Hello. I visited https://ssl.aukro.ua/fnd/authentication/ (online auction, ukrainian “ebay”) a few hours ago and web browser (all default: without addons, themes etc.) said: ssl.aukro.ua uses an invalid security certificate, the certificate is only valid for search.dnsadvantage.com (and it expired on 19.05.2014).
I checked the Windows DNS-preferences, and there was “188.8.131.52” and “184.108.40.206” (Comodo DNS-servers) here. I know that there was autoDNS from my internet-provider here (one month ago). I am sure that I didn
t install adware with CIS installation and upgrades (such as PrivDog etc.) and I unchecked all unnecessary options. I changed DNS-preferences to autoDNS from my internet-provider, reboot and checked my PC with 4 antivirus BootCD (todays). The system was clean. And now the certificate of the https://ssl.aukro.ua/fnd/authentication/ is valid. I created virtual Windows and changed its DNS-servers to “220.127.116.11” and “18.104.22.168”. There was the same invalid security certificate on the https://ssl.aukro.ua/fnd/authentication/ . Then I changed DNS-preferences to autoDNS and the certificate became valid. I also changed the DNS-servers to “22.214.171.124” and “126.96.36.199” (OpenDNS) and the security certificate was valid.
What is it? MITM from ComodoDNS?
[attachment deleted by admin]
Then with 188.8.131.52" and "184.108.40.206 in the DNS-preferences I added the invalid security certificate to trust certificates and page redirected me to “securedns.comodo.com” witn the inscription “Unsafe Website Blocked”. I googled about ComodoDNS, found ( Free Comodo Secure DNS | Best DNS Security Solution 2022 ) 2 another IP: 220.127.116.11 and 18.104.22.168. After that I changed DNS-preferences to these IP, and security certificate was valid without any warnings. Incidentally ownership of these IP: 22.214.171.124 - Peak 10, Inc. ( http://bgp.he.net/ip/126.96.36.199 ) and 188.8.131.52 - Elvate, LLC ( http://bgp.he.net/ip/184.108.40.206 ) and it
s strange. I googled about "220.127.116.11" and "18.104.22.168": now these IP belong to NeuStar, Inc. ( http://bgp.he.net/ip/22.214.171.124 ) but I dont know that these IP belonged NeuStar, Inc. in the past or not. And “search.dnsadvantage.com” (from invalid certificate) belongs to NeuStar, Inc. too. But there are many mentions about “126.96.36.199” and “188.8.131.52” as ComodoDNS IP in the internet. Perhaps ComodoDNS used these IP in the past but now don
t do it, and it try to work in defined bad way (Secure by friendly MitM, yeah). And I dont know how it happened (“184.108.40.206” and “220.127.116.11” in my DNS-prefernces), because as default CIS don`t install its SecureDNS and I was very attentive by the installation and upgrades (and I install exactly CIS 8, not previous versions). Maybe it was a bug, a strange vile bug, though that is no excuse for MitM from SecureDNS.