SSL Revoked Certificate Detection

Critical Nessus Network Monitor Plugin ID 5837

Synopsis

The remote host has been compromised and is running a 'Backdoor' program

Description

The remote SSL server is using a certificate which has been revoked. The particular SSL certificate has a serial number of '\xb0\xb7\x13\x3e\xd0\x96\xf9\xb5\x6f\xae\x91\xc8\x74\xbd\x3a\xc0' and an Issuer of USERTRUST.

Solution

There is a high probability that your server has been compromised. You should manually inspect and fix this system.

See Also

https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-browser-collusion

Plugin Details

Severity: Critical

ID: 5837

File Name: 5837.prm

Family: Backdoors

Published: 2011/03/23

Modified: 2016/01/15

Dependencies: 5620

Risk Information

Risk Factor: Critical