Advertisement
ComodoHacker

A message from Comodo Hacker

Mar 26th, 2011
200,981
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.50 KB | None | 0 0
  1. Hello
  2.  
  3. I'm writing this to all the world, so you'll know more about us..
  4.  
  5. At first I want to give some points, so you'll be sure I'm the hacker:
  6.  
  7. I hacked Comodo from InstantSSL.it, their CEO's e-mail address mfpenco@mfpenco.com
  8. Their Comodo username/password was: user: gtadmin password: globaltrust
  9. Their DB name was: globaltrust and instantsslcms
  10.  
  11. Enough said, huh? Yes, enough said, someone who should know already knows...
  12.  
  13. Anyway, at first I should mention we have no relation to Iranian Cyber Army, we don't change DNSes, we
  14.  
  15. just hack and own.
  16.  
  17. I see Comodo CEO and other wrote that it was a managed attack, it was a planned attack, a group of
  18.  
  19. cyber criminals did it, etc.
  20.  
  21. Let me explain:
  22.  
  23. a) I'm not a group, I'm single hacker with experience of 1000 hacker, I'm single programmer with
  24.  
  25. experience of 1000 programmer, I'm single planner/project manager with experience of 1000 project
  26.  
  27. managers, so you are right, it's managed by 1000 hackers, but it was only I with experience of 1000
  28.  
  29. hackers.
  30.  
  31. b) It was not really a managed hack. At first I decided to hack RSA algorithm, I did too much
  32.  
  33. investigation on SSL protocol, tried to find an algorithm for factoring integer, for now I was not
  34.  
  35. able to do so, at least not yet, but I know it's not impossible and I'll prove it, anyway... I saw
  36.  
  37. that there is easier ways of doing it, like hacking a CA. I was looking to hack some CAs like Thawthe,
  38.  
  39. Verisign, Comodo, etc. I found some small vulnerabilities in their servers, but it wasn't enough to
  40.  
  41. gain access to server to sign my CSRs. During my search about InstantSSL of Comodo, I found
  42.  
  43. InstantSSL.it which was doing same thing under control of Comodo.
  44. After a little try, easily I got FULL access on the server, after a little investigation on their
  45.  
  46. server, I found out that TrustDll.dll takes care of signing. It was coded in C#.
  47.  
  48. Simply I decompiled it and I found username/password of their GeoTrust and Comodo reseller account.
  49.  
  50. GeoTrust reseller URL was not working, it was in ADTP.cs. Then I found out their Comodo account works
  51.  
  52. and Comodo URL is active. I logged into Comodo account and I saw I have right of signing using APIs. I
  53.  
  54. had no idea of APIs and how it works. I wrote a code in C# for signing my CSRs using POST request to
  55.  
  56. APIs, I learned their APIs so FAST and their TrustDLL.DLL was too old and was sending too little
  57.  
  58. parameters, it wasn't enough for signing a CSR. As I said, I rewrote the code for !AutoApplySSL and !
  59.  
  60. PickUpSSL APIs, first API returns OrderID of placed Order and second API returns entire signed
  61.  
  62. certificate if you pass OrderID from previous call. I learned all these stuff, re-wrote the code and
  63.  
  64. generated CSR for those sites all in about 10-15 minutes. I wasn't ready for these type of APIs, these
  65.  
  66. type of CSR generation, API calling, etc. But I did it very very fast.
  67.  
  68. Anyway, I know you are really shocked about my knowledge, my skill, my speed, my expertise, that's all
  69.  
  70. OK, all of it was so easy for me, I did more important things I can't talk about, so if you have to
  71.  
  72. worry, you can worry... I should mention my age is 21
  73.  
  74. Let's back to reason of posting this message.
  75.  
  76. I'm telling this to the world, so listen carefully:
  77.  
  78. When USA and Israel write Stuxnet, nobody talks about it, nobody gots blamed, nothing happened at all,
  79.  
  80. so when I sign certificates nothing happens, I say that, when I sign certificates nothing should
  81.  
  82. happen. It's a simple deal.
  83.  
  84. When USA and Isarel could read my emails in Yahoo, Hotmail, Skype, Gmail, etc. without any simple
  85.  
  86. little problem, when they can spy using Echelon, I can do anything I can. It's a simple rule. You do,
  87.  
  88. I do, that's all. You stop, I stop. It's rule #1 (My Rules as I rule to internet, you should know it
  89.  
  90. already...)
  91.  
  92. Rule#2: So why all the world got worried, internet shocked and all writers write about it, but nobody
  93.  
  94. writes about Stuxnet anymore? Nobody writes about HAARP, nobody writes about Echelon... So nobody
  95.  
  96. should write about SSL certificates.
  97.  
  98. Rule#3: Anyone inside Iran with problems, from fake green movement to all MKO members and two faced
  99.  
  100. terrorist, should afraid of me personally. I won't let anyone inside Iran, harm people of Iran, harm
  101.  
  102. my country's Nuclear Scientists, harm my Leader (which nobody can), harm my President, as I live, you
  103.  
  104. won't be able to do so. as I live, you don't have privacy in internet, you don't have security in
  105.  
  106. digital world, just wait and see...
  107.  
  108. Rule#4: Comodo and other CAs in the world: Never think you are safe, never think you can rule the
  109.  
  110. internet, rule the world with a 256 digit number which nobody can find it's 2 prime factors, I'll show
  111.  
  112. you how someone in my age can rule the digital world.
  113.  
  114. Rule#5: To microsoft, mozilla and chrome who updated their softwares as soon as instructions came from
  115.  
  116. CIA. You are my targets too. Why Stuxnet's Printer vulnerability patched after 2 years? Because it was
  117.  
  118. need in Stuxnet? So you'll learn sometimes you have to close your eyes on some stuff in internet,
  119.  
  120. you'll learn... You'll learn... I'll bring equality in internet. My orders will equal to CIA orders,
  121.  
  122. lol ;)
  123.  
  124. Rule#6: I'm a GHOST
  125.  
  126. Rule#7: I'm unstoppable, so afraid if you should afraid, worry if you should worry.
  127.  
  128. A message in Persian: Janam Fadaye Rahbar
  129.  
  130.  
  131.  
  132.  
  133.  
  134. [Proof Of Hack 1]: http://pastebin.com/DBDqm6Km
  135. [Proof of Hack 2]: http://pastebin.com/X8znzPWH
  136. [UPDATE 1]: http://pastebin.com/CvGXyfiJ
  137. [UPDATE 2]: http://pastebin.com/kkPzzGKW (response to all comments)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement