Re: Incidents involving the CA WoSign

2016-08-29 Thread 233sec Team
e details about where this certificate came from? Did you > issue it using one of the vulnerabilities discussed in this thread? > > > On Aug 26, 2016, at 01:12, 233sec Team wrote: > > > > Wosign's Issue mechanism is high risking for large enterprise. > > This is

Re: Incidents involving the CA WoSign

2016-08-26 Thread 233sec Team
Wosign's Issue mechanism is high risking for large enterprise. This is one prove: https://gist.github.com/xiaohuilam/8589f2dfaac435bae4bf8dfe0984f69e Alicdn.com is the cdn asset domain name of Taobao/tmall who belong to alibaba, which are Chinese biggest online shopping websites. With the fake c