home.social

#heartbleed — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #heartbleed, aggregated by home.social.

fetched live
  1. CVE-2014-0160 Heartbleed exploit using OpenSSL s_client with -tlsextdebug flag to extract up to 64KB of server heap memory per heartbeat request. Tested on Ubuntu 22.04, Debian 12, Kali Linux. #cve #heartbleed #ValtersIT

    valtersit.com/vault/cve2014016

  2. Exploit Heartbleed (CVE-2014-0160) with OpenSSL s_client: send a malformed heartbeat request with oversized payload length to extract up to 64KB of heap memory. Use -no_ssl3 -no_tls1 for TLS 1.0/1.1, -msg to capture leaked data. #cve #snippet #heartbleed #cve-2014-0160 #ValtersIT

    valtersit.com/vault/heartbleed

  3. “Wie alt bin ich", #kritis Edition

    Weißt du, wo du warst bei
    - #Heartbleed
    - #log4j
    - #gsmr Ausfall 1
    - #gsmr Ausfall 2
    - #WannaCry
    - #solarWinds
    - #NotPetya
    ?

    Zähle deine “Ja”-Antworten und du erfährst dein biologisches Alter:

    (0-1) frische 16
    (2-4) junge 25
    (4-6) bedenkliche 42
    (7) oh oh..

  4. @carlamelee @AwetTesfaiesus
    Volle Zustimmung zur literarischen Knoblauchsauce! Letztens erklären wollen wieso ich zu #FOSS beitrage, zusammenfassung war: weil es mir wichtig ist. Mehr Motivationen wären wichtig, insbesondere wenn jetzt die Aufmerksamkeit steigt und der öffentliche Diskurs in diese Richtung gehen soll, wäre zumindest eine Anerkennung der Gemeinnützigkeit sinnvoll.

    Eigentlich hätte uns bei #heartbleed schonmal auffallen müssen, dass freie Software gefördert werden muss (1v2)

  5. @carlamelee @AwetTesfaiesus
    Volle Zustimmung zur literarischen Knoblauchsauce! Letztens erklären wollen wieso ich zu #FOSS beitrage, zusammenfassung war: weil es mir wichtig ist. Mehr Motivationen wären wichtig, insbesondere wenn jetzt die Aufmerksamkeit steigt und der öffentliche Diskurs in diese Richtung gehen soll, wäre zumindest eine Anerkennung der Gemeinnützigkeit sinnvoll.

    Eigentlich hätte uns bei #heartbleed schonmal auffallen müssen, dass freie Software gefördert werden muss (1v2)

  6. Thinking about #InfoSec organizational behaviors derived from cognitive bias. In particular, availability bias from things that are memorable.

    #Log4j #Heartbleed #SolarWinds #ShellShock #Spectre #Meltdown #SQLSlammer

  7. Thinking about #InfoSec organizational behaviors derived from cognitive bias. In particular, availability bias from things that are memorable.

    #Log4j #Heartbleed #SolarWinds #ShellShock #Spectre #Meltdown #SQLSlammer

  8. CitrixBleed II – kolejny błąd powodujący, że serwer zwraca więcej danych niż powinien

    Większość naszych Czytelników zapewne kojarzy krytyczną podatność OpenSSL – Heartbleed, która stała się niemal książkowym przykładem błędu, który dotyka bardzo szerokiego grona użytkowników. Za sprawą błędnej obsługi rozmiaru przesyłanego bufora w nowo dodanym rozszerzeniu TLS/DTLS Heartbeat, możliwe było zdalne odczytanie aż do 64k bajtów pamięci klienta lub serwera. Zdarzało się,...

    #WBiegu #Citrix #Heartbleed #Netscaler #OutOfBoundRead #Podatność

    sekurak.pl/citrixbleed-ii-kole

  9. CitrixBleed II – kolejny błąd powodujący, że serwer zwraca więcej danych niż powinien

    Większość naszych Czytelników zapewne kojarzy krytyczną podatność OpenSSL – Heartbleed, która stała się niemal książkowym przykładem błędu, który dotyka bardzo szerokiego grona użytkowników. Za sprawą błędnej obsługi rozmiaru przesyłanego bufora w nowo dodanym rozszerzeniu TLS/DTLS Heartbeat, możliwe było zdalne odczytanie aż do 64k bajtów pamięci klienta lub serwera. Zdarzało się,...

    #WBiegu #Citrix #Heartbleed #Netscaler #OutOfBoundRead #Podatność

    sekurak.pl/citrixbleed-ii-kole

  10. How to make #opensource #software more secure
    The #xz attack, which followed other well-known cybersecurity incidents involving open source software like #Heartbleed, #Shellshock, and #Log4j, was another stark reminder that open source software, given how widespread it is, can pose significant #security risks.  
    techcrunch.com/2024/11/01/how- #itsec

  11. How to make #opensource #software more secure
    The #xz attack, which followed other well-known cybersecurity incidents involving open source software like #Heartbleed, #Shellshock, and #Log4j, was another stark reminder that open source software, given how widespread it is, can pose significant #security risks.  
    techcrunch.com/2024/11/01/how- #itsec

  12. Als ich meinte, wir brauchen mal wieder richtige Bugs, meinte ich nicht dieses auf #Wish bestellte #Heartbleed

    jbp.io/2024/06/27/cve-2024-553

  13. Este parasitismo provoca precariedad, agotamiento y hartazgo en desarrolladores y lleva a problemas de seguridad global como #Heartbleed

    Por eso nuestras autoridades se plantean obligar a las BigTech a contribuir… ¡NO! Se plantean obligar a voluntarios a darles mantenimiento 🤯

  14. Este parasitismo provoca precariedad, agotamiento y hartazgo en desarrolladores y lleva a problemas de seguridad global como #Heartbleed

    Por eso nuestras autoridades se plantean obligar a las BigTech a contribuir… ¡NO! Se plantean obligar a voluntarios a darles mantenimiento 🤯

  15. Today marks the 10th anniversary of the #Heartbleed vulnerability in OpenSSL. It had the same ultimate root cause as recent #XZUtils backdoor incident. This underscores the importance of public funding to protect vital open source projects that underpin our internet infrastructure. Learn more: optimizedbyotto.com/post/what- #OpenSource #Security

  16. Today marks the 10th anniversary of the #Heartbleed vulnerability in OpenSSL. It had the same ultimate root cause as recent #XZUtils backdoor incident. This underscores the importance of public funding to protect vital open source projects that underpin our internet infrastructure. Learn more: optimizedbyotto.com/post/what- #OpenSource #Security

  17. Thinking a lot about the #xz backdoor this week. Almost exactly 10 years ago, I wrote this about the #Heartbleed attack and how we should do more to support #OSS, especially for important libraries. Sadly, almost all of what I wrote then is still relevant. web.archive.org/web/2014042013

  18. Thinking a lot about the #xz backdoor this week. Almost exactly 10 years ago, I wrote this about the #Heartbleed attack and how we should do more to support #OSS, especially for important libraries. Sadly, almost all of what I wrote then is still relevant. web.archive.org/web/2014042013

  19. À quelques jours près, la découverte du code malicieux de #xz coïncide avec la découverte de #HeartBleed avec 10 ans d'écart. 🥳

    (J'ai l'impression que les choses n'ont pas tellement évoluée depuis 😓)

  20. À quelques jours près, la découverte du code malicieux de #xz coïncide avec la découverte de #HeartBleed avec 10 ans d'écart. 🥳

    (J'ai l'impression que les choses n'ont pas tellement évoluée depuis 😓)

  21. The important role #OpenSSL plays in securing the Internet has never been matched by the financial resources devoted to maintaining it.
    The open source #cryptographic #software library secures hundreds of thousands of Web servers and many products sold by multi-billion-dollar companies,
    but it operates on a shoestring budget.
    OpenSSL Software Foundation President Steve Marquess wrote in a blog post last week that OpenSSL typically receives about $2,000 in donations a year
    and has just one employee who works full time on the open source code.

    Given that, perhaps we shouldn’t be surprised by the existence of #Heartbleed, a security flaw in OpenSSL that can expose user passwords and the private encryption keys needed to protect websites.

    OpenSSL’s bare-bones operations are in stark contrast to some other open source projects that receive sponsorship from corporations relying on their code.
    Chief among them is probably the #Linux operating system #kernel, which has a foundation with multiple employees and funding from HP, IBM, Red Hat, Intel, Oracle, Google, Cisco, and many other companies.
    Workers at some of these firms spend large amounts of their employers’ time writing code for the Linux kernel, benefiting everyone who uses it.
    That’s never been the case with OpenSSL, but the Linux Foundation wants to change that.
    ⭐️The foundation today is announcing a three-year initiative with at least $3.9 million to help under-funded open source projects⭐️
    —with OpenSSL coming first.
    Amazon Web Services, Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Qualcomm, Rackspace, and VMware have all pledged to commit 💥at least $100,000 a year for at least three years💥 to the “#Core #Infrastructure #Initiative,” Linux Foundation Executive Director Jim Zemlin told Ars.
    To be clear, the money will go to multiple open source projects
    —OpenSSL will get a portion of the funding but likely nowhere close to the entire $3.9 million.
    The initiative will identify important open source projects that need help in addition to OpenSSL.

    arstechnica.com/information-te

  22. The important role #OpenSSL plays in securing the Internet has never been matched by the financial resources devoted to maintaining it.
    The open source #cryptographic #software library secures hundreds of thousands of Web servers and many products sold by multi-billion-dollar companies,
    but it operates on a shoestring budget.
    OpenSSL Software Foundation President Steve Marquess wrote in a blog post last week that OpenSSL typically receives about $2,000 in donations a year
    and has just one employee who works full time on the open source code.

    Given that, perhaps we shouldn’t be surprised by the existence of #Heartbleed, a security flaw in OpenSSL that can expose user passwords and the private encryption keys needed to protect websites.

    OpenSSL’s bare-bones operations are in stark contrast to some other open source projects that receive sponsorship from corporations relying on their code.
    Chief among them is probably the #Linux operating system #kernel, which has a foundation with multiple employees and funding from HP, IBM, Red Hat, Intel, Oracle, Google, Cisco, and many other companies.
    Workers at some of these firms spend large amounts of their employers’ time writing code for the Linux kernel, benefiting everyone who uses it.
    That’s never been the case with OpenSSL, but the Linux Foundation wants to change that.
    ⭐️The foundation today is announcing a three-year initiative with at least $3.9 million to help under-funded open source projects⭐️
    —with OpenSSL coming first.
    Amazon Web Services, Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Qualcomm, Rackspace, and VMware have all pledged to commit 💥at least $100,000 a year for at least three years💥 to the “#Core #Infrastructure #Initiative,” Linux Foundation Executive Director Jim Zemlin told Ars.
    To be clear, the money will go to multiple open source projects
    —OpenSSL will get a portion of the funding but likely nowhere close to the entire $3.9 million.
    The initiative will identify important open source projects that need help in addition to OpenSSL.

    arstechnica.com/information-te

  23. @Bibobu

    Le pire, c'est que le débat autour des petits projets extrêmement utilisés et pourtant complètement sous-financés avait déjà eu lieu plusieurs fois ces dernières années, à la suite de failles mémorables telles que #Heartbleed.

    Sauf que ça s'agite un peu sur le moment, ça créé divers fonds pour financer le libre, mais une fois la tempête passée, on en entend plus parler et rien ne change ☹️

    next.ink/4883/cybersecurite-et

    #Linux #logiciellibre #FOSS #cybersecurity

  24. @Bibobu

    Le pire, c'est que le débat autour des petits projets extrêmement utilisés et pourtant complètement sous-financés avait déjà eu lieu plusieurs fois ces dernières années, à la suite de failles mémorables telles que #Heartbleed.

    Sauf que ça s'agite un peu sur le moment, ça créé divers fonds pour financer le libre, mais une fois la tempête passée, on en entend plus parler et rien ne change ☹️

    next.ink/4883/cybersecurite-et

    #Linux #logiciellibre #FOSS #cybersecurity

  25. #Heartbleed was caused by a memory safety issue, friends, not by inexperienced programmers or an integration team that lacks basic scrutiny.

  26. #Heartbleed was caused by a memory safety issue, friends, not by inexperienced programmers or an integration team that lacks basic scrutiny.

  27. @lauren @djb

    All in all, this seems like another wildly overblown security vulnerability #publicity tour. I'm only shocked it doesn't have its own website and professional logo like "#shellshock" or "#heartbleed".

    Signed,

    Long time qmail guy & #internet #mail #infrastructure consultant

    5/5

    #PRStunt #security #vulnerability #researcher #report #PR #stunt

  28. @lauren @djb

    All in all, this seems like another wildly overblown security vulnerability #publicity tour. I'm only shocked it doesn't have its own website and professional logo like "#shellshock" or "#heartbleed".

    Signed,

    Long time qmail guy & #internet #mail #infrastructure consultant

    5/5

    #PRStunt #security #vulnerability #researcher #report #PR #stunt

  29. CW: Long thread/36

    But as open source projects have learned the hard way, the fact that anyone *can* audit your widely used, high-stakes code doesn't mean that anyone *will*.

    The #Heartbleed vulnerability in #OpenSSL was a wake-up call for the open source movement - a bug that endangered every secure webserver connection in the world, which had hidden in plain sight for years.

    36/

  30. Etwas früh dran zum runden Jubiläum hat K2 jetzt #Heartbleed Gedächtnisturnschuhe. 😍 de.m.wikipedia.org/wiki/Heartb

  31. @dekkzz76 The argument is not that #opensource means 100% secure & proven code.

    The argument is that closed source can't be checked by interested parties.

    So #FOSS has a chance to be checked. Closed source can't be checked.

    The fact that #heartbleed was detected & fixed in a short-term period is actually a great argument for FOSS. If #OpenSSL had been closed source, we probably would still run insecure code all over the world because of this issue without noticing except maybe some bad guys.

  32. Firmen sollten sich nicht auf ihren Spenden an Open-Source-Communities ausruhen, fordert Josep Prat: Sie wissen oft gar nicht, wie abhängig sie von ihnen sind.
    Drei Fragen und Antworten: Bei Open Source mit anpacken, nicht nur spenden