BugTraq
Privacy leak in VeriSign's SiteFinder service Sep 23 2003 09:04PM
Richard M. Smith (rms computerbytesman com) (2 replies)
GoDaddy vs Verisign Sep 25 2003 02:32AM
Scott Buchanan (scott buchanan axegroup com au)
Privacy leak in VeriSign's SiteFinder service #2 Sep 24 2003 06:00PM
Mark Coleman (markc uniontown com) (3 replies)
Re: Privacy leak in VeriSign's SiteFinder service #2 Sep 24 2003 07:45PM
der Mouse (mouse Rodents Montreal QC CA) (1 replies)
Re: Privacy leak in VeriSign's SiteFinder service #2 Sep 24 2003 08:58PM
Jay D. Dyson (jdyson treachery net)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, 24 Sep 2003, der Mouse wrote:

> > Bad, verisign. Very bad.
>
> Well, yes, but we knew _that_ from the day the wildcard went in.

The concerns expressed thus far are just the canonical tip of the
iceberg, considering the services running on sitefinder-idn.verisign.com.

PORT STATE SERVICE
23/tcp filtered telnet
25/tcp open smtp
79/tcp filtered finger
80/tcp open http
161/tcp filtered snmp
162/tcp filtered snmptrap
514/tcp filtered shell

Imagine how much fun one could have if, say, port 23 was suddenly
unfiltered; or if port 22 were opened; or if Verisign got really tricky
and opened up port 443 with a specially-crafted "wildcard" SSL certificate
implementation (maybe a stretch...but Verisign *is* a CA, no?).

The system as it presently functions is already ripe for abuse.
There is no question of that. But imagine the quantity and quality of
abuse that will occur when (not if) the system residing on 64.94.110.11
gets 0wn3d by someone who answers to no-one.

I think now would be a good time to null route all traffic to and
from 64.94.110.0/24 until Verisign grows a conscience and terminates this
abomination.

- -Jay

( ( _______
)) )) .-"There's always time for a good cup of coffee"-. >====<--.
C|~~|C|~~| (>----- Jay D. Dyson -- jdyson (at) treachery (dot) net [email concealed] -----<) | = |-'
`--' `--' `- Life is hard. Even harder if you're stupid. -' `------'

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (TreacherOS)
Comment: See http://www.treachery.net/~jdyson/ for current keys.

iD8DBQE/cgV7Nlg1oZSC9mkRAitrAJsGajN4leAI350REufRCA7AgvI2jwCeIo9y
wpYr5kYx7nRhngA0+YVU2pU=
=/Qvq
-----END PGP SIGNATURE-----

[ reply ]
Re: Privacy leak in VeriSign's SiteFinder service #2 Sep 24 2003 07:26PM
Hugo van der Kooij (hvdkooij vanderkooij org)
Re: Privacy leak in VeriSign's SiteFinder service #2 Sep 24 2003 07:00PM
Marco Ivaldi (raptor 0xdeadbeef info) (2 replies)
Re: Privacy leak in VeriSign's SiteFinder service #2 Sep 25 2003 09:37AM
Henning Rust (Henning Rust stud uni-hannover de) (1 replies)
Re: Privacy leak in VeriSign's SiteFinder service #2 Sep 25 2003 03:21PM
Niels Bakker (niels=bugtraq bakker net)
Re: Privacy leak in VeriSign's SiteFinder service #2 Sep 24 2003 08:05PM
Diego Bitencourt Contezini (diego redesul net)


 

Privacy Statement
Copyright 2010, SecurityFocus