Unconfigured Ad Widget

Collapse

OpenSSL TLS Heartbeat Exploit

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • #16
    TMcC
    CGN/CGSSA Contributor
    • Jul 2011
    • 920

    Originally posted by Jason95357

    That said, bad guys/nations are scanning for unpatched servers.
    That happens 24x7 365 a year. Nothing new.

    Comment

    • #17
      laurelpark
      Senior Member
      • Aug 2011
      • 1013

      I agree that it is being blown out of proportion - but that very media attention is what is making this so dangerous. Before Monday, most bad guys had no clue this vulnerability was there. When the news hit, it broadcast the vulnerability to everyone who might want to exploit it.

      Most sites aren't doing much - the big guys are, but the mom and pop shops don't have the resources and probably won't for several weeks.

      So, that leaves a window of opportunity open to the bad guys to scour the net for any vulnerable site - and grab whatever they can. What makes it bad is that things are blown so out of proportion that the average Joe is freaking out and going around changing usernames/passwords on all the sites he frequents.

      The net result: many of the sites that the bad guys would not have bothered looking at are now potentially being compromised. At the same time, the bad guys are grabbing any data they can. Once they get someone's username/password, they know darned well that most people are lazy and they use the same username/password across dozens of sites.

      Next thing to happen: people who just changed their username/password to "be safe" will find out that their accounts have started to get compromised. That's where it gets really ugly.

      It sucks - I'm afraid to change a username/password anywhere unless that site has clearly stated that they have implemented a fix.

      I wish this weren't as big a deal as it is. Fortunately or unfortunately, I work in the internet security business, and there is some serious freaking out going on - and it is real.

      Originally posted by ocabj
      Frankly, heartbleed is being blown out of proportion by the media. Yes, it's a serious vulnerability that needs to be fixed. But at the same time, 99% of the people out there are being led to believe that the Internet is going to blow up because of this.

      Now we have regular people at my workplace using various website tools to scan our servers as if they know what they're doing telling us we have SSL problems and our sites are insecure.

      It's about as painful as listening to Democrats talk about barrel shrouds and ghost guns.

      Comment

      • #18
        j-shot
        Senior Member
        • Jan 2014
        • 1646

        Originally posted by Jason95357
        It is not that big because of the behind the scenes work being done ahead of time.

        That said, bad guys/nations are scanning for unpatched servers.
        True.

        Originally posted by TMcC
        That happens 24x7 365 a year. Nothing new.
        More true. Scans are always going down for O/S or device signatures.
        Originally posted by Citadelgrad87
        ...what we have here is a hillary panty sniffer...
        Originally posted by Appleseed
        A Rifleman understands that owning and mastering a rifle is part of his heritage as an American.
        Originally posted by ProShooter
        No man, butt rape is happening like, all of the time in prison. It's basically just one huge orgy.

        Comment

        • #19
          bacon_lover
          Senior Member
          • Jul 2010
          • 819

          Originally posted by NytWolf
          Technically it's a bug, not an exploit. An exploit is when someone takes advantage of the vulnerability caused by the bug.
          The NSA has reportedly been taking advantage of the vulnerability. If the reports are true, well, it wouldn't be surprising.

          I've been running the Qualys SSL test against a bunch of firearms sites that I created accounts on or from which I've made purchases. Thus far the only one that shows up vulnerable is Daniel Defense's site.
          "The American Republic will endure until the day Congress discovers that it can bribe the public with the public's money."
          - Alexis de Tocqueville

          Comment

          Working...
          UA-8071174-1