Hacker Exploits SSL.com Domain Validation to Illegitimately Obtain Certificate for Alibaba Cloud Domain

A critical bug in SSL.com’s domain validation system has led to the unauthorized issuance of digital certificates for several high-profile domains, including Alibaba Cloud’s aliyun.com.

The flaw, uncovered by a security researcher known as “Sec Reporter,” allowed attackers to trick the certificate authority into granting them certificates for domains they did not control, raising serious concerns about the integrity of internet security.

How the Exploit Worked

According to Mozilla’s report, SSL.com’s domain validation process is designed to confirm that the requester controls a domain before issuing a TLS certificate, which secures encrypted web traffic.

One validation option involves adding a special DNS TXT record to the domain, specifying a contact email address. SSL.com would then send a verification code to that email; entering the code would confirm control over the domain.

However, due to a faulty implementation, SSL.com’s system mistakenly treated the domain portion of the contact email address as a verified domain.

For example, if an applicant used myusername@aliyun.com As the contact email for a random domain, SSL.com would incorrectly consider them authorized to request certificates for aliyun.com itself.

Step-by-Step Attack

Sec Reporter demonstrated the exploit in five steps:

  • Start a test on a domain validation tool.
  • Add a TXT record for the test domain with a contact email at aliyun.com.
  • Request a certificate for the test domain, selecting the aliyun.com email as the approver.
  • Retrieve the validation code sent to the aliyun.com email and complete the process.
  • SSL.com would then add aliyun.com to the list of verified domains, allowing the attacker to request certificates for aliyun.com and www.aliyun.com, without being an administrator or having any legitimate control over Alibaba Cloud’s domain.

Wider Impact and Response

The vulnerability was not limited to Alibaba Cloud. SSL.com has since revoked 11 certificates that were wrongly issued through this mechanism, including those for:

  • *.medinet.ca (Canadian healthcare software)
  • help.gurusoft.com.sg (Singapore tech support)
  • banners.betvictor.com (BetVictor gambling site)
  • production-boomi.3day.com (window blinds manufacturer)
  • kisales.com and medc.kisales.com (multiple times)

SSL.com’s technical compliance officer confirmed the flaw and stated that the affected domain control validation (DCV) method has been disabled pending a full fix.

The company has pledged to release a detailed incident report by May.

Security Implications

This incident underscores the risks inherent in automated domain validation systems, especially when bugs allow attackers to bypass intended controls.

Fraudulently obtained certificates can be used for phishing, man-in-the-middle attacks, and other malicious activities, putting users and organizations at risk.

SSL.com has thanked the researcher for responsibly disclosing the issue and is treating the incident with high priority.

As of now, there is no public evidence that the flaw was exploited for criminal purposes, but the potential for abuse was significant.

The episode highlights the ongoing challenges in securing the web’s trust infrastructure and the need for constant vigilance and robust validation mechanisms by certificate authorities.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories