Sanctum Zone

Keyword
A+ A A-
Welcome, Guest
Username: Password: Remember me
  • Page:
  • 1

TOPIC: Massive security bug - Heartbleed

Massive security bug - Heartbleed 08 Apr 2014 14:21 #1

  • Quality Street
  • Quality Street's Avatar
  • ZONED OUT
  • Junior Boarder
  • Rank2
  • Posts: 402
  • Thank you received: 750
  • Karma: 0
https://www.bbc.co.uk/news/technology-26935905

This is a real big deal apparently.
Not up with the tech jargon myself but I wouldn't log into yahoo mail for the next day or two.
https://twitter.com/search?q=yahoo%20heartbleed&src=typd
Gmail and Hotmail are safe

Also if you use Lastpass to store passwords they are also vulnerable.
You must register to post here.
The following user(s) said Thank You: Space Bandit, SilvaRizla, 3point5, Wise Haven, scrappydoo

Massive security bug - Heartbleed 08 Apr 2014 14:50 #2

  • Quality Street
  • Quality Street's Avatar
  • ZONED OUT
  • Junior Boarder
  • Rank2
  • Posts: 402
  • Thank you received: 750
  • Karma: 0
If you want to know if any particular server is vulnerable you can test it here:

https://filippo.io/Heartbleed/

Put in yahoo.com and it comes up vulnerable.

This vulnerability has been out there for 2 years apparently.

More here: https://www.reddit.com/r/programming/comments/22ghj1/the_heartbleed_bug/
Last Edit: 08 Apr 2014 14:54 by Quality Street. Reason: added redit link
You must register to post here.
The following user(s) said Thank You: Wise Haven

Massive security bug - Heartbleed 08 Apr 2014 16:29 #3

  • Quality Street
  • Quality Street's Avatar
  • ZONED OUT
  • Junior Boarder
  • Rank2
  • Posts: 402
  • Thank you received: 750
  • Karma: 0
Just tested Indiegogo and its vulnerable.

https://filippo.io/Heartbleed/#indiegogo.com
You must register to post here.
The following user(s) said Thank You: Babs, Wise Haven

Massive security bug - Heartbleed 10 Apr 2014 06:03 #4

  • batou
  • batou's Avatar
  • ZONED OUT
  • Forum Facilitator
  • Rankmod
  • Premier Subscriber
  • Posts: 4480
  • Thank you received: 3847
  • Karma: 91
Hey Andy does this effect me in any way?
my limbless friend will die alone
a torso of flesh upon the throne

Violence is not the answer, it is the question. the answer is yes.
You must register to post here.

Massive security bug - Heartbleed 10 Apr 2014 07:47 #5

  • SilvaRizla
  • SilvaRizla's Avatar
  • ZONED OUT
  • Expert Boarder
  • Rank4
  • Erm, hiya :)
  • Posts: 1015
  • Thank you received: 867
  • Karma: 0
It effects everyone, it is incredibly serious.

It means that any "secure" server still vulnerable to this bug is in no way secure.

Using the exploit it is possible to dump (copy) a large portion of the servers memory, and depending on whats in the servers memory at the time determines how bad it is. Its bad for the server admins as it means a complete compromise for them but In practical terms for us, it is possible for attackers to steal your login info, your credit card info, read your emails, read PM's, everything you do on a vulnerable website and any information you have on there can be viewable/stealable. Its very serious indeed.

Check any site for vulnerability before logging in to it.
You must register to post here.
The following user(s) said Thank You: Quality Street

Massive security bug - Heartbleed 10 Apr 2014 10:04 #6

  • diforumreject
  • diforumreject's Avatar
  • ZONED OUT
  • Junior Boarder
  • Rank2
  • Posts: 113
  • Thank you received: 118
  • Karma: 0
While it is a serious bug, there are tons of vulnerabilities online and always have been. Essentially, if you have information stored online, or on a computer that that you use online, someone can get their paws on it if they want it bad enough. Drive by java exploits, trojans hidden in software/video downloads, phishing, xss injection attacks etc etc etc. Plus of course you have the ever popular employee fraud and negligence where your personal information is left on an unencrypted disc on the train :chuckle: Its a vulnerability for sure, but how many people do you know that had have their bank accounts emptied due to this vulnerability which has existed since 2012?
You must register to post here.

Massive security bug - Heartbleed 10 Apr 2014 12:37 #7

  • SilvaRizla
  • SilvaRizla's Avatar
  • ZONED OUT
  • Expert Boarder
  • Rank4
  • Erm, hiya :)
  • Posts: 1015
  • Thank you received: 867
  • Karma: 0
diforumreject wrote:
While it is a serious bug, there are tons of vulnerabilities online and always have been. Essentially, if you have information stored online, or on a computer that that you use online, someone can get their paws on it if they want it bad enough. Drive by java exploits, trojans hidden in software/video downloads, phishing, xss injection attacks etc etc etc. Plus of course you have the ever popular employee fraud and negligence where your personal information is left on an unencrypted disc on the train :chuckle: Its a vulnerability for sure, but how many people do you know that had have their bank accounts emptied due to this vulnerability which has existed since 2012?

I think you're blurring the lines here somewhat.

I like to make distinctions between social engineering based attacks, client/local exploitation and server exploitation. Server based attacks are by far the worst. You can't actually answer your question either. There may have been a great deal of incidents of fraud attributed to this exploit but the method of obtaining such info was never found.

There may have only been 100 serious incidents due to it, but 100 is enough and now that its in the wild and skids have gotten their hands on it, there will be much much more.
You must register to post here.

Massive security bug - Heartbleed 10 Apr 2014 12:59 #8

  • diforumreject
  • diforumreject's Avatar
  • ZONED OUT
  • Junior Boarder
  • Rank2
  • Posts: 113
  • Thank you received: 118
  • Karma: 0
SilvaRizla wrote:

I think you're blurring the lines here somewhat.
not really, I would say I'm just putting it into perspective
SilvaRizla wrote:
I like to make distinctions between social engineering based attacks, client/local exploitation and server exploitation. Server based attacks are by far the worst.
server based attacks have been around for years, how many sites get defaced, taken over using various techniques including xss injection on dbase driven websites? Answer = lots! Getting to the root on a server is one of the most popular attacks online, spammers use this for phishing, link building, hosting spam gateway pages and email blasts all the time. I know plenty of people that have experienced this, including me! This latest vulnerabilty is just another exploit, that is now mostly fixed.
SilvaRizla wrote:
There may have been a great deal of incidents of fraud attributed to this exploit but the method of obtaining such info was never found..
Ok I'll rephrase the question, this vulnerability has been around for 2 years now, how many people do you know that have had their bank accounts emptied but don't know the exact method used? My answer=none. Yes it happens, has always happened, probably will always happen. Just putting things into perspective.

check out this similar doom announcement 2 years ago
www.bbc.co.uk/news/technology-16812064

nothing new here
Last Edit: 10 Apr 2014 13:03 by diforumreject.
You must register to post here.

Massive security bug - Heartbleed 10 Apr 2014 13:47 #9

  • diforumreject
  • diforumreject's Avatar
  • ZONED OUT
  • Junior Boarder
  • Rank2
  • Posts: 113
  • Thank you received: 118
  • Karma: 0
In addition I would suggest the time to really panic about an exploit or vulnerability, is when a select few are using it to extract money from bank accounts while the online banking companies are scratching their heads wondering how they are doing it!

Once the exploit is splashed across the mainstream media worldwide and every IT bod in the universe knows about it and how to fix it, much less worrying, but a still good headline.
You must register to post here.

Massive security bug - Heartbleed 10 Apr 2014 13:58 #10

  • SilvaRizla
  • SilvaRizla's Avatar
  • ZONED OUT
  • Expert Boarder
  • Rank4
  • Erm, hiya :)
  • Posts: 1015
  • Thank you received: 867
  • Karma: 0
diforumreject wrote:
SilvaRizla wrote:

I think you're blurring the lines here somewhat.
not really, I would say I'm just putting it into perspective
SilvaRizla wrote:
I like to make distinctions between social engineering based attacks, client/local exploitation and server exploitation. Server based attacks are by far the worst.
server based attacks have been around for years, how many sites get defaced, taken over using various techniques including xss injection on dbase driven websites? Answer = lots! Getting to the root on a server is one of the most popular attacks online, spammers use this for phishing, link building, hosting spam gateway pages and email blasts all the time. I know plenty of people that have experienced this, including me! This latest vulnerabilty is just another exploit, that is now mostly fixed.
SilvaRizla wrote:
There may have been a great deal of incidents of fraud attributed to this exploit but the method of obtaining such info was never found..
Ok I'll rephrase the question, this vulnerability has been around for 2 years now, how many people do you know that have had their bank accounts emptied but don't know the exact method used? My answer=none. Yes it happens, has always happened, probably will always happen. Just putting things into perspective.

check out this similar doom announcement 2 years ago
www.bbc.co.uk/news/technology-16812064

nothing new here

I'd can't say I agree, for example the link you've posted would need to make use of either a drive-by or some form of social engineering or local exploit first. Its fairly straight forward to FUD the malware packaged with some illegal download. In other words, it would only affect those committing dodgy downloads, or those stupid enough to click on some dodgy a link in an email from some Thai bride or whatever.

This new vulnerability is server based only, its the biggest thing since SQLi and in a completely different league to your standard skids spreading RATs, or Ugandan Phishers. Some of the the most secure servers in the world are having their pants pulled down and its nothing that can be blamed on the end user.
You must register to post here.
The following user(s) said Thank You: Quality Street

Massive security bug - Heartbleed 10 Apr 2014 14:09 #11

  • SilvaRizla
  • SilvaRizla's Avatar
  • ZONED OUT
  • Expert Boarder
  • Rank4
  • Erm, hiya :)
  • Posts: 1015
  • Thank you received: 867
  • Karma: 0
diforumreject wrote:
In addition I would suggest the time to really panic about an exploit or vulnerability, is when a select few are using it to extract money from bank accounts while the online banking companies are scratching their heads wondering how they are doing it!

Once the exploit is splashed across the mainstream media worldwide and every IT bod in the universe knows about it and how to fix it, much less worrying, but a still good headline.

You mean say if you were sitting on a massive list of bank details that you might get from I don't know, the heartbleed bug, and all you had to do was wait until you'd figured out how to transfer/wash the money? Yeah thats pretty bad.

People won't empty entire bank accounts, they might take £1 from a million accounts though, wash them through some bitcoin servers and get them paid to their own account.

Yes its nothing to worry about at all.... :thumbup:
You must register to post here.

Massive security bug - Heartbleed 10 Apr 2014 14:16 #12

  • diforumreject
  • diforumreject's Avatar
  • ZONED OUT
  • Junior Boarder
  • Rank2
  • Posts: 113
  • Thank you received: 118
  • Karma: 0
SilvaRizla wrote:
diforumreject wrote:
In addition I would suggest the time to really panic about an exploit or vulnerability, is when a select few are using it to extract money from bank accounts while the online banking companies are scratching their heads wondering how they are doing it!

Once the exploit is splashed across the mainstream media worldwide and every IT bod in the universe knows about it and how to fix it, much less worrying, but a still good headline.

You mean say if you were sitting on a massive list of bank details that you might get from I don't know, the heartbleed bug, and all you had to do was wait until you'd figured out how to transfer/wash the money? Yeah thats pretty bad.

People won't empty entire bank accounts, they might take £1 from a million accounts though, wash them through some bitcoin servers and get them paid to their own account.

Yes its nothing to worry about at all.... :thumbup:

there is a big difference between my statement of "much less worrying", when categorising an exploit which has become well known, and your sarky "Yes its nothing to worry about at all" comment, as I am sure you know.

I stand by my statement, now this bug is known and being patched, it is definitely much less worrying.
You must register to post here.

Massive security bug - Heartbleed 10 Apr 2014 14:35 #13

  • SilvaRizla
  • SilvaRizla's Avatar
  • ZONED OUT
  • Expert Boarder
  • Rank4
  • Erm, hiya :)
  • Posts: 1015
  • Thank you received: 867
  • Karma: 0
diforumreject wrote:
SilvaRizla wrote:
diforumreject wrote:
In addition I would suggest the time to really panic about an exploit or vulnerability, is when a select few are using it to extract money from bank accounts while the online banking companies are scratching their heads wondering how they are doing it!

Once the exploit is splashed across the mainstream media worldwide and every IT bod in the universe knows about it and how to fix it, much less worrying, but a still good headline.

You mean say if you were sitting on a massive list of bank details that you might get from I don't know, the heartbleed bug, and all you had to do was wait until you'd figured out how to transfer/wash the money? Yeah thats pretty bad.

People won't empty entire bank accounts, they might take £1 from a million accounts though, wash them through some bitcoin servers and get them paid to their own account.

Yes its nothing to worry about at all.... :thumbup:

there is a big difference between my statement of "much less worrying", when categorising an exploit which has become well known, and your sarky "Yes its nothing to worry about at all" comment, as I am sure you know.

I stand by my statement, now this bug is known and being patched, it is definitely much less worrying.

Well it is less worrying yes, but its been unpatched for 2 years, would you notice if a quid went missing from your account? I bet people have made millions off this already
You must register to post here.

Massive security bug - Heartbleed 10 Apr 2014 15:37 #14

  • diforumreject
  • diforumreject's Avatar
  • ZONED OUT
  • Junior Boarder
  • Rank2
  • Posts: 113
  • Thank you received: 118
  • Karma: 0
SilvaRizla wrote:
diforumreject wrote:
SilvaRizla wrote:
diforumreject wrote:
In addition I would suggest the time to really panic about an exploit or vulnerability, is when a select few are using it to extract money from bank accounts while the online banking companies are scratching their heads wondering how they are doing it!

Once the exploit is splashed across the mainstream media worldwide and every IT bod in the universe knows about it and how to fix it, much less worrying, but a still good headline.

You mean say if you were sitting on a massive list of bank details that you might get from I don't know, the heartbleed bug, and all you had to do was wait until you'd figured out how to transfer/wash the money? Yeah thats pretty bad.

People won't empty entire bank accounts, they might take £1 from a million accounts though, wash them through some bitcoin servers and get them paid to their own account.

Yes its nothing to worry about at all.... :thumbup:

there is a big difference between my statement of "much less worrying", when categorising an exploit which has become well known, and your sarky "Yes its nothing to worry about at all" comment, as I am sure you know.

I stand by my statement, now this bug is known and being patched, it is definitely much less worrying.

Well it is less worrying yes, but its been unpatched for 2 years, would you notice if a quid went missing from your account? I bet people have made millions off this already

well it remains to be seen whether or nor people have been siphoning money from accounts using this exploit over the last 2 years, however, as yet I am struggling to find a single case of theft or fraud reported. What is more certain however, is now that the exploit is known, the threat is largely over, with banks patching the exploit and changing passwords etc if system was affected.

That scenario you posted about hackers stealing £1 from a million accounts to get £1million, I know that happened in a movie, but has it ever happened in real life? I cant find examples of that either, though it does sound familiar, but perhaps I am thinking of that movie:-) All the big frauds I have seen involved large unauthorised transfers from multiple accounts, not skimming a pound/dollar here and there.
You must register to post here.

Massive security bug - Heartbleed 10 Apr 2014 22:03 #15

  • andyh
  • andyh's Avatar
  • ZONED OUT
  • Platinum Boarder
  • Rank6
  • Posts: 10337
  • Thank you received: 3545
  • Karma: 62
There is no such thing as a secure computer unless you pull out the network cards and all the USB ports, weld the case shut and encrypt the hard drive with 2056bit encryption and prevent a human being from going anywhere near the keyboard :p lol.
“Fascists are not human. A snake is more human.” - Hugo Chávez
You must register to post here.
  • Page:
  • 1
Moderators: psketti, oioioi, batou
Time to create page: 0.190 seconds

Latest Members Blogs

  • 1
  • 2
  • 3
Prev Next

What is going on when it comes to 9-11 I…

The EPA (environmental protection agency) and OSHA took air samples in the days following September 11th, they reported that they found no excessive levels of asbestos contrary to other findings....

Read more

9-11 Eleven Years Later

9-11 Eleven Years Later

With the anniversary of September 11th literally just around the corner, unanswered questions still remain for families who lost loved ones during the tragic event, as well as from families...

Read more

Strange Noises, Possible Link to Mass An…

Strange Noises, Possible Link to Mass Animal Deaths

In 2008 the U.S. Supreme Court agreed to review a series of lower court rulings that restrict the United States Navy's use of sonar in submarine detection training exercises off...

Read more

Annual Server Target

Whether its 50 cents or five dollars, your donations are appreciated and help keep this community site running so we can all continue to enjoy using it.
This target is to meet our server cost for one year, June 2020 - May 2021, in USD.
$ 340 - Target
( £ 250 GBP )
donation thermometer
donation thermometer
$ 192 - Raised
( £ 140 GBP )
donation thermometer
56%
Most Recent Donation:
$122 USD on 4th Jan 2021
Bitcoin Address: bc1q0kazqya0nurfxtunxv807vm0m8852nnrrk8mj8
 
Ethereum Address: 0xe69915c80dd75df19f438d556267e04f932f057d
 
More Info: Donation options for TZ

No one is obliged to donate, please only donate what you can afford. Even the smallest amount helps. Being an active member is a positive contribution. Thank You.

TradeZone Latest

Visitors

Today827
Yesterday774
Week827
Month9810
Total1108234

Your IP Address: 216.73.217.123 Your Browser and OS: Unknown - Unknown Monday, 17 August 2026 20:43

Who Is Online

Guests : 248 guests online Members : No members online
© 2012 – 2021 Sanctum Zone | All rights reserved. This website is a place for people to express and discuss their views on the news and world events. DISCLAIMER: Please Note: Views expressed and submitted by contributors are their own personal opinions and do not necessarily reflect the views, opinions and beliefs of the Sanctum Zone website and its founder(s) , administrators , moderators , and any other website maintenance technicians, personnel and volunteers. Articles and messages posted on this website and forum are solely the opinion of their authors.

Login or Register

LOG IN

Register

User Registration
or Cancel