top of page
CCLLogos-new.jpg

Heartbleed

The Heartbleed Bug The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs). The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.

What leaks in practice? We have tested some of our own services from attacker's perspective. We attacked ourselves from outside, without leaving a trace. Without using any privileged information or credentials we were able steal from ourselves the secret keys used for our X.509 certificates, user names and passwords, instant messages, emails and business critical documents and communication. H

ow to stop the leak? As long as the vulnerable version of OpenSSL is in use it can be abused. Fixed OpenSSL has been released and now it has to be deployed. Operating system vendors and distribution, appliance vendors, independent software vendors have to adopt the fix and notify their users. Service providers and users have to install the fix as it becomes available for the operating systems, networked appliances and software they use.

ISSA
download
moonjuice
LA Sports Color
osea
17_nextLA_AQUA
SCLN Logo
recharge
SilverMidmarketSolutionProvider
58316-trend-micro-box
silver-partner.jpg
oracle.jpg
Kaspersky_Lab_logo.jpg
samsung-silver.jpg
Los Angeles Area Chamber of Commerce
Irvine Chamber of Commerce
HUBLA2.jpg
Intronis
Proud Microsoft Partner
Datto_Authorized_Partner_Badge.jpg
Axcient1.jpg
Hewlett pACKARD.gif
APC
Proud IBM Partners
Proud Cisco Meraki Partners
Microsoft Certified Professional
Samsung
Cisco Meraki
AdobeRegistered
Edited Image 2014-1-27-13:23:4
CCLLogos ccl-new.jpg
CalCyberEZW LogoLG.png

Voice Over IP -Backup and Disaster Recovery

Data - Compliance Risk Exposure Analysis

Critical Infrastructure Resilience

Security Awareness Training

 Enterprise Network and Data Security Services

CalCyberLab | Cal Cyber Defense Labs |  EZworknet   

Nevada     California     Utah     New Mexico    Hawaii

© 2024 CalCyberLab llc

bottom of page