Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

PrivDog Releases Update After Being Compared to Superfish

The developers of PrivDog released an update for the application on Monday after researchers discovered that it failed to validate SSL certificates.

The developers of PrivDog released an update for the application on Monday after researchers discovered that it failed to validate SSL certificates.

PrivDog is designed to make surfing the Web safe and private by blocking processes that track users’ activities and by replacing ads with ones that have been vetted by AdTrustMedia. It’s not uncommon for advertising-related apps to put users at risk, but this shouldn’t be the case with PrivDog since the software is backed by Comodo, the renowned security firm and certificate authority. PrivDog is not only promoted by the company, but it’s also bundled with Comodo solutions.

The existence of the security issue came to light just days after the world learned that Lenovo had preloaded an insecure browser add-on from Superfish on new laptops. The Superfish app used a local proxy and a self-signed root certificate to intercept traffic and inject ads into webpages.

The problem, as highlighted by security experts, was that the program broke HTTPS browsing and exposed users to man-in-the-middle (MitM) attacks because all of the certificates had been signed with the same private key protected by the same weak password.

After a detailed analysis, researchers discovered that the vulnerability had been caused by libraries developed by Komodia. These libraries have been used in at least a dozen other applications and even malware.

PrivDog doesn’t use the libraries from Komodia, but a different third party component which, according to experts, is just as problematic. Because it doesn’t validate SSL certificates, the application exposes users to HTTPS spoofing attacks.

“The MITM capabilities are provided by NetFilterSDK.com. Although the root CA certificate is generated at install time, resulting in a different certificate for each installation, Privdog does not use the SSL certificate validation capabilities that the NetFilter SDK provides. This means that web browsers will not display any warnings when a spoofed or MITM-proxied HTTPS website is visited,” the CERT Coordination Center at Carnegie Mellon University explained in an advisory.

In an advisory published on Monday, PrivDog noted that the issue affects versions 3.0.96.0 and 3.0.97.0, but it does not impact the plugin distributed with Comodo Browsers. The company highlighted that while the flaw caused browsers not to trigger warnings for self-signed certificates, it did not break encryption.

Advertisement. Scroll to continue reading.

The updated version of PrivDog can be downloaded from the official website, but it is also distributed automatically, the company said.

According to PrivDog, the vulnerability impacts up to 57,568 users, roughly 6,000 of which are located in the United States.

CloudFlare’s Filippo Valsorda has updated his Superfish testing tool to allow users to check if they are running vulnerable versions of PrivDog.

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.