Results 1 to 9 of 9

Thread: The Heartbleed Bug

  1. #1
    Join Date
    Jan 1970
    Location
    33º 29' S 150º 13'30" E
    Posts
    1,148
    Total Downloaded
    0

    "Heartbleed" security problems

    Heard about this over the past few days? Apparently, all the secure websites (Banking, Auction/Paypal, email, etc) we've all been using safely with the knowledge that https (little padlock icon) is a secure site, is wrong!


    What the "Heartbleed" Security Bug Means For You

  2. #2
    Join Date
    Feb 2007
    Location
    Perth
    Posts
    3,919
    Total Downloaded
    0
    Some of the Australian major banks and other financial institutions (PayPal) have reportedly come out and said they are not affected, one actually confirming they do not use 'open SSL'.

    Have Australian websites staunched "catastrophic" Heartbleed risk?
    2024 RRS on the road
    2011 D4 3.0 in the drive way
    1999 D2 V8, in heaven
    1984 RRC, in hell

  3. #3
    Join Date
    Dec 2007
    Location
    South East Tasmania
    Posts
    10,705
    Total Downloaded
    0

    The Heartbleed Bug

    Interesting reading about a headache for the cyber security people.

    The Heartbleed Bug: Are you at risk?

    Diagnosis of the OpenSSL Heartbleed Bug

  4. #4
    jemsa Guest
    It's hell for a lot of IT people - I know one of our work servers is offline until I have time to update OpenSSL (of course, it doesn't like me and doesn't want to update) - the majority of IT Sys Admins I know are having a hell of a time with it!

  5. #5
    Join Date
    Dec 2007
    Location
    South East Tasmania
    Posts
    10,705
    Total Downloaded
    0

  6. #6
    Join Date
    Dec 2006
    Location
    Barmera .SA.
    Posts
    1,841
    Total Downloaded
    0
    Oddly, this only affects systems running openssl, usually Linux\BSD type operating systems and a great deal of open source software runs it too.
    Those who use Windows Server and MSSSL are fine, of course if you are running a Linux VM in your win server, watch out.

  7. #7
    NavyDiver's Avatar
    NavyDiver is online now Very Very Lucky! Gold Subscriber
    Join Date
    Feb 2010
    Location
    Melbourne
    Posts
    10,268
    Total Downloaded
    0
    what about http://www.aulro.com/ is it affected like Yahoo, Google, Facebook........

  8. #8
    Join Date
    Apr 2002
    Location
    Godwin Beach 4511
    Posts
    20,694
    Total Downloaded
    32.38 MB
    Quote Originally Posted by weakestlink View Post
    what about http://www.aulro.com/ is it affected like Yahoo, Google, Facebook........
    Is fine

    It only affects certain versiobs of openssl not all btw
    2007 Discovery 3 SE7 TDV6 2.7
    2012 SZ Territory TX 2.7 TDCi

    "Make the lie big, make it simple, keep saying it, and eventually they will believe it." -- a warning from Adolf Hitler
    "If you don't have a sense of humour, you probably don't have any sense at all!" -- a wise observation by someone else
    'If everyone colludes in believing that war is the norm, nobody will recognize the imperative of peace." -- Anne Deveson
    “What you leave behind is not what is engraved in stone monuments, but what is woven into the lives of others.” - Pericles
    "We can ignore reality, but we cannot ignore the consequences of ignoring reality.” – Ayn Rand
    "The happiness of your life depends upon the quality of your thoughts." Marcus Aurelius

  9. #9
    Join Date
    Nov 2008
    Location
    Maudsland, QLD
    Posts
    260
    Total Downloaded
    0
    All our serious production servers are Red Hat, and use openSSL -

    HOWEVER its only the very latest open SSL that has the issue. The nature of Red Hat being older stable versions software means all of our servers are running the older unaffected version.

    The first affected version shipped with RHEL 6.5 (RHEL 6.4 and older shipped with the unaffected openssl-1.0.0 series). Systems which report as RHEL 6.0 - 6.3 could still have been updated to a newer [vulnerable] openssl-1.0.1 series package.

    Luckily for me, I had not patched to the newer affected version.

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Search AULRO.com ONLY!
Search All the Web!