An SSL.com certificate authority has discovered a vulnerability in the domain ownership verification system that allowed obtaining a TLS certificate for any domain by providing the attacker's email. Access to the email with the target domain was sufficient to obtain the TLS certificate. For example, the vulnerability allowed obtaining a TLS certificate for domains used in public email services, such as gmail.com, yandex.ru, yahoo.com, outlook.com, and icloud.com.
The vulnerability also gave attackers the opportunity to carry out targeted attacks on employees of well-known companies and participants in major projects to gain access to their email and obtain TLS certificates for recognized domains. For example, hacking an employee of Google with the email name@google.com allowed obtaining a certificate for the domain google.com.
The vulnerability was caused by an error in the implementation of the domain ownership verification system via email confirmation. To obtain email confirmation, it is necessary to add a DNS TXT record "_validation-contactemail" in the DNS zone of the domain for which the certificate is requested. For example, "_validation-contactemail.test.com DNS TXT name@example.com". After initiating the domain verification, a confirmation code will be sent to the email name@example.com, entering which confirms ownership of the domain "test.com" and allows obtaining a TLS certificate for "test.com".
The essence of the vulnerability is that, in addition to the domain "test.com" for which the certificate was requested, the indication of ownership confirmation was also set for the domain "example.com", used in the email. The researcher who identified the problem demonstrated obtaining a working TLS certificate for the domain aliyun.com, used in the webmail service of the Chinese company Alibaba. During a test attack, the researcher registered a verification domain "d2b4eee07de5efcb8598f0586cbf2690.test.dcv-inspector.com" in the service "dcv-inspector.com" and requested a TLS certificate for it by adding the DNS record: _validation-contactemail.d2b4eee07de5efcb8598f0586cbf2690.test.dcv-inspector.com DNS TXT myusername@aliyun.com
After that, he requested a TLS certificate for the domain d2b4eee07de5efcb8598f0586cbf2690.test.dcv-inspector.com from SSL.com and selected email verification. The SSL.com certificate authority sent a verification code to myusername@aliyun.com, and upon entering this code, added not only 'd2b4eee07de5efcb8598f0586cbf2690.test.dcv-inspector.com' but also 'aliyun.com' to the list of verified domains. After that, the researcher successfully obtained a TLS certificate for the domain 'aliyun.com', ownership of which was confirmed.
The SSL.com certificate authority resolved the issue and identified 11 certificates that were issued using a vulnerable verification scheme with an external domain via email. Presumably, there are no signs of malicious activity in the identified cases, and out of the 11, only one certificate has been revoked so far, which was obtained by the researcher for the site aliyun.com. The other certificates included domains medinet.ca, help.gurusoft.com.sg, banners.betvictor.com, production-boomi.3day.com, kisales.com, and medc.kisales.com. SSL.com plans to publish an incident report by May 2.
Source: opennet.ru
