Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-08-2014, 06:47 PM   #1
adultmobile
No, I am not banned
 
adultmobile's Avatar
 
Industry Role:
Join Date: Nov 2003
Location: ChatGF.com
Posts: 5,345
Heartbleed openssl bug (private keys at risk)

Heartbleed openssl bug (private keys at risk)

http://heartbleed.com/
http://arstechnica.com/security/2014...eavesdropping/
http://threatpost.com/seriousness-of...sets-in/105309

OpenSSL is default for apache and nginc, 66% of web sites.

"A missing bounds check allows an attacker to read up to 64 KB of memory on a machine protected by OpenSSL."

"Leaked secret keys allows the attacker to decrypt any past and future traffic to the protected services and to impersonate the service at will. Recovery from this leak requires patching the vulnerability, revocation of the compromised keys and reissuing and redistributing new keys. Even doing all this will still leave any traffic intercepted by the attacker in the past still vulnerable to decryption."

Test your server:

http://filippo.io/Heartbleed/
__________________

TubeCamGirl.com

Last edited by adultmobile; 04-08-2014 at 06:52 PM..
adultmobile is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-08-2014, 08:24 PM   #2
Seth Manson
Please dont fuck animals
 
Seth Manson's Avatar
 
Industry Role:
Join Date: Jul 2010
Location: Henderson, NV
Posts: 3,988
fucking god dammit
Seth Manson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-08-2014, 08:29 PM   #3
ErectMedia
Confirmed Chicago Pimp
 
ErectMedia's Avatar
 
Industry Role:
Join Date: Aug 2004
Location: Chicago
Posts: 7,100
patched this/rebooted a few hours ago
ErectMedia is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-09-2014, 03:09 AM   #4
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
jesus what a bug, how the fuck they just found it now
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-09-2014, 05:02 AM   #5
Barry-xlovecam
It's 42
 
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
Problem is, you cannot fix the past problem of a few years by patching.

Change your critical passwords (banking especially, financial services, (internet wallets?)).

If you think about places where your credit card numbers are shown in plain text (including PDF downloads -- credit card statements, etc.) that are password protected -- we may, MAY, be in for a shit storm.

Whatever damage has been done has already been done -- mitigate your future exposure ...
Barry-xlovecam is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-09-2014, 05:34 AM   #6
polipie
Confirmed User
 
polipie's Avatar
 
Industry Role:
Join Date: Jun 2012
Location: Belgium
Posts: 81
Webmasters can test their site here: filippo.io
__________________
TrafficMansion.com
polipie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-09-2014, 08:45 AM   #7
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Quote:
Originally Posted by adultmobile View Post
Even doing all this will still leave any traffic intercepted by the attacker in the past still vulnerable to decryption."
The NSA must be falling all over themselves to try to find as many vulnerable servers as possible so they can finally decipher that mystery encrypted data they've been capturing all this time.

... assuming they only found out about it 2 days ago, like the rest of us, rather than 2 years ago when the bug first appeared in the source code...
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-09-2014, 07:58 PM   #8
adultmobile
No, I am not banned
 
adultmobile's Avatar
 
Industry Role:
Join Date: Nov 2003
Location: ChatGF.com
Posts: 5,345
Quote:
Originally Posted by rowan View Post
The NSA must be falling all over themselves to try to find as many vulnerable servers as possible so they can finally decipher that mystery encrypted data they've been capturing all this time.

... assuming they only found out about it 2 days ago, like the rest of us, rather than 2 years ago when the bug first appeared in the source code...
It could well be that NSA knew the exploit since a year and it is upset that it was found and patched.
__________________

TubeCamGirl.com
adultmobile is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-09-2014, 08:26 PM   #9
noshit
Confirmed User
 
noshit's Avatar
 
Industry Role:
Join Date: Dec 2001
Location: Midwest USA
Posts: 1,582
Quote:
Originally Posted by seeandsee View Post
jesus what a bug, how the fuck they just found it now
That's easy... company that found the bug has connections to Google, Obama, DHS, and FBI. Funny how a company with those ties found a bug that seems to beg for government intervention
noshit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-09-2014, 09:01 PM   #10
anexsia
Confirmed User
 
anexsia's Avatar
 
Industry Role:
Join Date: May 2010
Posts: 5,735
already updated my servers
anexsia is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.