Dutch SSL certificate provider Gemnet investigates website compromise

The website of Dutch SSL certificate provider Gemnet was taken offline after a hacker gained access to the server

By Lucian Constantin, IDG News Service |  Security Add a new comment

Gemnet, a Dutch company that provides SSL certificates for the Dutch government, has closed down its website after it was compromised by a hacker who found sensitive information on the server hosting it.

According to Webwereld, the hacker was able to break into gemnet.nl through a phpMyAdmin installation that wasn't password-protected. PhpMyAdmin is a popular software utility that facilitates the administration of MySQL databases through a Web interface.

The hacker took control of the server and accessed confidential information about the company's secure network, forcing KPN, the company that owns Gemnet, to temporarily shut down the website and launch an investigation.

KPN rejected the claims that its network has been put at risk because of this incident in a public statement and said that the hacker was only able to gain access to publicly available information.

The company also pointed out that Gemnet does not issue digital certificates. However, while this might be true, Gemnet CSP, a separate company controlled by KPN, does issue certificates for the Dutch government, and its website was also taken offline following the incident.

KPN did not immediately reply to a request for information about the decision to shut down gemnetcsp.nl as well. Before being taken offline, the website informed visitors that Gemnet CSP helps government and public sector organizations to increase the reliability of electronic data by providing certificates that can be used for authentication, identification, encryption and digital signing.

The Dutch government noticed the incident and launched an investigation to determine the nature of the compromise. Dutch Interior Ministry spokesman Vincent van Steen confirmed the existence of a probe, but declined to reveal any additional details pending its results.

This is not the first time that a company that provides digital certificates for the Dutch government has been compromised. In August Dutch certificate authority DigiNotar announced that a hacker broke into its network and issued fraudulent certificates for a number of high-profile domains, including Google and Hotmail.

Following the incident, the Dutch government revoked all DigiNotar certificates and the company's main CA certificate was blacklisted in browsers and OSes.

At the beginning of November, KPN temporarily suspended digital certificate issuing for another of its subsidiaries, Getronics, after the company found traces of a four-year-old compromise on one of its servers.

(With reporting by Brenno de Winter at Webwereld, an IDG Netherlands publication)

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question