Go Back   IceInSpace > Equipment > Software and Computers
Register FAQ Calendar Today's Posts Search

Reply
 
Thread Tools Rate Thread
  #1  
Old 29-04-2014, 09:37 AM
GeoffW1's Avatar
GeoffW1 (Geoff)
Registered User

GeoffW1 is offline
 
Join Date: Sep 2006
Location: Sydney
Posts: 1,847
Heartbleed bug - what can WE do?

Hi,

Here's an interesting newsletter from Malwarebytes on the Heartbleed bug, especially the bit about an extension available for Chrome users. Also of interest is a list of affected servers, which includes several that IIS members would use, eg Dropbox.

http://blog.malwarebytes.org/online-...eartbleed-bug/

Cheers
Reply With Quote
  #2  
Old 29-04-2014, 10:02 AM
multiweb's Avatar
multiweb (Marc)
ze frogginator

multiweb is offline
 
Join Date: Oct 2007
Location: Sydney
Posts: 22,080
Quote:
Originally Posted by GeoffW1 View Post
Hi,

Here's an interesting newsletter from Malwarebytes on the Heartbleed bug, especially the bit about an extension available for Chrome users. Also of interest is a list of affected servers, which includes several that IIS members would use, eg Dropbox.

http://blog.malwarebytes.org/online-...eartbleed-bug/

Cheers
SSL certificates that may have been compromised by the Heartbleed vulnerability on OpenSSL should have all been replaced from April 12th onwards. OpenSSL is mostly used by UNIX/Linux service providers. I believe the problem was limited to specific OS as well. Some Ubuntu version were, FreeBSD wasn't, etc...
Reply With Quote
  #3  
Old 29-04-2014, 10:12 AM
GeoffW1's Avatar
GeoffW1 (Geoff)
Registered User

GeoffW1 is offline
 
Join Date: Sep 2006
Location: Sydney
Posts: 1,847
Hope so.

And now this. I don't mean to be a scaremonger, it is about information.

http://www.smh.com.au/it-pro/securit...428-zr11i.html

Cheers
Reply With Quote
  #4  
Old 29-04-2014, 10:24 AM
multiweb's Avatar
multiweb (Marc)
ze frogginator

multiweb is offline
 
Join Date: Oct 2007
Location: Sydney
Posts: 22,080
XP end of life was this April so obviously you use it at your own risks.
Reply With Quote
  #5  
Old 29-04-2014, 11:01 AM
Steffen's Avatar
Steffen
Ebotec Alpeht Sicamb

Steffen is offline
 
Join Date: Feb 2010
Location: Toongabbie, NSW
Posts: 1,977
Since the TLS heartbeat extension is essentially symmetric the Heartbleed vulnerability affects not just servers, but clients (web browsers etc.), too. See http://blog.meldium.com/home/2014/4/...rse-heartbleed for more information. It appears to be possible to obtain blocks of memory contents from client PCs.

Cheers
Steffen.
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time is now 06:29 AM.

Powered by vBulletin Version 3.8.7 | Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Advertisement
Astrophotography Prize
Advertisement
Bintel
Advertisement