Unconfigured Ad Widget

Collapse

OpenSSL TLS Heartbeat Exploit

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ocabj
    Calguns Addict
    • Oct 2005
    • 7924

    OpenSSL TLS Heartbeat Exploit



    If you run 0.9.8, it's not vulnerable. But if you're running a 1.x branch, you better pull source and recompile ASAP. Remember to restart all OpenSSL linked services, or just reboot your box completely.

    Distinguished Rifleman #1924
    NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
    NRL22 Match Director at WEGC

    https://www.ocabj.net
  • #2
    ghost_shooter
    Junior Member
    • Feb 2014
    • 65

    Missing bounds check for a security protocol layer? This is amazing!

    Comment

    • #3
      ocabj
      Calguns Addict
      • Oct 2005
      • 7924

      What sucks is that you can exfiltrate the server's private key. So even if after you patch, it's probably a good idea to rekey, regenerate a CSR, and reissue a new SSL certificate. Total PITA.
      Last edited by ocabj; 04-08-2014, 8:59 AM.

      Distinguished Rifleman #1924
      NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
      NRL22 Match Director at WEGC

      https://www.ocabj.net

      Comment

      • #4
      • #5
        ocabj
        Calguns Addict
        • Oct 2005
        • 7924

        A lot of people who use the package manager in their respective Linux distro(s) to install OpenSSL instead of compiling from source are confused when the look at the dpkg logs (etc) and see libssl1.0.0 and think they're still vulnerable.

        Here's a useful document:



        Pay attention to the openssl build date if you're installing from a package and not from source.

        Distinguished Rifleman #1924
        NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
        NRL22 Match Director at WEGC

        https://www.ocabj.net

        Comment

        • #6
          ocabj
          Calguns Addict
          • Oct 2005
          • 7924

          I pulled the github code yesterday and have been using that. You can also just use the openssl CLI client and grep for specific output in the TLS transaction.

          But the Heartbleed go code is nifty since it's easily scriptable (and uses posix-style exit codes).

          Distinguished Rifleman #1924
          NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
          NRL22 Match Director at WEGC

          https://www.ocabj.net

          Comment

          • #7
            TMcC
            CGN/CGSSA Contributor
            • Jul 2011
            • 920

            Eventually, part of the Internet population will realize that they need to change their credentials, everywhere. Some will, some wont. Many may miss that they need to do so after site $foo updates/rebuilds openssl - including new keys and certs. pita is a real understatement.

            Comment

            • #8
              Californio
              CGN/CGSSA Contributor - Lifetime
              CGN Contributor - Lifetime
              • Dec 2006
              • 4169

              Now they are saying its in the routers and hubs also.
              "The California matrix of gun control laws is among the harshest in the nation and are filled with criminal law traps for people of common intelligence who desire to obey the law." - U.S. District Judge Roger T. Benitez

              Comment

              • #9
                Kestryll
                Head Janitor
                • Oct 2005
                • 21601

                For those who are concerned Calguns.net does NOT use OpenSSL and is NOT vulnerable to the Heartbleed bug.
                sigpic NRA Benefactor Life Member / CRPA Life Member / SAF Life Member
                Calguns.net an incorported entity - President.
                The Calguns Shooting Sports Assoc. - Vice President.
                The California Rifle & Pistol Assoc. - Director.
                DONATE TO NRA-ILA, CGSSA, AND CRPAF NOW!
                Opinions posted in this account are my own and unless specifically stated as such are not the approved position of Calguns.net, CGSSA or CRPA.

                Comment

                • #10
                  laurelpark
                  Senior Member
                  • Aug 2011
                  • 1013

                  Thanks for this information!!! This is very good news.

                  What a nightmare this bug is. I don't think people realize how vulnerable they are. Everyone is running around changing their credentials on all the sites they use, and many of those sites have not implemented a fix yet. So, now that the bad guys have been very effectively notified of the vulnerability, and they're scrambling to exploit it during this window of opportunity, we have a ton of people changing their passwords and therefore broadcasting their credentials to the bad guys. It's just a matter of time before very sensitive accounts are hacked. This could get really bad...

                  Originally posted by Kestryll
                  For those who are concerned Calguns.net does NOT use OpenSSL and is NOT vulnerable to the Heartbleed bug.

                  Comment

                  • #11
                    ocabj
                    Calguns Addict
                    • Oct 2005
                    • 7924

                    Frankly, heartbleed is being blown out of proportion by the media. Yes, it's a serious vulnerability that needs to be fixed. But at the same time, 99% of the people out there are being led to believe that the Internet is going to blow up because of this.

                    Now we have regular people at my workplace using various website tools to scan our servers as if they know what they're doing telling us we have SSL problems and our sites are insecure.

                    It's about as painful as listening to Democrats talk about barrel shrouds and ghost guns.

                    Distinguished Rifleman #1924
                    NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
                    NRL22 Match Director at WEGC

                    https://www.ocabj.net

                    Comment

                    • #12
                      NytWolf
                      Veteran Member
                      • Feb 2010
                      • 3935

                      Originally posted by ocabj
                      https://www.openssl.org/news/secadv_20140407.txt

                      If you run 0.9.8, it's not vulnerable. But if you're running a 1.x branch, you better pull source and recompile ASAP. Remember to restart all OpenSSL linked services, or just reboot your box completely.
                      Technically it's a bug, not an exploit. An exploit is when someone takes advantage of the vulnerability caused by the bug.

                      Comment

                      • #13
                        Jason95357
                        Senior Member
                        • Feb 2013
                        • 1130

                        Originally posted by Kestryll
                        For those who are concerned Calguns.net does NOT use OpenSSL and is NOT vulnerable to the Heartbleed bug.
                        Hah, yeah, the one time where passwords in the clear ended up being more secure.
                        LTCs: CA, OR, AZ, UT, FL, NV
                        GOA & NRA Member

                        Comment

                        • #14
                          ocabj
                          Calguns Addict
                          • Oct 2005
                          • 7924

                          Originally posted by Jason95357
                          Hah, yeah, the one time where passwords in the clear ended up being more secure.
                          Or in some cases, people still running the older 0.9.8 branch of OpenSSL.

                          Distinguished Rifleman #1924
                          NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
                          NRL22 Match Director at WEGC

                          https://www.ocabj.net

                          Comment

                          • #15
                            Jason95357
                            Senior Member
                            • Feb 2013
                            • 1130

                            Originally posted by ocabj
                            Frankly, heartbleed is being blown out of proportion by the media. Yes, it's a serious vulnerability that needs to be fixed. But at the same time, 99% of the people out there are being led to believe that the Internet is going to blow up because of this.

                            Now we have regular people at my workplace using various website tools to scan our servers as if they know what they're doing telling us we have SSL problems and our sites are insecure.

                            It's about as painful as listening to Democrats talk about barrel shrouds and ghost guns.
                            It is not that big because of the behind the scenes work being done ahead of time.

                            That said, bad guys/nations are scanning for unpatched servers.
                            LTCs: CA, OR, AZ, UT, FL, NV
                            GOA & NRA Member

                            Comment

                            Working...
                            UA-8071174-1