Book Mark

Ike.ninja

Linux Fun
  • Home
  • How to
  • Reference Links
  • Categories
    • Releases
    • Plesk
    • Community
    • CMS
    • security
    • MYSQL
    • cPanel
  • Tools
    • IP Checker
    • Byte Converter
RSS

Ubuntu: 1542-1: PostgreSQL vulnerabilities

Aug23
by Ike on August 23, 2012 at 2:18 am
Posted In: Uncategorized

(Aug 20) PostgreSQL could allow unintended access to files over the network whenusing the XML2 extension.

 Comment 

Ubuntu: 1543-1: Config-IniFiles vulnerability

Aug23
by Ike on August 23, 2012 at 2:18 am
Posted In: Uncategorized

(Aug 20) Config-IniFiles could be made to overwrite arbitrary files.

 Comment 

Red Hat: 2012:1181-01: gimp: Moderate Advisory

Aug23
by Ike on August 23, 2012 at 2:18 am
Posted In: Uncategorized

(Aug 20) Updated gimp packages that fix multiple security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More…]

└ Tags: Red Hat, security, update
 Comment 

Red Hat: 2012:1174-01: kernel: Low Advisory

Aug23
by Ike on August 23, 2012 at 2:18 am
Posted In: Uncategorized

(Aug 21) Updated kernel packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low [More…]

└ Tags: Red Hat, security, update
 Comment 

Phishing on sites using SSL Certificates

Aug22
by Ike on August 22, 2012 at 2:50 pm
Posted In: security

Over the years the Internet community has been taught that one of the key steps in protecting their personal information on the Internet is to ensure that it is entered only over an encrypted connection, perhaps by looking for the lock symbol in the browser address bar or web addresses beginning with https://. As a result, phishing attacks which make use of SSL certificates are especially dangerous  as most users associate the presence of a valid SSL certificate with an increased level of assurance. Such attacks  erode the reputation of Certificate Authorities and SSL certificates, which makes identifying and revoking maliciously used certificates a material issue.

Netcraft’s anti-phishing feed has blocked over 5 million unique phishing sites to date, receiving over 4 reports a minute from our reporter community, and while the majority of phishing attacks run over HTTP,  a significant number run on sites for which SSL certificates have been issued. In July 2012 alone, Netcraft found 505 unique valid certificates on blocked sites.

The following table, produced for the Netcraft SSL Survey, shows the number of unique valid certificates returned by phishing sites that were blocked by Netcraft in July 2012:

Certificate Authority (CA) Unique certificates …with matching Common Names …and accessed by https://
Symantec 216 41 21
Comodo 130 16 7
Go Daddy 67 19 8
Other 41 11 6
GlobalSign 39 2 1
DigiCert 12 2 2

The columns of the table are ordered left to right by trustworthiness, as using a valid SSL certificate is not always enough to trick a user into trusting a phishing website and two further conditions have to be met:

  • The Subject Common Name of the certificate has to match the hostname of the phishing site that returned it. Some sites will return the hosting company’s certificate when requested over HTTPS. As most modern browsers display warnings when a non-matching certificate is encountered (pictured below), such certificates only serve to make the user more suspicious instead of increasing the perceived security of the site.
  • A phishing site accessed over HTTPS displays the SSL certificate for the hosting company.

  • The phishing attack has to actively use the SSL certificate by including https:// in the phishing URL. Having a valid SSL certificate does not make a phishing site appear more trustworthy if victims only access it over HTTP.

Fraudsters will often host their phishing content on a compromised website and so can make use of the website’s legitimate certificate, however they may not have realized that SSL services are available and so serve the content over HTTP. None of the certificates found on phishing sites in this period appeared to have been issued specifically for the purpose of phishing.

Taking Certificate Authority market shares into consideration, Go Daddy has a lower proportion of its SSL certificates used in phishing attacks than the other large CAs, in part because it provides the hosting for a large proportion of the certificates which they issue and is a long term user of Netcraft’s feed to remove phishing attacks.

└ Tags: security
 Comment 
  • Page 2,845 of 2,976
  • « First
  • «
  • 2,843
  • 2,844
  • 2,845
  • 2,846
  • 2,847
  • »
  • Last »

What’s New?

  • Fedora 43: Firefox Update 2025-f20b9f321d – Aarch64 Crashes Fixed
  • Chromium Medium Problems in Password Manager and Toolbar for Fedora 42
  • Debian: vlc Critical Denial of Service and Code Execution DSA-6082-1
  • Debian: Thunderbird Critical Arbitrary Code Exec DSA-6081-1 CVE-2025-14321
  • Fedora 41: Apptainer CVE-2025-65105 Security Fix Advisory
  • Fedora 43: Apptainer 1.4.5 Important Fix CVE-2025-65105
  • Ubuntu 18.04: USN-7907-5 Linux Kernel Important Security Flaws
  • Debian: Chromium Important DSA-6080-1 Code Exec DoS Issues
  • Fedora 42: SingularityCE Important Upgrade 4.3.5 – FEDORA-2025-54d78b9fed
  • Fedora 43: perl-Alien-Brotli Critical Security DoS Fix 2025-d93200cf16
  • Fedora 42: Wireshark 4.6.1 Critical Issue Advisory – FEDORA-2025-f810869906
  • Fedora 42: yarnpkg Command Injection Fix CVE-2025-64756 Advisory
  • Ubuntu 25.10: Linux Kernel Critical Flaws Security Patch USN-7906-3
  • Ubuntu 22.04: USN-7889-6 Linux Kernel Important Security Patch
  • Ubuntu 22.04 LTS: Linux Kernel Critical Security Issues USN-7928-3
  • Ubuntu 22.04: 7928-2 Linux Kernel FIPS Security Updates
  • Ubuntu 22.04 LTS: USN-7928-1 Linux Kernel Critical Security Issues
  • Significant Vulnerabilities in OpenStack Keystone on Ubuntu 22.04 LTS
  • Ubuntu 24.04 LTS: urllib3 Important DoS Vulnerabilities USN-7927-1
  • Debian: Important DoS Vulnerabilities in FFmpeg DSA-6080-1 Advisory
  • Ubuntu 20.04 LTS: USN-7922-1 Linux Kernel Important Security Issues
  • Ubuntu 24.04 LTS: Kernel Important Security Fixes USN-7921-1 CVE-2025-39946
  • Debian: firefox-esr Critical Privilege Escalation DSA-6078-1 CVE-2025-14321
  • 2026 Global Partner Program Announcement
  • Debian: pdns-recursor Critical Denial of Service Vulnerability DSA-6077-1

Search

Translator

Tags

Business and industry code Community cPanel CVE Debian Debian Linux Distribution - Security Advisories Development Events Fedora Fedora Linux Distribution - Security Advisories General Hosting Important Advisory Linux Moderate Advisory Month in WordPress news Parallels Plesk Parallels Plesk Panel Performance PHP Plesk news and announcements Plesk Panel Podcast ProdDevSec Product and technology Products Project Release News Red Hat Red Hat Linux Distribution - Security Advisories Releases security Security Centre sensitive site Ubuntu Ubuntu Linux Distribution - Security Advisories update updates Various vulnerability Web Server Survey Wordpress wp-briefing

Posts

Helpful Links

  • Liquidweb.com
  • MYSQL Dev Documentation
  • Plugins
  • Source forge SED command
  • Themes
  • WordPress Documentation
  • You Tube
December 2025
M T W T F S S
« Nov    
1234567
891011121314
15161718192021
22232425262728
293031  
  • Google
  • Yahoo
  • Liquid Web
  • Storm
  • YouTube

©1999-2025 Ike.ninja | Powered by WordPress with Easel | Subscribe: RSS | Back to Top ↑

50 queries. 8.5 mb Memory usage. 0.260 seconds.