由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
Programming版 - godaddy的digital certificates竟然有问题!
相关主题
$1500的domain,我耽误两天,被一个老印买去了你们都是用什么工具来看网站用户统计数据 ?
借东风问一下:用JS可以cross domain接受SSL certificate吗?《黑客攻防技术宝典》(The Web Application Hacker's Handbook Finding and Exploiting Security Flaws)第二版[PDF]
aws的https不接受godaddy买的ssl,咋办?有谁在做drupal programming吗?
aws大幅度出故障原来是一个程序员输错了命令 (转载)为什么这年代还有大量用PHP的网站??
老程序员的日常 (转载)Azure, AWS这些云服务适合哪种规模的公司?
Obamacare website大家用哪个免费的网站,自己把code upload上去?
请教Node.js 应用的安全问题小网站加Blogging 功能
网页input问题请问有啥好的域名提供商?
相关话题的讨论汇总
话题: godaddy话题: thayer话题: domain话题: validation
进入Programming版参与讨论
1 (共1页)
c*********e
发帖数: 16335
1
Thousands of bogus certs issued after GoDaddy bug blunder
Flaw unnoticed since July last year.
Domain name registrar and hosting firm GoDaddy has been forced to revoke
thousands of digital certificates this week, after a bug allowed them to be
issued without proper validation.
GoDaddy senior internet product and technology leader Wayne Thayer wrote
that the company had been made aware of a flaw affecting its domain
validation processing system over last weekend.
The bug was introduced to GoDaddy's validation code back in July 30 last
year, meaning a large number of digital certificates were subsequently
issued without proper checks, Thayer admitted.
The bug was discovered by a Microsoft customer, who emailed GoDaddy about
the issue last weekend.
Thayer said the bug was caused by the validation process completing
succesfully even if the control check returned a HTTP 404 not found status
code, when looking for the presence of data on a web page that demonstrated
a customer controlled a domain.
Prior to the bug being introduced in July, the domain validation process
would only complete if it received a HTTP 200 (success) code.
In total, Thayer said, 8850 certificates were issued without proper domain
validation.
In the time it took for GoDaddy to investigate the bug, the number of
problematic certificates went up to 8951 as a further 101 certificates were
issued using cached and potentially unverified domain validation
inforrmation, Thayer said.
GoDaddy has started revoking the affected certificates. Thayer said GoDaddy
is not aware of "any malicious exploitation of this bug to procure a
certificate for a domain that was not authorised."
http://www.itnews.com.au/news/thousands-of-bogus-certs-issued-after-godaddy-bug-blunder-447178
1 (共1页)
进入Programming版参与讨论
相关主题
请问有啥好的域名提供商?老程序员的日常 (转载)
现在个人及小商户网站web hosting哪里比较好?Obamacare website
请教GoodBug等AWS重度用户请教Node.js 应用的安全问题
请问哪里注册域名比较好?网页input问题
$1500的domain,我耽误两天,被一个老印买去了你们都是用什么工具来看网站用户统计数据 ?
借东风问一下:用JS可以cross domain接受SSL certificate吗?《黑客攻防技术宝典》(The Web Application Hacker's Handbook Finding and Exploiting Security Flaws)第二版[PDF]
aws的https不接受godaddy买的ssl,咋办?有谁在做drupal programming吗?
aws大幅度出故障原来是一个程序员输错了命令 (转载)为什么这年代还有大量用PHP的网站??
相关话题的讨论汇总
话题: godaddy话题: thayer话题: domain话题: validation