Heartbleed

The Heartbleed Bug The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs). The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.

What leaks in practice? We have tested some of our own services from attacker's perspective. We attacked ourselves from outside, without leaving a trace. Without using any privileged information or credentials we were able steal from ourselves the secret keys used for our X.509 certificates, user names and passwords, instant messages, emails and business critical documents and communication. H

ow to stop the leak? As long as the vulnerable version of OpenSSL is in use it can be abused. Fixed OpenSSL has been released and now it has to be deployed. Operating system vendors and distribution, appliance vendors, independent software vendors have to adopt the fix and notify their users. Service providers and users have to install the fix as it becomes available for the operating systems, networked appliances and software they use.

Featured Posts
Recent Posts
Search By Tags
Follow Us
  • Facebook Classic
  • Twitter Classic
  • Google Classic
ISSA
IDAgentPartner-Logo-black
download
LA Sports Color
17_nextLA_AQUA
SCLN Logo
SilverMidmarketSolutionProvider
sophos reflexion
58316-trend-micro-box
Microsoft-Partner-Silver-Small-and-Midmarket-Cloud
mspp_trustmark150
polycom-logo-h-cmyk_highres.jpeg
silver-partner.jpg
samsung-silver.jpg
oracle.jpg
Kaspersky_Lab_logo.jpg
Dlink.jpg
AVG-Reseller-Logo-Lockup_Authorized-Reseller_Authorized-Reseller.png
Los Angeles Area Chamber of Commerce
EZworknet Logo Bold.png
Irvine Chamber of Commerce
HUBLA2.jpg
Intronis
Proud Microsoft Partner
Hewlett pACKARD.gif
Datto_Authorized_Partner_Badge.jpg
Axcient1.jpg
Hewlett pACKARD.gif
APC
Ingram Micro Distribution
Proud IBM Partners
Proud Cisco Meraki Partners
Sonicwall
Dell Sonic Wall
Protect yourself with McAfee
Microsoft Certified Professional
Samsung
Cisco Meraki
Dell Partner Direct.
Proud Lenovo Partner
AdobeRegistered

Managed Technology Support Services  | Managed Security Service Provider

Irvine | Los Angeles | Santa Monica | Palm Springs | San Diego | Santa Barbara | Inland Valleys | Temecula

Toll Free:   1-800-884-1103      |       Email:  Info@ezworknet.com

  • Facebook App Icon
  • Twitter App Icon
  • Google+ Classic
  • LinkedIn App Icon
  • Pinterest App Icon
  • YouTube Classic

© 2019 EZworknet llc

EZworknet Logo Bold.png