{"id":6097,"date":"2014-04-10T09:54:17","date_gmt":"2014-04-10T07:54:17","guid":{"rendered":"http:\/\/blog.netspark.de\/?p=6097"},"modified":"2014-04-10T09:54:17","modified_gmt":"2014-04-10T07:54:17","slug":"heartbleed-or-when-the-it-goes-crazy","status":"publish","type":"post","link":"https:\/\/blog.netspark.de\/?p=6097","title":{"rendered":"Heartbleed &#8211; Or when the IT goes crazy"},"content":{"rendered":"<p><a href=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-Post-Thumb wp-image-6098\" alt=\"heartbleed\" src=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-64x64.png\" width=\"64\" height=\"64\" srcset=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-64x64.png 64w, https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-150x150.png 150w\" sizes=\"auto, (max-width: 64px) 100vw, 64px\" \/><\/a>Since the leak got public, every IT service provider is going crazy about<br \/>\nthe heartbleed bug that is active with OpenSSL 1.0.1 to 1.0.1f. But what<br \/>\nexactly makes the heartbleed bug so dangerous? <a href=\"http:\/\/heartbleed.com\/\" target=\"_blank\">This website<\/a> has com-<br \/>\nprehensive information available for those running OpenSSL.<\/p>\n<p><!--more-->Since there are hundreds of thousands of websites active that use one of the affected OpenSSL versions, the chance is high, that a malicious exploit user has already taken action to successfully gain access to the private encryption key. Once one has the pkey, it is possible to fake a server&#8217;s identity with the customer not noticing this as the server is able to create valid OpenSSL-connections. The customer only sees the Lock logo indicating that all is well so far but in the background he is sending his private information to another server.<\/p>\n<p>As many e-shops, e-banking websites and other protected services all run OpenSSL on their webservers, the risk is high. There&#8217;s a website to check one&#8217;s personal favourites that use secured connections if they&#8217;re exposed to the bug or really secure. Check yours here: <a href=\"http:\/\/filippo.io\/Heartbleed\" target=\"_blank\">Heartbleed check site<\/a><\/p>\n<p>I found out that all of my favs are already secure. In switzerland, the MELANI office warned about the issue 48 hours ago. Yesterday most of the swiss websites have already been secured as website operators have applied the supplied patch. But there are numerous websites out in the world that may not have applied the patch till now.<\/p>\n<p>So how to determine if your website&#8217;s allright?<\/p>\n<p>Open the Heartbleed check site and enter the URL of the site to be checked in the form of <strong>https:\/\/&lt;yourURL&gt;<\/strong><\/p>\n<p>If the result is this (checked https:\/\/auvito.ru for example):<\/p>\n<p><a href=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-explained_03.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-6099\" alt=\"heartbleed-explained_03\" src=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-explained_03-624x480.png\" width=\"624\" height=\"480\" srcset=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-explained_03-624x480.png 624w, https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-explained_03-768x590.png 768w, https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-explained_03.png 1094w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/a><\/p>\n<p>&#8230;it means your website is vulnerable and affected by the bug and you&#8217;re now in charge to update your OpenSSL version as soon as possible!<\/p>\n<p>And if you get this:<\/p>\n<p><a href=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-explained_01.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-6100\" alt=\"heartbleed-explained_01\" src=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-explained_01-640x392.png\" width=\"640\" height=\"392\" \/><\/a><\/p>\n<p>&#8230;then all should be fine (yet it&#8217;s a good idea to update to the newest OpenSSL version if it hasn&#8217;t been done since!<\/p>\n<p>But what exactly does the exploit do? Symantec has made a very clear and short description:<\/p>\n<p><a href=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-explained_02.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6101\" alt=\"heartbleed-explained_02\" src=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-explained_02.png\" width=\"600\" height=\"1299\" srcset=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-explained_02.png 600w, https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed-explained_02-222x480.png 222w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>The malicious client sends a heartbeat request which should be usually less than 1KB in size however the header of the request asks for the first 64KB(!) of the server data.<\/p>\n<p>The server then collects the first 64KB of the momory and encapsulates it into the heartbeat request.<\/p>\n<p><a href=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6098\" alt=\"heartbleed\" src=\"https:\/\/blog.netspark.de\/wp-content\/uploads\/2014\/04\/heartbleed.png\" width=\"341\" height=\"413\" \/><\/a><\/p>\n<p>Last, the client unpacks the heartbeat request and has now access to the 64KB of data sent back. Either you&#8217;re in luck and the memory content in the first 64KB was just garbage which ain&#8217;t of much interest or the client got sensitive information such as stored, unencrypted passwords or other secure information. The most mean thing about the heartbleed exploit is, that a server operator won&#8217;t notice traces!<\/p>\n<p>And what can you do as the end user?<\/p>\n<p>If you&#8217;re serious about your privacy, you can check your sites using SSL and check them with the heartbleed test if they&#8217;re vulnerable. If so, consider not using that site until they fix the exploit!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since the leak got public, every IT service provider is going crazy about the heartbleed bug that is active with OpenSSL 1.0.1 to 1.0.1f. But what exactly makes the heartbleed bug so dangerous? This website has com- prehensive information available for those running OpenSSL.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[55,4,3],"tags":[660,2372,2788,1071,317,2787,2789],"class_list":["post-6097","post","type-post","status-publish","format-standard","hentry","category-computer-2","category-curiosities","category-news","tag-attack","tag-exploit","tag-heartbleed","tag-leak","tag-memory","tag-openssl","tag-unsecure"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.netspark.de\/index.php?rest_route=\/wp\/v2\/posts\/6097","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.netspark.de\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.netspark.de\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.netspark.de\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.netspark.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6097"}],"version-history":[{"count":0,"href":"https:\/\/blog.netspark.de\/index.php?rest_route=\/wp\/v2\/posts\/6097\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.netspark.de\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6097"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.netspark.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6097"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.netspark.de\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6097"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}