Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Security

August 30th, 2011, 13:11 GMT · By

Microsoft Protects IE Users Against Google Spoofing Attacks Abusing Rogue DigiNotar Certificate

SHARE:

Adjust text size:


Internet Explorer
Enlarge picture
Microsoft has removed a rogue SSL root certificate issued by DigiNotar from the list of trusted Windows root certificates in an effort designed to protect users of Internet Explorer from attacks impersonating Google online properties, including Gmail.

Dave Forstrom, director of Trustworthy Computing for Microsoft, informed that the software giant is only aware of a single fraudulent DigiNotar digital certificate so far, which is no longer featured on the Microsoft Certificate Trust List.

“DigiNotar has since revoked the digital certificate. This is not a Microsoft security vulnerability; however, the certificate potentially affects Internet users attempting to access websites belonging to Google,” Forstrom revealed.

While attacks leveraging the rogue SSL root certificate are not exploiting actual vulnerabilities, they still represent a security issue, since cybercriminals can abuse them in order to masquerade malicious websites as legitimate Google sites.

“A fraudulent certificate may be used to spoof Web content, perform phishing attacks or perform man-in-the-middle attacks against end users,” Forstrom explained.

All browsers are impacted by this problem to the same degree as IE. However, after the Redmond company excluded the fraudulent digital certificate issued by DigiNotar from the Microsoft Certificate Trust List, the browser will warn users that sites leveraging it are not safe.

“All supported editions of Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2 use the Microsoft Certificate Trust List to validate the trust of a certification authority,” Microsoft explained.

“Users of these operating systems will be presented with an invalid certificate error when they browse to a Web site or try to install programs signed by the DigiNotar root certificate. In those cases users should follow the instructions in the message. Microsoft will release a future update to address this issue for all supported editions of Windows XP and Windows Server 2003.”

TELL US WHAT YOU THINK:

2,370 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Windows 7 Update Lets IE9 Install Without Restarting the PC

Download Free Windows 7 SP1, Vista SP2 and XP SP3 Virtual Images

Internet Explorer Is 16 Years Old

“IE9 Offers the Best Protection against Socially Engineered Malware” - NSS Labs

IE9 Sites-Like-Apps Resources Internationalized, Available in 40 Markets

READER COMMENTS:


Comment #1 by: Sam on 30 Aug 2011, 15:25 UTC reply to this comment

XP is NOT in the list. XP users are NOT protected. This article is misleading.

Comment #1.1 by: mike on 31 Aug 2011, 18:49 GMT

Given the last two paragraphs (4 whole sentences), I can't think of any way that this article could be construed as misleading

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM