Heartbleed openssl bug (private keys at risk)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • adultmobile
    No, I am not banned
    • Nov 2003
    • 5345

    #1

    Heartbleed openssl bug (private keys at risk)

    Heartbleed openssl bug (private keys at risk)

    http://heartbleed.com/
    http://arstechnica.com/security/2014...eavesdropping/
    http://threatpost.com/seriousness-of...sets-in/105309

    OpenSSL is default for apache and nginc, 66% of web sites.

    "A missing bounds check allows an attacker to read up to 64 KB of memory on a machine protected by OpenSSL."

    "Leaked secret keys allows the attacker to decrypt any past and future traffic to the protected services and to impersonate the service at will. Recovery from this leak requires patching the vulnerability, revocation of the compromised keys and reissuing and redistributing new keys. Even doing all this will still leave any traffic intercepted by the attacker in the past still vulnerable to decryption."

    Test your server:

    http://filippo.io/Heartbleed/
    Last edited by adultmobile; 04-08-2014, 05:52 PM.

    TubeCamGirl.com
  • Seth Manson
    Please dont fuck animals
    • Jul 2010
    • 3988

    #2
    fucking god dammit

    Comment

    • ErectMedia
      Confirmed Chicago Pimp
      • Aug 2004
      • 7100

      #3
      patched this/rebooted a few hours ago

      Comment

      • seeandsee
        Check SIG!
        • Mar 2006
        • 50945

        #4
        jesus what a bug, how the fuck they just found it now
        BUY MY SIG - 50$/Year

        Contact here

        Comment

        • Barry-xlovecam
          It's 42
          • Jun 2010
          • 18083

          #5
          Problem is, you cannot fix the past problem of a few years by patching.

          Change your critical passwords (banking especially, financial services, (internet wallets?)).

          If you think about places where your credit card numbers are shown in plain text (including PDF downloads -- credit card statements, etc.) that are password protected -- we may, MAY, be in for a shit storm.

          Whatever damage has been done has already been done -- mitigate your future exposure ...

          Comment

          • polipie
            Confirmed User
            • Jun 2012
            • 81

            #6
            Webmasters can test their site here: filippo.io
            TrafficMansion.com

            Comment

            • rowan
              Too lazy to set a custom title
              • Mar 2002
              • 17393

              #7
              Originally posted by adultmobile
              Even doing all this will still leave any traffic intercepted by the attacker in the past still vulnerable to decryption."
              The NSA must be falling all over themselves to try to find as many vulnerable servers as possible so they can finally decipher that mystery encrypted data they've been capturing all this time.

              ... assuming they only found out about it 2 days ago, like the rest of us, rather than 2 years ago when the bug first appeared in the source code...

              Comment

              • adultmobile
                No, I am not banned
                • Nov 2003
                • 5345

                #8
                Originally posted by rowan
                The NSA must be falling all over themselves to try to find as many vulnerable servers as possible so they can finally decipher that mystery encrypted data they've been capturing all this time.

                ... assuming they only found out about it 2 days ago, like the rest of us, rather than 2 years ago when the bug first appeared in the source code...
                It could well be that NSA knew the exploit since a year and it is upset that it was found and patched.

                TubeCamGirl.com

                Comment

                • noshit
                  Confirmed User
                  • Dec 2001
                  • 1582

                  #9
                  Originally posted by seeandsee
                  jesus what a bug, how the fuck they just found it now
                  That's easy... company that found the bug has connections to Google, Obama, DHS, and FBI. Funny how a company with those ties found a bug that seems to beg for government intervention

                  Comment

                  • anexsia
                    Confirmed User
                    • May 2010
                    • 5735

                    #10
                    already updated my servers

                    Comment

                    Working...