Lots Of Digitally-Signed Malware Out There
3 Nov
2017
3 Nov
'17
8:14 a.m.
One of the security weaknesses exploited by the “Stuxnet” worm that sabotaged Iran’s nuclear enrichment program was that it had a valid digital signature from a recognized issuer of certificates for Windows software. Of course, the issuer would never knowingly have validated a piece of malware, but the certificate had been compromised so it could be used without their permission.
Turns out this sort of thing is not only quite common, there is a further problem in that anti-malware software, which is supposed to pick up revoked certificates and reject signatures that use them, frequently has bugs in their implementation of the signature-checking protocol, so they can let these bad signatures through.
2443
Age (days ago)
2443
Last active (days ago)
0 comments
1 participants
participants (1)
-
Lawrence D'Oliveiro