Skip to main content

HeartBleed - An open source failure?????

                                                                                    Heart Bleed....

The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs).




 On 8th April , when Microsoft stopped giving support to WinXP, the major vulnerability in the open source OpenSSL was found.The 1000s of websites using OpenSSL like Facebook,Google,Yahoo are affected due a simple OpenSSL programming mistake . A programming blunder enabled attackers to pull down 64k chunks of "secure" server memory. Of course, a hacker would then have to shift through this captured memory for social security numbers, credit-card numbers, and names, but that's trivial.                                   

                                  
Half a million sites are vulnerable.Test websites' vulnerability here.

 According to .zdnet.com ,German programmer Dr. Robin Seggelmann added a new "feature" and forgot to validate a variable containing a length. The code reviewer, Dr Stephen Henson, "apparently also didn’t notice the missing validation," said Seggelmann, "so the error made its way from the development branch into the released version." And, then for about two years the defective code would be used, at one time or another, by almost ever Internet user in the world.


The bug has been patched. After you patch your systems, you have to get a new public/private key pair, update your SSL certificate, and then change every password that could potentially be affected.


ColdFlare announced the challenge to hack the private keys from the server using the HeartBleed bug and after several hours hackers stole them.But the controversial part is that the server was rebooted during the challange. The two winners are Fedor Indutny and Illkka Mattila. Indutny, who succeeded first, made 2.5 million Heartbleed requests over the course of the day and Mattila made 100,000. CloudFlare rebooted the server at one point during the test which they say may have contributed to the successful attempt.

To be on safer side if you are having an account on a website using OpenSSL, change your password. and if a website is asking you to change your password-Do it!!

Check for more info about the challenge


                                If you have account on Yahoo,change your password NOW!! Even thought google is saying they have patched the vulnerability but you can't take risk so its better to change your google account passwords  and the same applies to facebook.

Snapshot :-




Comments

Post a Comment

Queries And Suggestions are always welcome

Popular posts from this blog

GMAIL HACK

HOW HACK GMAIL ACCOUNT!!!!! How to hack gmail account password In this post i will show you various methods regarding "How to hack Gmail account password" OR How to hack gmail account password",I only suggest the two possible methods methods to hack gmail account passwords What is:- 1.PHISHING The act of sending an Email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. The Email directs the user to visit a Web site where they are asked to update personal information, such as passwords and credit card, social security, and bank account numbers, that the legitimate organization already has. The Web site, however, is Bogus and set up only to steal the User’s information. Phishing attacks are Trying to steal your Money !!! Phishing Scams Could Be-

Securing your Account

2 basic vulnerabilities in the recovery options were   1. account recovery question  2. 3 trusted friends   1. Account recovery question Now Facebook asks you these questions as security concerns  1.What was the last name of your first grade teacher? you can use this question as very few will know the answer of this question but you..    2. In what city or town was your mother born? never ever use this question if it's not secret. there is no secret in it.. most of the people who know little about you will find out this question simply by guessing or by visiting your mother's Facebook profile...   3. What street did you live on when you were 8 years old?   one of 50-50 questions very few except the one's who played with you on that street or who watched you there will know the answer.   4. What was the last name of your third grade teacher?   Same as the first Question     now question 4 and 5 I would suggest y...