, Venafi has released a free piece of software that can significantly reduce the time needed to perform this operation.

It’s called the Venafi MD5 Certificate Assessor and it allows firms to identify all the certificates deployed in a network and highlight the locations of those that are signed using MD5.

The tool also provides validity periods, encryption key details, and the name of the certificate authority responsible for issuing each certificate.

“The risks are no longer hypothetical. MD5 certificates were the open door that allowed Flame to penetrate networks and gather information. Microsoft closed their door by issuing a security patch,” said Jeff Hudson, the company’s CEO.

“Your door, however, remains wide open. Intrusion detection systems, firewalls, antivirus and other security measures do not address these open doors on your network. Organizations need to take specific action immediately to remove MD5."

Other experts, such as Eric Ogren, principal analyst with Ogren Group, agree that the risks are present and reinforce the need for applications such as the MD5 Certificate Assesor.

“Cybercriminals are exceptionally creative, financially organized, and highly motivated to steal confidential information. Organizations focused on reducing security risk need to do all they can to close as many open doors and to change as many locks as they can,” Ogren explained.

“Free tools such as this one being provided by Venafi to track down weak certificates could provide an advantage in staying a step ahead of the attackers,” he added.

Venafi MD5 Certificate Assessor is available for download here


2,374 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Expert on Flame: Microsoft Have Fixed Their Problem, Not “the Problem”

Flame Uses Cryptographic Collision Attack to Sign Code, Microsoft Says

Expert: Firms’ Inability to Fend Off MitM Attacks Allows Crooks to Steal Billions

Valid VeriSign Certificate Used to Sign Mediyes Malware

Softpedia Exclusive Interview: Venafi CEO on Cybercrime and Digital Certificates

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM