Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


nunz

1421 posts

Uber Geek
+1 received by user: 314
Inactive user


#238073 2-Jul-2018 12:03
Send private message

I got an expired cert message when logging in - *.io   Expired July 1. 

 

 


Create new topic
freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41029

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2047390 2-Jul-2018 12:05
Send private message

Sorry, no idea - *.io? Could you please be more precise?





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 




nunz

1421 posts

Uber Geek
+1 received by user: 314
Inactive user


  #2047394 2-Jul-2018 12:12
Send private message

freitasm:

 

Sorry, no idea - *.io? Could you please be more precise?

 

 

Eset popped up an invalid cert warning when logging on - ended in .io.    Expired 1 July. Looked like part of a chain from a CDN content provider or similar . 

 

 


UHD

UHD
655 posts

Ultimate Geek
+1 received by user: 298
Inactive user


  #2047862 2-Jul-2018 20:45
Send private message

I think freitasm might have been asking for the characters directly before the .io in order to chase this up.




freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41029

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2047863 2-Jul-2018 20:47
Send private message

I am thinking probably an external service as we do not directly use any .io domain.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Aredwood
3885 posts

Uber Geek
+1 received by user: 1749


  #2047942 3-Jul-2018 00:21

nunz:

I got an expired cert message when logging in - *.io   Expired July 1. 


 



Definitely investigate this. As I'm guessing that *.io would be a wildcard certificate for every website that happens to have a .io domain. Such a certificate will almost certainly be fraudulent.

This is a very big red flag that someone is trying or has successfully completed a MITM attack on your internet connection or browser.

Note that some corporate devices have self signed certificates to allow the company to monitor what employees do online, including on secure websites.





nunz

1421 posts

Uber Geek
+1 received by user: 314
Inactive user


  #2051084 7-Jul-2018 13:30
Send private message

Aredwood:
nunz:

 

I got an expired cert message when logging in - *.io   Expired July 1. 

 

 

 

 

 



Definitely investigate this. As I'm guessing that *.io would be a wildcard certificate for every website that happens to have a .io domain. Such a certificate will almost certainly be fraudulent.

This is a very big red flag that someone is trying or has successfully completed a MITM attack on your internet connection or browser.

Note that some corporate devices have self signed certificates to allow the company to monitor what employees do online, including on secure websites.

 

 

 

I've run tests on all systems and my firewall  / outer system is pretty much invisible / closed.

 

browser passes all av checks from three AVs as well as malware etc checks.

 

It is bog standard firefox with almost all addins turned off / deleted.

 

It felt like a CDN message  - something from an advert or third party part of the page


 
 
 

Want to support Geekzone and browse the site without the ads? Subscribe to Geekzone now (monthly, annual and lifetime options).
hio77
'That VDSL Cat'
13036 posts

Uber Geek
+1 received by user: 3896

ID Verified
Trusted
Lizard Networks
Subscriber

  #2051086 7-Jul-2018 13:36
Send private message

my .io domains are fine?.. 

 

 

 

Sounds like a MITM attack imo, maybe just a poorly setup network with transparent injection?





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have. 


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.