------ SUMMARY Vagabond has reported a problem in the Japanese version of VeriSign provided seals. The problem allows a malicious site owner to create an authenticity seal (false one) for his site without it being actually issued by VeriSign. DETAILS VeriSign's Seal displays parameters when it transfers them from the form to CGI script. At this point the company name and other information used in authentication, which is hidden in the form but displayed when the authentication process is complete, is transferred. Thus, the authentication window used by VeriSign's seal can be spoofed by preparing a page set with the hidden elements containing the information the attacker wants to spoof. For your reference, the HTML source code for the form portion is appended at the end of this message. Which VeriSign's are vulnerable? We cannot confirm the problem in VeriSign's other than VeriSign Japan. It also should be noted that VeriSign.com (US version) seems to use a different method of showing authenticity seals. Exploit: Appended below is the source code for the VeriSign form. Virtually all of the hidden information can be rewritten. All of the content rewritten onto VeriSign Japan's authentication window is clearly displayed. For example, "USO-DAPYON" in value ="USO-DAPYON" in the above string can be displayed by rewriting it to a different character string.
ADDITIONAL INFORMATION The information has been provided by