SliTaz SliTaz Forum

You are not logged in.

#1 2014-04-09 18:19:44

Guest
Guest

OpenSSL compromised

According to another website I frequent, OpenSSL has had a security hole for a couple of years(?).

Quote:

Just heard on BBC news that the Secure Sockets Layer encryption has been breached and that logging on to things like your bank can give your password to criminals. DO NOT go on to change your passwords as this will still allow them to get in later.

STAY away from any site you have to use a password for that you don't want anyone to get into - like your bank.

This is not a scare but seems genuine.

http://www.bbc.co.uk/news/technology-26954540

http://www.huffingtonpost.com/2014/04/08/heartbleed-66-percent_n_5112793.html

http://www.gizmodo.co.uk/2014/04/heartbleed-why-the-internets-gaping-security-hole-is-so-scary/

[/quote]

#2 2014-04-09 18:31:11

sixofeight
Member
Registered: 2013-07-02
Posts: 234

Re: OpenSSL compromised

What versions of the OpenSSL are affected?

Status of different versions:

    OpenSSL 1.0.1 through 1.0.1f (inclusive) are vulnerable

    OpenSSL 1.0.1g is NOT vulnerable

    OpenSSL 1.0.0 branch is NOT vulnerable

    OpenSSL 0.9.8 branch is NOT vulnerable

Bug was introduced to OpenSSL in December 2011

and has been out in the wild since OpenSSL release 1.0.1 on 14th of March 2012.

OpenSSL 1.0.1g released on 7th of April 2014 fixes the bug.

http://heartbleed.com/

https://www.openssl.org/

Offline

#3 2014-04-09 18:47:04

mojo
Administrator
Registered: 2011-03-29
Posts: 2,174

Re: OpenSSL compromised

Heartbleed test for servers :

http://filippo.io/Heartbleed/

http://possible.lv/tools/hb/

Offline

Registered users online in this topic: 0, guests: 1
[Bot] ClaudeBot

Board footer

Powered by FluxBB
Modified by Visman

[ Generated in 0.017 seconds, 8 queries executed - Memory usage: 1.53 MiB (Peak: 1.77 MiB) ]