Scramble to fix huge 'heartbleed' security bug

The researchers who discovered the bug publicised their findings via the web A bug in software used by millions of web servers could have exposed anyone visiting sites they hosted to spying and eavesdropping, say researchers. The bug is in a software library used in servers, operating systems and email and instant messaging systems. Called OpenSSL the software is supposed to protect sensitive data as it travels back and forth. It is not clear how widespread exploitation of the bug has been because attacks leave no trace. "If you need strong anonymity or privacy on the internet, you might want to stay away from the internet entirely for the next few days while things settle," said a blog entry about the bug published by the Tor Project which produces software that helps people avoid scrutiny of their browsing habits. 'Serious' vulnerability A huge swathe of the web could be vulnerable because OpenSSL is used in the widely used Apache and Nginx server software. Statistics from net monitoring firm Netcraft suggestthat about 500,000 of the web's secure servers are running versions of the vulnerable software. "It's the biggest thing I've seen in security since the discovery of SQL injection," said Ken Munro, a security expert at Pen Test Partners. SQL injection is a way to extract information from the databases behind web sites and services using specially crafted queries. Many firms were scrambling to apply patches to vulnerable programs and others had shut down services while fixes were being worked on, he said. Many were worried that with proof of concept code already being shared it would only be a matter of time before cyber thieves started exploiting the vulnerability. Mojang, maker of the hugely popular Minecraft game, took all its services offline while Amazon, which it uses to host games, patched its systems. The bug in OpenSSL was discovered by researchers working for Google and security firm Codenomicon. In a blog entry about their findings the researchers said the "serious vulnerability" allowed anyone to read chunks of memory in servers supposedly protected with the flawed version of OpenSSL. Via this route, attackers could get at the secret keys used to scramble data as it passes between a server and its users. "This allows attackers to eavesdrop [on] communications, steal data directly from the services and users and to impersonate services and users," wrote the team that discovered the vulnerability. They called it the "heartbleed" bug because it occurs in the heartbeat extension for OpenSSL. The bug has been present in versions of OpenSSL that have been available for over two years. The latest version of OpenSSL released on 7 April is no longer vulnerable to the bug. "Considering the long exposure, ease of exploitation and attacks leaving no trace this exposure should be taken seriously," wrote the researchers. Installing an updated version of OpenSSL did not necessarily mean people were safe from attack, said the team. If attackers have already exploited it they could have stolen encryption keys, passwords or other credentials required to access a server, they said. Full protection might require updating to the safer version of OpenSSL as well as getting new security certificates and generating new encryption keys. To help people check their systems some security researchers have produced tools that help people work out if they are running vulnerable versions of OpenSSL.

Comments

Anonymous said…
The typical age varirty is early 40's to mid 50's.


Also visit my webpage ... lifestyle lyrics youtube
Anonymous said…
Its lioke you read my mind! You seem to know so much aboit
this, like you wrote the book in itt or something.
I think that you could do with some pics to
drive the messae home a bit, but instead of that, this is fantastic blog.

A fantastic read.I will definitely be back.

Feel free to surf to myy weeb blog :: search engine optimization pricing ()
Anonymous said…
Whhat better gift can one particular pass down than the wish
to lead a healthy wayy of life and the enhanced hkgh quality of life that goes with it?



Here is my page; lifestyle blogs on blogger ()
Anonymous said…
Half the world's popupation access to the Internet now a
days.

Check out my web page :: search engine optimization google
Anonymous said…
The plan can turn vital preventative care into a productive and relaxing corporate
retreat.

my weblog ... lifestyle blogs for over 50s []
Anonymous said…
As wel as the greatest free cyclist is Alex Salmond, a male paid by the taxpayer to
shield the legal representative cost-free riders.


Here is my webpage Texas mesothelioma cancer
Anonymous said…
It tends to make us really feel taller to inbdignantly puff ourselvs up with outrage.


Here is my web bkog - lifestyle blkogs chicago; ,
Anonymous said…
The a lot more reliant I turn into on the internet, the far more concerrned I turn into about privacy.



Feel free to visit my blog post :: searc engine
optimization google ()
Anonymous said…
These tools let you too evaluate reputation as effectively as
brainstorm most clicked keywords and phrases by the buyers.


Allso visit my site search engine optimization companies in mumbai
Anonymous said…
There are some information to be worked out nevertheless, buut the effort now seems certain of achievement.
I count on our College to be the stronger for it.

Visit my page :: lifestyle rich gang
Anonymous said…
As the title implies, simple, genuine living is the
magazine's principal theme.

Here is my website; lifestyle lyrics youtube []
Anonymous said…
We make suggestions for expense powerful options created to minimize your liability exposures, losses and damages.


Here is my homepage golf netting material uk
Anonymous said…
I use They have a cost-free keyword tool that permits you to sort
a broad keyword phrase and itt provides you oone hundred
narrowed keywords.

My web site; search engine optimization definition english
Anonymous said…
Is it actually free?

Visit my webpage - make money online fast and easy paypal
Anonymous said…
A: Dallas mesothelioma settlement cancer is generally
dued to asbestos fibers tht get stuck in lungs aas well as induce scarring.
Anonymous said…
search engine optimization tips wordpress engine optimization may
possibly soubd scary, but really it's not.
Anonymous said…
Sales Supervisor: The sales manager has a sales team under him, and
iis responsible for achieving sales targets via inspiration as well as guidance.


Heree is my weblolg email marketing strategy outline
Anonymous said…
Functioning online as a cokputer gaje tester is one off
the ways a multitude of young adults earn Make Money Online () online.
Anonymous said…
Infobarrel gives create a site lot of possibilites for freelance writers.
Anonymous said…
The top 10 techniques forr making bitcoins as well as various other digital
currencies, and more than 20 of tthe very best websktes to gaion digital
make money online teens.
Anonymous said…
A law firm focusing on mesothelioma asbestos Dallas TX, ,
cancer will certainly submit appropriate lawsuits for you to get
settlement that commonly covers a million dollars.
Anonymous said…
He iss remembered for his job that gave a new measurement to television.

My weblog ... Lifestyle In Texas
Anonymous said…
Mediocre markters believe in terms oof campaigns.


My website: internet marketing ninjas clients ()
Anonymous said…
You after that seee a couple of vital experriences during that life time,
Lifestyle In Texas () addition to the
death scene.
Anonymous said…
Think about using it the following time you are wanting to make money online fast a large
transaction.
Anonymous said…
Articles, ideas and techniques all inn 1 place!

Stop by my website :: internet marketing ninjas reviews
Anonymous said…
Take faar more vegetables and fruits and give significance too house cooking.



My webpage lifestype lift locations ()
Anonymous said…
After filing the claim, the mesothelioma lawyer louisiana casncer lawyer would call both
the events in the casee as well as the court exists.

Popular posts from this blog

First computer made of carbon nanotubes is unveiled.

2014 Prophecies By Dr. DK Olukoya Of MFM

A-Z Country Domain List Extensions