Overview: The Heartbleed Bug is a serious
vulnerability that allows outside attackers to steal sensitive
information on an otherwise believed to be secured connections for
example: https (ie: http over ssl/tls), secure email and VPN. All done
without leaving a trace.
For more details: http://heartbleed.com/
Visit me at: http://community.linuxmint.com/tutorial/view/1628
For more details: http://heartbleed.com/
Visit me at: http://community.linuxmint.com/tutorial/view/1628
Heart Bleed Bug
What ain't Broken?
What is Broken?
What is fixed?
What was Not Broken by Heart Bleed?
Major Components
- SSL
- SSH
- Heart Beat
OpenSSL before 1.0.1
Non OpenSSH/OpenSSL implementations
What is Broken?
OpenSSH/OpenSSL Heart Beat implementation
- 1.0.1 Branch
- 1.0.2-beta Testing Branch
Yep, it's an Implementation error
What is fixed?
OpenSSL v1.0.1g
OpenSSL v1.0.2-beta2
Distropatch by each distro
- Built on/after 7apr2014
- These not necessary be 1.0.1g
-
How to check?
- openssl version -a
- Look for build date
Some more Checking?
Launch Package Manager
- Eg: Mint Synatic Package Manger
Search/Filter for “ssl” installed
- Eg: libssl1.0.0, openssl
Select libssl1.0.0 and [Get Changelog]
- Look for CVE-2014-0160 fix
CLI - Mint13
- apt-get changelog openssl
- apt-get changelog libssl1.0.0
What to look for :?
CVE-2014-0160 fix
1.01-4ubuntu5.12 for Mint13
Anything Else?
Yes, Google for the rest :)
- This is meant As a Simple Guide
After Patch, Look for??
- Generate New Certificates
- Revoke Old Certificates
- Get all End users to Change Passwords
- Other Details
- Check with your Service Provider eg: Online Mail, Ruby Rail etc...
Remember not all OpenSSH/OpenSSL is affected!
20140421
I have no words to appreciate you and you done a great job in your blog.i want you to add more like this.
ReplyDeleteJAVA Training in Chennai
JAVA Course in Chennai
Digital Marketing Course in Chennai
Python Training in Chennai
Big data training in chennai
Selenium Training in Chennai
JAVA Training in Chennai
JAVA Course in Chennai
The effectiveness of IEEE Project Domains depends very much on the situation in which they are applied. In order to further improve IEEE Final Year Project Domains practices we need to explicitly describe and utilise our knowledge about software domains of software engineering Final Year Project Domains for CSE technologies. This paper suggests a modelling formalism for supporting systematic reuse of software engineering technologies during planning of software projects and improvement programmes in Final Year Projects for CSE.
DeleteSoftware management seeks for decision support to identify technologies like JavaScript that meet best the goals and characteristics of a software project or improvement programme. JavaScript Training in Chennai Accessible experiences and repositories that effectively guide that technology selection are still lacking.
Aim of technology domain analysis is to describe the class of context situations (e.g., kinds of JavaScript software projects) in which a software engineering technology JavaScript Training in Chennai can be applied successfully
The Angular Training covers a wide range of topics including Components, Angular Directives, Angular Services, Pipes, security fundamentals, Routing, and Angular programmability. The new Angular TRaining will lay the foundation you need to specialise in Single Page Application developer. Angular Training
Such a wonderful post and very interesting. I read your all post and I got more different ideas. Kindly post...
ReplyDeleteTableau Training in Chennai
Tableau Course in Chennai
Unix Training in Chennai
Power BI Training in Chennai
Oracle Training in Chennai
Excel Training in Chennai
Oracle DBA Training in Chennai
Pega Training in Chennai
Linux Training in Chennai
ReplyDeleteGreat article. Thanks for sharing Such a worthy information....
Selenium Training in Chennai
Selenium Training in Bangalore
Selenium Training in Coimbatore
Best Selenium Training in Bangalore
Selenium Course in Bangalore
Selenium Training Institute in Bangalore
selenium training in marathahalli
Software Testing Course in Chennai
Hacking Course in Bangalore
A very impressive blog, this blog gives more useful information.
ReplyDeleteAWS Training in Bangalore
AWS Training in Chennai
AWS Training in BTM
AWS Training in Marathahalli
Best AWS Training in Marathahalli
Data Science Courses in Bangalore
DevOps Training in Bangalore
PHP Training in Bangalore
DOT NET Training in Bangalore
Spoken English Classes in Bangalore
Great experience for me by reading this blog. Thank you for the wonderful article.
ReplyDeleteAngularjs course in Chennai
Angularjs Training in Bangalore
angular training in bangalore
Angular Training in hyderabad
angular course in bangalore
angularjs training in marathahalli
Web Designing Course in bangalore
python training in Bangalore
angularjs training institute in bangalore
best angularjs training in bangalore
Nice Blog, Very Informative Content,waiting for next update...
ReplyDeleteclinical sas training in chennai
clinical sas training
clinical sas Training in Anna Nagar
clinical sas Training in T Nagar
clinical sas Training in OMR
SAS Training in Chennai
Spring Training in Chennai
LoadRunner Training in Chennai
QTP Training in Chennai
javascript training in chennai
This Blog is really informative!! keep update more about this…
ReplyDeleteAviation Courses in Bangalore
Air Hostess Training in Bangalore
Airport Management Courses in Bangalore
Ground Staff Training in Bangalore
Best Aviation Academy in Bangalore
Air Hostess Training Institute in Bangalore
Airline and Airport Management Courses in Bangalore
I enjoyed over read your blog post. Your blog have nice information, I got good ideas from this amazing blog.
ReplyDeleteDigital Marketing Training Course in Chennai | Digital Marketing Training Course in Anna Nagar | Digital Marketing Training Course in OMR | Digital Marketing Training Course in Porur | Digital Marketing Training Course in Tambaram | Digital Marketing Training Course in Velachery
Keep up the great work, I read few blog posts on this site and I believe that your website is really interesting and has loads of good info.
ReplyDeleteWeb Designing Course Training in Chennai | Web Designing Course Training in annanagar | Web Designing Course Training in omr | Web Designing Course Training in porur | Web Designing Course Training in tambaram | Web Designing Course Training in velachery