Major OpenSSL Vulnerability Discovered

Status
Not open for further replies.

Tom Bombadildo

Dick, With Balls
OP
Member
Joined
Jul 11, 2009
Messages
14,575
Trophies
2
Age
29
Location
I forgot
Website
POCKET.LIKEITS
XP
19,214
Country
United States
PvTDhxT.png

OpenSSL, the open-sourced SSL/TSL protocols used by a large amount of websites, suffers from what most are calling a "very serious and very damaging vulnerability" called the "Heartbleed Bug". For any web devs out there currently using OpenSSL 1.01 to 1.01f, it's STRONGLY recommended you update to 1.01g in order to fix this.


What leaks in practice?
We have tested some of our own services from attacker's perspective. We attacked ourselves from outside, without leaving a trace. Without using any privileged information or credentials we were able steal from ourselves the secret keys used for our X.509 certificates, user names and passwords, instant messages, emails and business critical documents and communication.

How to stop the leak?
As long as the vulnerable version of OpenSSL is in use it can be abused. Fixed OpenSSL has been released and now it has to be deployed. Operating system vendors and distribution, appliance vendors, independent software vendors have to adopt the fix and notify their users. Service providers and users have to install the fix as it becomes available for the operating systems, networked appliances and software they use.


More info and some FAQs can be seen from the Source.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    SylverReZ @ SylverReZ: Hello @realtimesave.