![]() |
|
Heartbleed Bug - What it is & How it Affects us - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: Heartbleed Bug - What it is & How it Affects us (/Thread-Heartbleed-Bug-What-it-is-How-it-Affects-us) |
Heartbleed Bug - What it is & How it Affects us - Equinox - 04-12-2014 What is it? If you don't know about heartbleed, kill yourself. But since you're probably reading this because you don't know what heartbleed is, kill yourself afterwards. As of lately, there's been talk of a new bug with OpenSSL. Heartbleed. Heartbleed obtains all data, requests, etc. through OpenSSL. Only a few versions are affected by heartbleed, but these few can really fuck us up if the webmaster, server, whoever setup OpenSSL uses a certain version. Here's all the versions of OpenSSL that are affected by Heartbleed.
As of OpenSSL version 1.0.1g, heartbleed has been fixed. How Does this Affect us? This is not how it affects Sinisterly. Sinisterly is covered by CloudFlare, and CloudFlare obtained news about heartbleed a week before it really struck us all, and to top it all, they already fixed it. So if we were running a vulnerable version, no need to fear, we're good. In any case, how will this bug affect us, users of the internet? Heartbleed leaks information such as login usernames, passwords, etc. If you registered on a site with OpenSSL, and a vulnerable version of it, don't be surprised if your account, or even the entire website, has been compromised. Talk of the NSA has it high waters. People have been stating that heartbleed has been used by the NSA, before it even came about. Using heartbleed to obtain all personal information, etc. Why? This seems like something the NSA would do. Do I believe the NSA did in-fact use it? I've no sure answer, as I don't know much about the subject, and while I'm not denying it, I will say no, they're not using it. There's no sure answer, that I've found, but the NSA has many, many, many ways of getting information without this bug. I highly doubt that out of their thousands of ways to grab you by the balls, they'd use heartbleed. The information provided was from a few articles that I've read online. If you have questions, commments, etc., leave them below. If you want to know about heartbleed itself and how to do it, I do not know. Google that sort of thing. ~Duubz RE: Heartbleed Bug - What it is & How it Affects us - DarkMuse - 04-12-2014 Good post Duubs. A for effort
RE: Heartbleed Bug - What it is & How it Affects us - Adorapuff - 04-12-2014 To be fair, the NSA spends $25,000,000 a year on 0days, so if they did have Heartblead I wouldn't be too surprised. People say they have had their servers being owned by unkown vulnerabilities that logging pin-pointed to OpenSLL, but they couldn't get much further as there was no public info about the exploit, so this exploit has been around and used before the whitehats released it causing unnecessary commotion. RE: Heartbleed Bug - What it is & How it Affects us - Reiko - 04-12-2014 Several issues: sinister.ly is NOT covered by CloudFlare because CloudFlare licks cock and butt sinister.ly NEVER ran a vulnerable version of OpenSSL and thus was NEVER affected If you're vigilant you already took care of anything that affected you days ago. RE: Heartbleed Bug - What it is & How it Affects us - Equinox - 04-12-2014 (04-12-2014, 08:00 AM)Starfall Wrote: Several issues: Sinisterly has CloudFlare... RE: Heartbleed Bug - What it is & How it Affects us - OversouL - 04-12-2014 (04-12-2014, 05:20 AM)Adorapuff Wrote: To be fair, the NSA spends $25,000,000 a year on 0days, so if they did have Heartblead I wouldn't be too surprised. People say they have had their servers being owned by unkown vulnerabilities that logging pin-pointed to OpenSLL, but they couldn't get much further as there was no public info about the exploit, so this exploit has been around and used before the whitehats released it causing unnecessary commotion. $25,000,000? O.o, where did you read about this? (04-12-2014, 08:19 AM)Duubz Wrote: Sinisterly has CloudFlare... Uhhm, I think Oni uses a different one. He said it before. RE: Heartbleed Bug - What it is & How it Affects us - Equinox - 04-12-2014 (04-12-2014, 08:40 AM)OversouL Wrote: $25,000,000? O.o, where did you read about this? Ngix is our engine. Just so you know. And I know for a fact SL has CloudFlare because the one day we kept getting hit off, before SSL, was because some kid got a stresser account. Nub. RE: Heartbleed Bug - What it is & How it Affects us - Reiko - 04-12-2014 50.49.245.198.in-addr.arpa domain name pointer ks4000946.ip-198-245-49.net. does not look like CloudFlare to me. Looks like OVH, a reputable, respectable service provider for people who know how to manage their own services and don't need CloudFlare. Maybe you should do basic research before talking? The only CloudFlare infrastructure that sinister.ly uses is their nameservers, and honestly it could do well without those too. Code: sinister.ly. IN NS
;; ANSWER SECTION:
sinister.ly. 21599 IN NS zara.ns.cloudflare.com.
sinister.ly. 21599 IN NS greg.ns.cloudflare.com.RE: Heartbleed Bug - What it is & How it Affects us - Equinox - 04-12-2014 (04-12-2014, 09:36 AM)Starfall Wrote: The only CloudFlare infrastructure that sinister.ly uses is their nameservers, and honestly it could do well without those too. Is there really any other way to use CloudFlare? ![]() I don't even use anything but their nameservers. RE: Heartbleed Bug - What it is & How it Affects us - w00t - 04-12-2014 I'm not sure how using cloudflare somehow mitigates sinister.ly's vulnerability. Whether or not cloudflare knew about the exploit a week ago is irrelevant, as the bug is years old. |