Go Back   { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Software > Mozilla Software > FireFox

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-21-2008, 02:38 PM
FTR
 
Posts: n/a
Is this a phishing campaign ?

I got twice an email supposedly from CACERT with the heading
[CAcert.org] Your Certificate is about to expire

When I follow the link the error page says :
Secure Connection Failed
www.cacert.org uses an invalid security certificate.

This sounds bizarre.

Anyone here with an ideas whether this is a phishing attack ?

- ft



-------- Original Message --------
From: - Fri Jul 18 15:28:41 2008
X-Account-Key: account19
X-UIDL: 1216276959.4618.mrelay3-g25
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
X-Mozilla-Keys:
Return-Path: <returns@cacert.org>
Delivered-To: xxx@xxx.xx
Received: (qmail 4587 invoked from network); 17 Jul 2008 06:42:39 -0000
Received: from 193.238.157.112 (HELO hlin.cacert.org) (193.238.157.112)
by mrelay3-g25.free.fr with SMTP; 17 Jul 2008 06:42:39 -0000
Received: from hlin.cacert.org (localhost [127.0.0.1]) by
hlin.cacert.org (Postfix) with SMTP id C0D32B005D for
<frank.thomasftr@free.fr>; Thu, 17 Jul 2008 08:45:05 +0200 (CEST)
X-Mailer: CAcert.org Website
X-OriginatingIP:
Sender: returns@cacert.org
Errors-To: returns@cacert.org
Reply-To: support@cacert.org
From: support@cacert.org
To: xxx@xxx.xx
Subject: [CAcert.org] Your Certificate is about to expire
Mime-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
Message-Id: <20080717064505.C0D32B005D@hlin.cacert.org>
Date: Thu, 17 Jul 2008 08:45:05 +0200 (CEST)


Hi Frank,

You are receiving this email as you are the listed contact for:

/CN=xxx@xxx.xx/emailAddress=xxx@xxx.xx

Your certificate is set to expire in approximately 30 days time, you can
renew this by going to the following URL:

https://www.cacert.org/account.php?id=5

Best Regards
CAcert Support


Reply With Quote
  #2 (permalink)  
Old 07-21-2008, 03:45 PM
Melchert Fruitema
 
Posts: n/a
Re: Is this a phishing campaign ?

On 21-07-2008 16:38 CET, FTR composed this enchanting statement:
> I got twice an email supposedly from CACERT with the heading
> [CAcert.org] Your Certificate is about to expire
>
> When I follow the link the error page says :
> Secure Connection Failed
> www.cacert.org uses an invalid security certificate.
>
> This sounds bizarre.
>
> Anyone here with an ideas whether this is a phishing attack ?
>
> - ft
>
>
>
> -------- Original Message --------
> From: - Fri Jul 18 15:28:41 2008
> X-Account-Key: account19
> X-UIDL: 1216276959.4618.mrelay3-g25
> X-Mozilla-Status: 0001
> X-Mozilla-Status2: 00000000
> X-Mozilla-Keys:
> Return-Path: <returns@cacert.org>
> Delivered-To: xxx@xxx.xx
> Received: (qmail 4587 invoked from network); 17 Jul 2008 06:42:39
> -0000
> Received: from 193.238.157.112 (HELO hlin.cacert.org)
> (193.238.157.112) by mrelay3-g25.free.fr with SMTP; 17 Jul 2008
> 06:42:39 -0000
> Received: from hlin.cacert.org (localhost [127.0.0.1]) by
> hlin.cacert.org (Postfix) with SMTP id C0D32B005D for
> <frank.thomasftr@free.fr>; Thu, 17 Jul 2008 08:45:05 +0200 (CEST)
> X-Mailer: CAcert.org Website
> X-OriginatingIP:
> Sender: returns@cacert.org
> Errors-To: returns@cacert.org
> Reply-To: support@cacert.org
> From: support@cacert.org
> To: xxx@xxx.xx
> Subject: [CAcert.org] Your Certificate is about to expire
> Mime-Version: 1.0
> Content-Type: text/plain; charset="utf-8"
> Content-Transfer-Encoding: 8bit
> Message-Id: <20080717064505.C0D32B005D@hlin.cacert.org>
> Date: Thu, 17 Jul 2008 08:45:05 +0200 (CEST)
>
>
> Hi Frank,
>
> You are receiving this email as you are the listed contact for:
>
> /CN=xxx@xxx.xx/emailAddress=xxx@xxx.xx
>
> Your certificate is set to expire in approximately 30 days time, you
> can renew this by going to the following URL:
>
> https://www.cacert.org/account.php?id=5
>
> Best Regards
> CAcert Support
>

Have you installed the Root Certificate, yet?

--
Kind regards,
Melchert

(MacOS 10.3.9 / Firefox 2.0, Thunderbird 2.0)
Reply With Quote
  #3 (permalink)  
Old 07-21-2008, 07:06 PM
Moz Champion (Dan)
 
Posts: n/a
Re: Is this a phishing campaign ?

Melchert Fruitema wrote:
> On 21-07-2008 16:38 CET, FTR composed this enchanting statement:
>> I got twice an email supposedly from CACERT with the heading
>> [CAcert.org] Your Certificate is about to expire
>>
>> When I follow the link the error page says :
>> Secure Connection Failed
>> www.cacert.org uses an invalid security certificate.
>>
>> This sounds bizarre.
>>
>> Anyone here with an ideas whether this is a phishing attack ?
>>
>> - ft
>>
>>
>>


>>
>> Your certificate is set to expire in approximately 30 days time, you
>> can renew this by going to the following URL:
>>
>> https://www.cacert.org/account.php?id=5
>>
>> Best Regards
>> CAcert Support
>>

> Have you installed the Root Certificate, yet?
>



All I get at the link provided is

Secure Connection Failed



www.cacert.org uses an invalid security certificate.

The certificate is not trusted because the issuer certificate is unknown.

(Error code: sec_error_unknown_issuer)



* This could be a problem with the server's configuration, or it
could be someone trying to impersonate the server.

* If you have connected to this server successfully in the past,
the error may be temporary, and you can try again later.







Or you can add an exception…
Reply With Quote
  #4 (permalink)  
Old 07-22-2008, 07:42 AM
Matt Nordhoff
 
Posts: n/a
Re: Is this a phishing campaign ?

FTR wrote:
> I got twice an email supposedly from CACERT with the heading
> [CAcert.org] Your Certificate is about to expire
>
> When I follow the link the error page says :
> Secure Connection Failed
> www.cacert.org uses an invalid security certificate.
>
> This sounds bizarre.
>
> Anyone here with an ideas whether this is a phishing attack ?
>
> - ft


<snip the email>

Doesn't look like a phish to me. <https://www.cacert.org/> is CAcert's
website. The mail headers look authentic too. Unless they're trying to
phish themselves...

If you don't use CAcert yourself, someone else did using your email
address. You should bring this up with CAcert. (Or if you did use
CAcert, you should do something about your cert before it expires!)

Firefox doesn't include CAcert's root cert, so it will give you that
error. You can add an exception and/or add the root cert if you want to.
(Of course, someone might actually be impersonating www.cacert.org and
using an invalid cert.)

(Wow, how many times did I use "cert" in that message?)
--
Reply With Quote
  #5 (permalink)  
Old 07-23-2008, 06:36 AM
=?ISO-8859-1?B?u1Gr?=
 
Posts: n/a
Re: Is this a phishing campaign ?

On Mon, 21 Jul 2008 15:06:42 -0400
"Moz Champion (Dan)" <moz.champion@sympatico.ca> wrote:

> All I get at the link provided is
>
> Secure Connection Failed
>
>
>
> www.cacert.org uses an invalid security certificate.
>
> The certificate is not trusted because the issuer certificate is
> unknown.
>
> (Error code: sec_error_unknown_issuer)
>
>
>
> * This could be a problem with the server's configuration, or it
> could be someone trying to impersonate the server.
>
> * If you have connected to this server successfully in the past,
> the error may be temporary, and you can try again later.
>
>
>
>
>
>
>
> Or you can add an exception…


It's really horrible UI, as far as I'm concerned. To get any info
about the certificate, you have to

1) Click that Oor you can add an exception..." link at the bottom of the
warning page. Note that clicking that doesn't actually add the
exception, as anyone would think it would.

2) Click on the "Add Exception" button that appears after step (1).
Note that clicking the "Add Exception" button also does *not* add the
exception. Now we at least see where the certificate will come from.

3) Click the "Get Certificate" button. This button at least makes
sense, and results in the certificate being downloaded.

4) Now we can click "View" to see something about the certificate.

But note again we had to click *two* things that said "add exception"
before we got to step 4. That's very bad, IMO -- any user who
doesn't know what's going on would be scared to click them.

5) After viewing, we can choose to confirm the security exception
either temporarily or permanently.

Also note that if you do it permanently and later want to get delete
the security exception, you will waste your time if you try the
Security tab of Options/Preferences -- you can only do it from the
Advanced tab.
Reply With Quote
Reply

  { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Software > Mozilla Software > FireFox


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 01:54 PM.


Powered by vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
© 1999-2008 mindfrost82.com v11.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109