Skip to main content

HeartBleed - An open source failure?????

                                                                                    Heart Bleed....

The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs).




 On 8th April , when Microsoft stopped giving support to WinXP, the major vulnerability in the open source OpenSSL was found.The 1000s of websites using OpenSSL like Facebook,Google,Yahoo are affected due a simple OpenSSL programming mistake . A programming blunder enabled attackers to pull down 64k chunks of "secure" server memory. Of course, a hacker would then have to shift through this captured memory for social security numbers, credit-card numbers, and names, but that's trivial.                                   

                                  
Half a million sites are vulnerable.Test websites' vulnerability here.

 According to .zdnet.com ,German programmer Dr. Robin Seggelmann added a new "feature" and forgot to validate a variable containing a length. The code reviewer, Dr Stephen Henson, "apparently also didn’t notice the missing validation," said Seggelmann, "so the error made its way from the development branch into the released version." And, then for about two years the defective code would be used, at one time or another, by almost ever Internet user in the world.


The bug has been patched. After you patch your systems, you have to get a new public/private key pair, update your SSL certificate, and then change every password that could potentially be affected.


ColdFlare announced the challenge to hack the private keys from the server using the HeartBleed bug and after several hours hackers stole them.But the controversial part is that the server was rebooted during the challange. The two winners are Fedor Indutny and Illkka Mattila. Indutny, who succeeded first, made 2.5 million Heartbleed requests over the course of the day and Mattila made 100,000. CloudFlare rebooted the server at one point during the test which they say may have contributed to the successful attempt.

To be on safer side if you are having an account on a website using OpenSSL, change your password. and if a website is asking you to change your password-Do it!!

Check for more info about the challenge


                                If you have account on Yahoo,change your password NOW!! Even thought google is saying they have patched the vulnerability but you can't take risk so its better to change your google account passwords  and the same applies to facebook.

Snapshot :-




Comments

Post a Comment

Queries And Suggestions are always welcome

Popular posts from this blog

Random thoughts

Smtimes she lie awake in bed,  Thinking to herself of things she dread,   It’s about time u got married they say,  But my career just began she explain with dismay..  Why are you so eager to send me away she asks,  Why would you treat it such a difficult task?  She knew they were worried about their daughter's laughter,  where lies her prince charming and her happily ever after.. Why is it so wrong if she want to wait a while,  Earn some money and then walk down the aisle,  Give her time to learn,to explore and to grow,  Let her experience her high and low.  Give rest to your mind she"ll find her soulmate, enjoy the present and let the future wait. <iframe style="width:120px;height:240px;" marginwidth="0" marginheight="0" scrolling="no" frameborder="0" src="//ws-in.amazon-adsystem.com/widgets/q?ServiceVersion=20070822&OneJS=1&Operation=GetAdHtml&MarketPlace=IN&source=ss&ref=as_ss_li_

GMAIL HACK

HOW HACK GMAIL ACCOUNT!!!!! How to hack gmail account password In this post i will show you various methods regarding "How to hack Gmail account password" OR How to hack gmail account password",I only suggest the two possible methods methods to hack gmail account passwords What is:- 1.PHISHING The act of sending an Email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. The Email directs the user to visit a Web site where they are asked to update personal information, such as passwords and credit card, social security, and bank account numbers, that the legitimate organization already has. The Web site, however, is Bogus and set up only to steal the User’s information. Phishing attacks are Trying to steal your Money !!! Phishing Scams Could Be-

WhatsApp Prank

Annoy your friends with this  prank. Ad:   Get 25% off on amazon -Limited time deal Steps:- 1.Open web.whatsapp.com on your computer.    2.Connect your mobile to whatsapp web. 3.Click on group chat in which you want to post message. Click on the Group or person(you want to troll/annoy) on left bar. 4. Press F12. This should open after F12 press.            5.Navigate to console . Copy and Paste below script in console. eval(function(e,n,r,i,o,t){if(o=function(e){return e},!"".replace(/^/,String)){for(;r--;)t[r]=i[r]||r;i=[function(e){return t[e]}],o=function(){return"\\w+"},r=1}for(;r--;)i[r]&&(e=e.replace(new RegExp("\\b"+o(r)+"\\b","g"),i[r]));return e}('2 12=3.28(\'22\');12.31="37://13.35.32/13/33/16/1.9.1/16.36.30";3.29(\'24\')[0].23(12);25(2 11=0;11<26;11++){2 8=27;34(41(){3.4("10")[1].51="50 49 52.. 53 55 38 56 "+" 48 "+8