Erik van Straten<p>Let's Encrypt</p><p>In <a href="https://infosec.exchange/@aral@mastodon.ar.al/114224524044750719" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@aral@mastodo</span><span class="invisible">n.ar.al/114224524044750719</span></a> <span class="h-card" translate="no"><a href="https://mastodon.ar.al/@aral" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>aral</span></a></span> wants us to pay taxes to keep Let's Encrypt "alive". Here's another reason NOT to do that.</p><p>Apparently the *.eu.org domain needed laundrying because it's reputation became too bad. So scammers create zillions of insane domain names and obtain *FREE* (for them) certificates for those sites. Usually such sites are not malicious; they're intended to have virusscanners remove detection, eventually for the sub-TLD ".eu.org".</p><p>To see this, you may consider opening<br> <a href="https://crt.sh?q=eu.org" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">crt.sh?q=eu.org</span><span class="invisible"></span></a><br>but that will fail because there are WAY too many results.</p><p>To restrict the amount of records, try a subdomain name and further restrict output by deduplicating and restricting to not expired, as follows:</p><p> <a href="https://crt.sh/?Identity=madaline.eu.org&exclude=expired&deduplicate=Y" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">crt.sh/?Identity=madaline.eu.o</span><span class="invisible">rg&exclude=expired&deduplicate=Y</span></a></p><p>The screenshot below gives an idea (they're all Let's Encrypt certs by the way, and I marked one with an insane domain name).</p><p>I wrote about this phenomenon before, e.g. in <a href="https://www.security.nl/posting/781057/Let%27s+Encrypt+git_git_git___" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">security.nl/posting/781057/Let</span><span class="invisible">%27s+Encrypt+git_git_git___</span></a> (at the time I did not understand why yet).</p><p>VirusTotal knows of 72.5K direct subdomains of *.eu.org:</p><p> "Subdomains (72.5 K)"</p><p>(open the RELATIONS tab in <a href="https://www.virustotal.com/gui/domain/eu.org/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">virustotal.com/gui/domain/eu.o</span><span class="invisible">rg/</span></a>).</p><p><span class="h-card" translate="no"><a href="https://mstdn.social/@TheDutchChief" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>TheDutchChief</span></a></span> <span class="h-card" translate="no"><a href="https://ec.social-network.europa.eu/@EUCommission" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>EUCommission</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@letsencrypt" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>letsencrypt</span></a></span> <span class="h-card" translate="no"><a href="https://social.nlnet.nl/@nlnet" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nlnet</span></a></span> </p><p><a href="https://infosec.exchange/tags/DV" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DV</span></a> <a href="https://infosec.exchange/tags/DVcerts" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DVcerts</span></a> <a href="https://infosec.exchange/tags/LetsEncrypt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LetsEncrypt</span></a></p>