Questions tagged [heartbleed]

A highly critical vulnerability in the OpenSSL library which allows an attacker to obtain random 64kByte blocks of memory from the process using said library, which could include user credentials, private SSL keys, and other data sent/received from the server.

OpenSSL Security Advisory [07 Apr 2014]

TLS heartbeat read overrun (CVE-2014-0160)

A missing bounds check in the handling of the TLS heartbeat extension can be used to reveal up to 64k of memory to a connected client or server.

Only 1.0.1 and 1.0.2-beta releases of OpenSSL are affected including 1.0.1f and 1.0.2-beta1.

Thanks for Neel Mehta of Google Security for discovering this bug and to Adam Langley and Bodo Moeller for preparing the fix.

Affected users should upgrade to OpenSSL 1.0.1g. Users unable to immediately upgrade can alternatively recompile OpenSSL with -DOPENSSL_NO_HEARTBEATS.

1.0.2 will be fixed in 1.0.2-beta2.

133 questions
19
votes
4 answers

Which services are affected by Heartbleed?

I have to admit that I'm confused as to which services exactly are affected by Heartbleed. I have read http://heartbleed.com but all I read is that OpenSSL is affected. Great, but I don't really know where OpenSSL is used. So concretely, are these…
Matthieu Napoli
  • 292
  • 1
  • 2
  • 7
9
votes
1 answer

Who proposed adding heartbeat to SSL? And who proposed it's form?

So we now know who wrote the bad code (Robin Seggelmann). And we have an idea of why it is needed: Why does TLS need an explicit heartbeat protocol? We can also understand why the client supplies the length: Heartbleed: Why does the client supply…
boatcoder
  • 345
  • 2
  • 8
4
votes
1 answer

Heartbleed: length of heatbeat message?

What is the right length of heartbeat message between 2^14 and 2^16 ? The RFC https://www.rfc-editor.org/rfc/rfc6520 says that The total length of a HeartbeatMessage MUST NOT exceed 2^14 or max_fragment_length when negotiated as defined in…
mpgn
  • 290
  • 3
  • 15
4
votes
2 answers

Does Heartbleed vulnerability affect other libraries (like BouncyCastle, .NET's SslStream, etc.)?

pretty much the title, how to know if the Heartbleed vulnerability (for OpenSSL) affects other libraries like .NET's SSLStream or BouncyCastle. (Sorry for ignorance, but have found no info on how to exploit, to see if is related to bufferoverruns…
3
votes
0 answers

How can you influence what will be leaked by Heartbleed?

I am working on a Heartbleed example exploit. I was able to set the server up with an older version of Apache and OpenSSL and the server is infact vulnerable. However, when leaking the information, the only information that's being returned is the…
3
votes
1 answer

How CloudBleed is different from HeartBleed?

given the recent exposure of the information leak stemmed from buffer-overrun of HTML-parser of CF's edge servers; fundamentally how it is different from HeartBleed? CloudFlare have detailed the bug here:…
kmonsoor
  • 131
  • 4
2
votes
2 answers

One year later, is Heartbleed still something the end-user needs to be careful against?

I'm running Chromebleed to defend against sites affected by Heartbleed, but it's been a very long time since I've used a site that was still vulnerable. By now I would think the vast majority of the Internet has upgraded to protect against the…
Dang Khoa
  • 325
  • 1
  • 6
2
votes
2 answers

What can a hacker do to my home router if I have the admin page enabled externally?

Say my home router uses an OpenSSL version that is vulnerable to Heartbleed and I have the admin page enabled and accessible from the outside (even though I never use it). What can a hacker do? Could he for example read any traffic on my router or…
Matthijs Wessels
  • 443
  • 1
  • 6
  • 10
2
votes
1 answer

Heartbleed: hackers have already used the vulnerability?

Read about the vulnerability and decided to check out the site. Receiving a response from the php code was surprised. Look at the screenshot. Perl-script: http://pastebin.com/rL0XkewP Hackers have already got down to business?
user44425
  • 21
  • 1
2
votes
1 answer

Heartbleed RSA Key

I'm currently a student doing some research into the Heartbleed Vulnerability and I'm having difficulty retrieving the correct RSA private keys. Here is my setup environment in VirtualBox: Kali Linux 2.0 Host Only Network with ip address…
1
vote
2 answers

Testing your site for the heartbleed vulnerability?

I've seen a number of articles on the heartbleed vulnerability that suggest testing your site to see if it was affecting using Filippo Valsorda's testing page which can be found here: https://filippo.io/Heartbleed/ When I put the URL to my site into…
Abe Miessler
  • 8,195
  • 11
  • 49
  • 73
1
vote
1 answer

Would memory of EC2 instances behind a vulnerable ELB be readable by heartbleed exploit?

It is public that Amazon's Elastic Load Balancers (ELBs) were vulnerable to the heartbleed exploit before they patched them all on April 8th. I understand that the memory of these ELBs (and therefore the certificates on them) could be compromised,…
Peter
  • 168
  • 5
1
vote
2 answers

OVPN Connections vulnerable to Heart Bleed?

This may be a stupid question, but I'll ask anyway. I have been reading quite a bit about the Heart Bleed vulnerability, and I'm curious as to whether it only affects web applications or whether OVPN connections secured with certs produced with…
DKNUCKLES
  • 9,237
  • 2
  • 38
  • 49
0
votes
2 answers

Is there a HeartBleed Honeypot so that I can pentest it?

I am looking to improve my skills, to do so I need a site with an old OpenSSL version, so that I can do a pentest on my own.
0
votes
2 answers

Are there stories of any individuals being affected by Heartbleed?

With all the coverage of the technical aspects and doomsday talk, it's hard to get co-workers to listen when they don't see stories of real people being affected by Heartbleed. So is there any evidence of individuals out there actually suffering at…
Kenzo
  • 259
  • 2
  • 6
1
2