Revoke a certificate in Windows that was used by hackers


Microsoft released updates to stop a fake Windows certificate, which could be used to create a man-in-the-middle assault on its live services.
security chain Windows

It all started in Finland, where hackers managed to gain access to a Microsoft admin account. Following the discovery of the hack, Comodo Certification Authority deleted the fake CERT, which it issued, and Redmond followed up with the update to revoke the certificate on their platforms. Windows.

The title of the update from Microsoft is: “Advisory Microsoft: Issued Incorrect Digital Certificate Could Enable Forgery”

“Microsoft is aware of the fake SSL certificate for the live.fi domain that could be used in phishing, or man-in-the-middle attacks” said The company.

"It can not be used for issuing new certificates, or for impersonating others , or for signing the code. ”

Microsoft said the malicious certificate was issued by a hacked privileged email account of Microsoft's live.fi service, which appears to be the Finnish version of its online services.

Someone managed to gain access to the privileged account via admin@live.fi, and immediately asked Comodo for a certificate.

The company urges all of them της να εφαρμόσουν τις αυτόματες ενημερώσεις. Οι χρήστες των can let the built-in updater perform the update, while those using Server 2008 and Windows 7 systems should install update 2917500.

For those who are interested can download the update from here.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).