If you run 0.9.8, it's not vulnerable. But if you're running a 1.x branch, you better pull source and recompile ASAP. Remember to restart all OpenSSL linked services, or just reboot your box completely.
Unconfigured Ad Widget
Collapse
|
|
|
|
|
|
|
|
OpenSSL TLS Heartbeat Exploit
Collapse
X
-
OpenSSL TLS Heartbeat Exploit
If you run 0.9.8, it's not vulnerable. But if you're running a 1.x branch, you better pull source and recompile ASAP. Remember to restart all OpenSSL linked services, or just reboot your box completely.
Distinguished Rifleman #1924
NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
NRL22 Match Director at WEGC
https://www.ocabj.netTags: None -
Missing bounds check for a security protocol layer? This is amazing!
-
What sucks is that you can exfiltrate the server's private key. So even if after you patch, it's probably a good idea to rekey, regenerate a CSR, and reissue a new SSL certificate. Total PITA.Last edited by ocabj; 04-08-2014, 8:59 AM.
Distinguished Rifleman #1924
NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
NRL22 Match Director at WEGC
https://www.ocabj.netComment
-
A lot of people who use the package manager in their respective Linux distro(s) to install OpenSSL instead of compiling from source are confused when the look at the dpkg logs (etc) and see libssl1.0.0 and think they're still vulnerable.
Here's a useful document:
Pay attention to the openssl build date if you're installing from a package and not from source.
Distinguished Rifleman #1924
NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
NRL22 Match Director at WEGC
https://www.ocabj.netComment
-
I pulled the github code yesterday and have been using that. You can also just use the openssl CLI client and grep for specific output in the TLS transaction.
But the Heartbleed go code is nifty since it's easily scriptable (and uses posix-style exit codes).
Distinguished Rifleman #1924
NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
NRL22 Match Director at WEGC
https://www.ocabj.netComment
-
Eventually, part of the Internet population will realize that they need to change their credentials, everywhere. Some will, some wont. Many may miss that they need to do so after site $foo updates/rebuilds openssl - including new keys and certs. pita is a real understatement.Comment
-
Now they are saying its in the routers and hubs also."The California matrix of gun control laws is among the harshest in the nation and are filled with criminal law traps for people of common intelligence who desire to obey the law." - U.S. District Judge Roger T. BenitezComment
-
For those who are concerned Calguns.net does NOT use OpenSSL and is NOT vulnerable to the Heartbleed bug.sigpic NRA Benefactor Life Member / CRPA Life Member / SAF Life Member
Calguns.net an incorported entity - President.
The Calguns Shooting Sports Assoc. - Vice President.
The California Rifle & Pistol Assoc. - Director.
DONATE TO NRA-ILA, CGSSA, AND CRPAF NOW!
Opinions posted in this account are my own and unless specifically stated as such are not the approved position of Calguns.net, CGSSA or CRPA.Comment
-
Thanks for this information!!! This is very good news.
What a nightmare this bug is. I don't think people realize how vulnerable they are. Everyone is running around changing their credentials on all the sites they use, and many of those sites have not implemented a fix yet. So, now that the bad guys have been very effectively notified of the vulnerability, and they're scrambling to exploit it during this window of opportunity, we have a ton of people changing their passwords and therefore broadcasting their credentials to the bad guys. It's just a matter of time before very sensitive accounts are hacked. This could get really bad...
Comment
-
Frankly, heartbleed is being blown out of proportion by the media. Yes, it's a serious vulnerability that needs to be fixed. But at the same time, 99% of the people out there are being led to believe that the Internet is going to blow up because of this.
Now we have regular people at my workplace using various website tools to scan our servers as if they know what they're doing telling us we have SSL problems and our sites are insecure.
It's about as painful as listening to Democrats talk about barrel shrouds and ghost guns.
Distinguished Rifleman #1924
NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
NRL22 Match Director at WEGC
https://www.ocabj.netComment
-
Technically it's a bug, not an exploit. An exploit is when someone takes advantage of the vulnerability caused by the bug.https://www.openssl.org/news/secadv_20140407.txt
If you run 0.9.8, it's not vulnerable. But if you're running a 1.x branch, you better pull source and recompile ASAP. Remember to restart all OpenSSL linked services, or just reboot your box completely.Comment
-
-
Distinguished Rifleman #1924
NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
NRL22 Match Director at WEGC
https://www.ocabj.netComment
-
It is not that big because of the behind the scenes work being done ahead of time.Frankly, heartbleed is being blown out of proportion by the media. Yes, it's a serious vulnerability that needs to be fixed. But at the same time, 99% of the people out there are being led to believe that the Internet is going to blow up because of this.
Now we have regular people at my workplace using various website tools to scan our servers as if they know what they're doing telling us we have SSL problems and our sites are insecure.
It's about as painful as listening to Democrats talk about barrel shrouds and ghost guns.
That said, bad guys/nations are scanning for unpatched servers.Comment
Calguns.net Statistics
Collapse
Topics: 1,868,685
Posts: 25,173,782
Members: 357,644
Active Members: 5,384
Welcome to our newest member, Ty160805.
What's Going On
Collapse
There are currently 15104 users online. 128 members and 14976 guests.
Most users ever online was 239,041 at 10:39 PM on 02-14-2026.

Comment