lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Mon, 18 Apr 2011 19:09:31 +0900
From: アドリアンヘンドリック
	<unixfreaxjp22@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: MSA-2524375 fraudulent digital certification
	updates on Windows Phone

Is there anyone know the further update information regarding to fraudulent
digital certificates for Windows Phone a.k.a Windows Mobile? Anyone know the
microsoft's timeline for the update schedule? Or, any plans??
AFAIK Windows Mobile is still vulnerable to the fraudulent digital
certificates. Or please mock me and proof me wrong.

----
best regards,
Hendrik ADRIAN
http://0day.jp
株式会社ケイエルジェイテック

2011/3/26 アドリアンヘンドリック <unixfreaxjp22@...il.com>

> Followingly I read article in the below url:
>
> http://www.winrumors.com/microsoft-working-on-new-windows-phone-7-update-to-patch-fraudulent-ssl-certificates/
>
> which quoted Microsoft statement as per below:
> “Fraudulent digital certificates are not a Microsoft security
> vulnerability” explained Microsoft Trustworthy Computing manager Bruce
> Cowper. “We have been working to develop a mitigation update for Windows
> Phones,” added Cowper. Microsoft has not provided a specific time-line for
> the update saying it will provide “additional guidance as it comes
> available.”
>
> Which means that,
> 1. the smartphone updates for fraudulent digital certification is not
> included in the MSA-2524375.
> 2. Microsoft agreed that until the update released smartphone platform/
> windows phone browser still have the fraudulent digital certificates
> problem.
>
> ----
> best regards,
> Hendrik ADRIAN
> http://0day.jp
>
> 2011/3/25 アドリアンヘンドリック <unixfreaxjp22@...il.com>
>
>> Please help to advise the clarification of the MSA-2524375 updates, it may
>> related to the zeroday.
>> Regarding to the fraudulent digital certification on March 23rd, 2011
>> Microsoft was releasing Microsoft Security Advisory 2524375 as per below
>> url:
>> http://www.microsoft.com/technet/security/advisory/2524375.mspx
>>
>> which describing "..An update is available for all supported versions of
>> Windows to help address this issue.."
>> I was reviewing the updates described my Micorosoft is the below url:
>> http://support.microsoft.com/kb/2524375
>>
>> ..and found that Windows Phone a.k.a Windows Mobile wasn't included into
>> the updates. Does it mean that Microsoft stated that smartphone browser is
>> not affected by the fraudulent digital certification? Please kindly explain
>> if I was wrong.
>> ----
>> best regards,
>> Hendrik ADRIAN
>> http://0day.jp
>
>
>

Content of type "text/html" skipped

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ