Login Register






Heartbleed Bug filter_list
Author
Message
Heartbleed Bug #1
Hey guys, i thought that you should all know about this new bug called 'heartbleed'. It is a vulnerability on openSSL and apparently it makes it possible for anyone to eavesdrop on encrypted sites and access sensitive data without leaving a trace. Even the Tor Project blog themselves said "If you need strong anonymity or privacy on the Internet, you might want to stay away from the Internet entirely for the next few days while things settle,". This has been going on for a few days now. There is even a website on it: http://heartbleed.com/ Stay safe!

Reply

RE: Heartbleed Bug #2
does it also bypass things like surveys?

Reply

RE: Heartbleed Bug #3
I don't exactly know the details but I'm sure that most websites have patched this up by now. Here's a thread made by alok9shm http://www.hackcommunity.com/Thread-The-HeartBleed-Bug which explains how it works.

Reply

RE: Heartbleed Bug #4
(04-30-2014, 08:34 PM)shayuken Wrote: does it also bypass things like surveys?

No, it does not. It allows you to send a HeartBeat request and even receive one in return when doing so.

Check out this comic, it explains it pretty well:

Spoiler:
[Image: heartbleed_explanation.png]



If you want to learn more, I'd suggest checking out @alok9shm's thread. Best of luck to you!

Reply

RE: Heartbleed Bug #5
i hope this virus isnt going to affect many hosting out there

Reply

RE: Heartbleed Bug #6
@kallysky, Heartbleed is a BUG in some versions of OpenSSL. By no means is it a virus.

And people should be fine as long as they have updated OpenSSL to the latest version available since they have already fixed this issue.

Reply

RE: Heartbleed Bug #7
It's a sneaky-ass little backdoor that's affected a good 2/3rds of the internet. As far as I know, it's entirely unfixable.
It's often the outcasts, the iconoclasts ... those who have the least to lose because they
don't have much in the first place, who feel the new currents and ride them the farthest.

Reply

RE: Heartbleed Bug #8
I'm going to have to disagree with your statement, @"Lorax". As I said before, it's just a flaw in the code of some versions of OpenSSL. By no means is it a backdoor. Not to mention that OpenSSL has already solved this issue by releasing a fixed version.

Reply

RE: Heartbleed Bug #9
(05-02-2014, 03:07 PM)Lorax Wrote: It's a sneaky-ass little backdoor that's affected a good 2/3rds of the internet. As far as I know, it's entirely unfixable.

Its very fixable, there was a patch before it was even publicly announced.

The fix: http://pastebin.com/5PP8JVqA

Code:
hbtype = *p++; n2s(p, payload); pl = p;

n2s grabs 2 bytes from p and places tehm into payload. Those two bytes are the user-supplied size of the payload. Which is then used to copy the the data from the heartbeat request into the response payload(the heartbeat is basically just supposed to echo w/e the user inputs)

Code:
memcpy(bp, pl, payload);
bp is the output buffer, pl is the original input payload, and payload is the result 2 bytes after the hbtype in the original request(the user-supplied size)

So it copies a user-supplied number of bytes from the original payload into the new payload. In the attack a user supplies a size larger than what they actually input causeing memory to be copied from the following blocks of memory beyond their own input.

--------------

So the fix, is pretty simple. Just check that the user-supplied input is not larger than the supplied payload length.

Code:
if (1 + 2 + 16 > s->s3->rrec.length) return 0; /* silently discard */ hbtype = *p++; n2s(p, payload); if (1 + 2 + payload + 16 > s->s3->rrec.length) return 0; /* silently discard per RFC 6520 se pl = p;

First line is just a minimum bounds check to ensure the payload that was recieved is atleast the min length to work with.
Next is grabs teh request type as before
Followed by the user-supplied size
Now the main fix is that it checks if the user-supplied size againsts the actual record length that was read in. If the user-supplied size is greater than the actual size is drops the packet.
Rest of the code remains the same.

See that fix wasn't very hard ^_^

Reply

RE: Heartbleed Bug #10
My website was using one of the affected versions of OpenSSL. Had to fix it real quick.

Reply