Security experts from Qualys conducted a global scan of websites for valid SSL certificates . A total of 119 million domains were scanned, of which 92 million were active, then about 12.4 million refused to be recognized correctly, 14.6 million did not respond. Of the remaining 34 million responded to a request to ports 80 and 443. Further analysis showed that SSL was active on about 23 million sites.
What is most surprising, of these 23 million sites, only 3.17% of the SSL certificate corresponded to the domain name on which it was installed. Qualys presented the results of its research at the Black Hat USA hacker conference.