January 16, 2017 By Larry Loeb 2 min read

GoDaddy recently discovered that almost 9,000 SSL certificates that it has issued since July 29, 2016, had to be revoked and reissued. A code bug that occurred during a service upgrade caused this SSL certificate security problem.

In July, GoDaddy changed its validation code. This change unintentionally allowed certain servers that were configured in a particular way to bypass GoDaddy’s authentication process, which is necessary to deliver an SSL certificate.

SSL Certificate Security Incident Reported

Wayne Thayer, GoDaddy’s general manager of security products, declared in an incident report that the company had fixed the problem.

“We are currently unaware of any malicious exploitation of this bug to procure a certificate for a domain that was not authorized,” he wrote. “The customer who discovered the bug revoked the certificate they obtained and subsequent certificates issued as the result of requests used for testing by Microsoft and GoDaddy have been revoked. Further, any certificate requests made for domains we flag as high-risk were also subjected to manual review, rather than being issued purely based on an invalid domain authorization.”

SecurityWeek noted that GoDaddy has identified 8,951 certificates that were issued without the proper domain validation. That would be about 2 percent of the total number of certificates issued between July 29, 2016, and Jan. 10, 2017. GoDaddy reported that the incident affected approximately 6,100 customers.

CA Inconsistency

Discussion on the Google board after Thayer’s incident report was published revolved around possible underlying operational inconsistency among certificate authorities (CA).

“As you will know, the method being used by GoDaddy here corresponds broadly to method 3.2.2.4.6 from ballot 169 — “Agreed-Upon Change to Website,” one user wrote. “Although this method is not currently in the BaselineRequirements due to it being part of ballot 182 and having a related IPR disclosure, at least one root store operator has suggested they are going to require strict adherence to the methods listed in that ballot by March 1.”

In other words, the exact implementation of a baseline requirement by a CA may vary from one CA to another. This points to a need for standardized approaches.

More from

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today