![]() |
|
Heartbleed Bug - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Computers (https://sinister.li/Forum-Computers) +--- Forum: Antivirus & Protection (https://sinister.li/Forum-Antivirus-Protection) +--- Thread: Heartbleed Bug (/Thread-Heartbleed-Bug) |
Heartbleed Bug - Idyll - 04-12-2014 Hey guys, i thought that you should all know about this new bug called 'heartbleed'. It is a vulnerability on openSSL and apparently it makes it possible for anyone to eavesdrop on encrypted sites and access sensitive data without leaving a trace. Even the Tor Project blog themselves said "If you need strong anonymity or privacy on the Internet, you might want to stay away from the Internet entirely for the next few days while things settle,". This has been going on for a few days now. There is even a website on it: http://heartbleed.com/ Stay safe! RE: Heartbleed Bug - shayuken - 04-30-2014 does it also bypass things like surveys? RE: Heartbleed Bug - Idyll - 05-01-2014 I don't exactly know the details but I'm sure that most websites have patched this up by now. Here's a thread made by alok9shm http://www.hackcommunity.com/Thread-The-HeartBleed-Bug which explains how it works. RE: Heartbleed Bug - Spirit - 05-01-2014 (04-30-2014, 08:34 PM)shayuken Wrote: does it also bypass things like surveys? No, it does not. It allows you to send a HeartBeat request and even receive one in return when doing so. Check out this comic, it explains it pretty well: Spoiler:![]() If you want to learn more, I'd suggest checking out @alok9shm's thread. Best of luck to you! RE: Heartbleed Bug - kallysky - 05-01-2014 i hope this virus isnt going to affect many hosting out there RE: Heartbleed Bug - Spirit - 05-01-2014 @kallysky, Heartbleed is a BUG in some versions of OpenSSL. By no means is it a virus. And people should be fine as long as they have updated OpenSSL to the latest version available since they have already fixed this issue. RE: Heartbleed Bug - Inori - 05-02-2014 It's a sneaky-ass little backdoor that's affected a good 2/3rds of the internet. As far as I know, it's entirely unfixable. RE: Heartbleed Bug - Spirit - 05-02-2014 I'm going to have to disagree with your statement, @"Lorax". As I said before, it's just a flaw in the code of some versions of OpenSSL. By no means is it a backdoor. Not to mention that OpenSSL has already solved this issue by releasing a fixed version. RE: Heartbleed Bug - dropzon3 - 05-02-2014 (05-02-2014, 03:07 PM)Lorax Wrote: It's a sneaky-ass little backdoor that's affected a good 2/3rds of the internet. As far as I know, it's entirely unfixable. Its very fixable, there was a patch before it was even publicly announced. The fix: http://pastebin.com/5PP8JVqA Code: hbtype = *p++;
n2s(p, payload);
pl = p;n2s grabs 2 bytes from p and places tehm into payload. Those two bytes are the user-supplied size of the payload. Which is then used to copy the the data from the heartbeat request into the response payload(the heartbeat is basically just supposed to echo w/e the user inputs) Code: memcpy(bp, pl, payload);So it copies a user-supplied number of bytes from the original payload into the new payload. In the attack a user supplies a size larger than what they actually input causeing memory to be copied from the following blocks of memory beyond their own input. -------------- So the fix, is pretty simple. Just check that the user-supplied input is not larger than the supplied payload length. Code: if (1 + 2 + 16 > s->s3->rrec.length)
return 0; /* silently discard */
hbtype = *p++;
n2s(p, payload);
if (1 + 2 + payload + 16 > s->s3->rrec.length)
return 0; /* silently discard per RFC 6520 se
pl = p;First line is just a minimum bounds check to ensure the payload that was recieved is atleast the min length to work with. Next is grabs teh request type as before Followed by the user-supplied size Now the main fix is that it checks if the user-supplied size againsts the actual record length that was read in. If the user-supplied size is greater than the actual size is drops the packet. Rest of the code remains the same. See that fix wasn't very hard ^_^ RE: Heartbleed Bug - cyborgamer - 05-02-2014 My website was using one of the affected versions of OpenSSL. Had to fix it real quick. |