Re: Is This Digital Signature To Be Trusted?
It has been known that as a cryptographic tool, MD5 has been broken for some time, and that it as better for people to use SHA. It is interesting to note, to those who know about certificates, that MD5 has been used to create hash collisions (i.e. two files having the same checksum). This has allowed false intermediary root certificates to be issued by unscrupulous individuals.
When making these changes to the binaries, even if the digest hash is SHA512, will Windows warn that the file has been invalidated? While I beg the question as to how much damage could be done by 200 bytes of additional data, it looks like you have identified a serious flaw in digital file signing.
And again, you were actually able to modify 4 bytes of the digital signature itself and add 200 bytes of additional data at the end of the binary? But only if it was signed with MD5? Fortunately, it looks like most installer executables are being signed with SHA1 and MD5 has been abandoned by most programmers right now.
Sincerely, Mike Fara Microsoft MVP Windows 8 Forums
Operating System Windows 8 Pro x64
Internet Explorer Version 10.0.9200.16384
DirectX Version 11
Computer Type Gigabyte GA-X58A-UD7 v1
CPU Type and Speed Intel Core i7 Extreme 975, 3500 MHz (26 x 135)
CPU Cooling CoolerMaster Hyper 212 Plus RR-B10-212P-G1
CPU Idle Temp 43c
CPU Load Temp 60c
Motherboard Chipset Gigabyte Intel X58 + ICH10R GA-X58A-UD7
System BIOS Revision F7
System Memory Type 24GB G Skill F3-12800CL9-4GBRL
System Memory Speed DDR3-1333 (667MHz)
System Memory Clocking 8-8-8-22
Video Card Type and Speed SAPPHIRE 100315L Radeon HD 6850 1GB 256-bit GDDR5
Video Card Cooling Standard
Video Card Temperature 54c
Power Supply Unit (PSU) Rosewill BRONZE Series RBR1000-M 1000W
Computer Monitor Dell 2007WFP 20" LCD
Sound Card Realtek ALC889 @ Intel 82801JB ICH10
Speakers Logitech 2.1
Headset/Microphone Sony MDR-V600/Yeti Mic
Storage Controller Intel IICH10R 3400 Series SATA RAID
Hard Drive x6 CRUCIAL_CT128M225
Optical Drives Portable USB DVD-RW
Keyboard and Mouse MS Keyboard / Logitech G500 Mouse
Modem-Router Type Cisco-Linksys WRT610N
Network Adapter x2 Realtek PCIe GBE Family Controller
Printer Canon MX850
Network Speed 1GBit Internet / LAN
USB Controller Intel 82801JB ICH10
Gaming Console PS3, XBox
Anti-virus Software ESET Smart Security
Productivity Suite Microsoft Office 2010
System Install Date 8/18/2012
Computer Skill Level Certified Professional
Windows Experience Index 7.7
Favorite Game Skyrim
Favorite Application Skype