EDITION:GLOBALNORTH AMERICACENTRAL & SOUTH AMERICAUK & IRELANDEUROPEMIDDLE EAST & AFRICAAUSTRALIA & NEW ZEALANDASIA
LANGUAGES:

Welcome
to ContactCenterWorld.com

Raj Wadhwani
President

President of Contact Center World
Wednesday, May 23, 2012
Learn the best practices in the industry from those who 'do the job' every day - click on Top Performers Conferences under conferences and events
OVER 129,000 MEMBERS

The Global Association for Contact Center Best Practices & Networking


Site Map
About this Site
Contact Us


 
 Pulse Survey

Global Benchmarking Study Promo

FEATURED SUPPLIERS
on ContactCenterWorld.com this week:

Global Benchmarking Study of Top Performers







Click on the company name for more details!


View:Folder:
Read:Page:
Order:Asc/Des:
To:CC:
Reply:Forward:
SearchP1:BCC:
Stack:
Error:
Stolen Government Certificate Signed Malware is an Upcoming Trend

According to a report by F-Secure, the certificate was used to sign a piece of malware which has been spread through malicious PDF files, dropped after an Acrobat Reader 8 exploit had taken place.

Tal Be’ery, Web Security Researcher at Imperva comments "Once more we are seeing an example of the growing trend in the theft of issued certificates by cyber-criminals. This time, F-Secure published an analysis of a widespread malware strain which used a stolen certificate belonging to the Malaysian Agricultural Research and Development. By using the stolen certificate, the malware appears to the operating system as a legitimate application and thus evades detection.

We can expect to see more stories of stolen certificates in the upcoming year, as hackers have come to understand that the weakest link in SSL is the Public Key Infrastructure (PKI). PKI deals with all aspects of digital certificates – and hackers are launching a brutal attack against it.

Attackers have compromised repeatedly various Certificate Authorities (CA) organizations this year including DigiNotar and GlobalSign. This is a direct consequence of the commoditization of certificates as smaller; less competent organizations are taking larger pieces of the certificate market. At the same time, any CA can issue a digital certificate for any application not having to receive consent from application owner. When hackers gain control on any CA they can use it to issue fraudulent certificates and masquerade any website.

The same is true for code signing certificates - Stealing the organization's code signing certificate is like stealing its rubber stamp. A stolen rubber stamp enables the attacker to sign on cheques and fill in an arbitrary amount and beneficiary. The bank will trust the cheque since it's signed. A stolen code signing certificate enables the attacker to sign on whatever code they like. The browser will trust the downloaded code since it is properly signed. Therefore, code signing certificate is, and will continue to be, a prime target for malware distributers."

 


Related Groups
Computer Hardware / Software
CRM
Performance
Quality
Security
Technology

Related News
Imperva Introduces Data Security for Microsoft SharePoint
Imperva Enhances Dynamic Profiling For Its Web Application Firewall
Imperva Expands File Protection with Broad Data Loss Prevention Integrations
Imperva Introduces Cloud-based Web Application Firewall Service
Imperva Bolsters File Protection with Agent Technology
Imperva Warns On The Real Insider Security Threat

About Imperva:
Imperva, a Data Security company, enables a complete security lifecycle for business databases and the applications that use them. Over 4,500 of the world’s leading enterprises, government organizations, and managed service providers rely on Imperva to prevent sensitive data theft, protect against data breaches, secure applications, and ensure data confidentiality. The award-winning Imperva SecureSphere is the only solution that delivers full activity monitoring from the database to the accountable application user and is recognized for its overall ease of management and deployment.

More Editorial from Imperva
Imperva Enhances Dynamic Profiling For Its Web Application Firewall
Imperva Deconstructs Local and Remote File Inclusion Attack Vectors
Imperva Analyzes High-Profile ‘Anonymous’ Attack
Imperva Finds Business Logic Attacks Attractive To Hackers
Imperva Introduces Data Security for Microsoft SharePoint
Imperva Welcomes Two New Board Members

Date Published: Thursday, November 24, 2011
Printer Friendly Version Printer friendly version
 Recommend to a friend
 Bookmark & Share



Post Message

Post Message






 

 

 





-Back To Top-

| Request Information from CRM & Contact Center Suppliers | About ContactCenterWorld |
| Advertise CRM & Contact Center Solutions | Link to this site |
| Submit CRM and Contact Center Content | Contact Us | Privacy Policy |
| Recommend this site to other CRM & Contact Center Professionals | Disclaimer |

©ContactCenterWorld.com 1999-2011
The Global Support Organization For Contact Center Professionals & the place for information on:
Quality Monitoring, Recruitment, Self Service, Speech Recognition, Telemarketing, Virtual Contact Center, VoIP, Web Chat, Work at Home, Workforce Management