home.social

#heartbleed — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #heartbleed, aggregated by home.social.

fetched live
  1. CVE-2014-0160 Heartbleed exploit using OpenSSL s_client with -tlsextdebug flag to extract up to 64KB of server heap memory per heartbeat request. Tested on Ubuntu 22.04, Debian 12, Kali Linux. #cve #heartbleed #ValtersIT

    valtersit.com/vault/cve2014016

  2. Exploit Heartbleed (CVE-2014-0160) with OpenSSL s_client: send a malformed heartbeat request with oversized payload length to extract up to 64KB of heap memory. Use -no_ssl3 -no_tls1 for TLS 1.0/1.1, -msg to capture leaked data. #cve #snippet #heartbleed #cve-2014-0160 #ValtersIT

    valtersit.com/vault/heartbleed

  3. @carlamelee @AwetTesfaiesus
    Volle Zustimmung zur literarischen Knoblauchsauce! Letztens erklären wollen wieso ich zu #FOSS beitrage, zusammenfassung war: weil es mir wichtig ist. Mehr Motivationen wären wichtig, insbesondere wenn jetzt die Aufmerksamkeit steigt und der öffentliche Diskurs in diese Richtung gehen soll, wäre zumindest eine Anerkennung der Gemeinnützigkeit sinnvoll.

    Eigentlich hätte uns bei #heartbleed schonmal auffallen müssen, dass freie Software gefördert werden muss (1v2)

  4. Thinking about #InfoSec organizational behaviors derived from cognitive bias. In particular, availability bias from things that are memorable.

    #Log4j #Heartbleed #SolarWinds #ShellShock #Spectre #Meltdown #SQLSlammer

  5. CitrixBleed II – kolejny błąd powodujący, że serwer zwraca więcej danych niż powinien

    Większość naszych Czytelników zapewne kojarzy krytyczną podatność OpenSSL – Heartbleed, która stała się niemal książkowym przykładem błędu, który dotyka bardzo szerokiego grona użytkowników. Za sprawą błędnej obsługi rozmiaru przesyłanego bufora w nowo dodanym rozszerzeniu TLS/DTLS Heartbeat, możliwe było zdalne odczytanie aż do 64k bajtów pamięci klienta lub serwera. Zdarzało się,...

    #WBiegu #Citrix #Heartbleed #Netscaler #OutOfBoundRead #Podatność

    sekurak.pl/citrixbleed-ii-kole

  6. How to make #opensource #software more secure
    The #xz attack, which followed other well-known cybersecurity incidents involving open source software like #Heartbleed, #Shellshock, and #Log4j, was another stark reminder that open source software, given how widespread it is, can pose significant #security risks.  
    techcrunch.com/2024/11/01/how- #itsec

  7. Als ich meinte, wir brauchen mal wieder richtige Bugs, meinte ich nicht dieses auf #Wish bestellte #Heartbleed

    jbp.io/2024/06/27/cve-2024-553

  8. Este parasitismo provoca precariedad, agotamiento y hartazgo en desarrolladores y lleva a problemas de seguridad global como #Heartbleed

    Por eso nuestras autoridades se plantean obligar a las BigTech a contribuir… ¡NO! Se plantean obligar a voluntarios a darles mantenimiento 🤯

  9. Today marks the 10th anniversary of the #Heartbleed vulnerability in OpenSSL. It had the same ultimate root cause as recent #XZUtils backdoor incident. This underscores the importance of public funding to protect vital open source projects that underpin our internet infrastructure. Learn more: optimizedbyotto.com/post/what- #OpenSource #Security

  10. Thinking a lot about the #xz backdoor this week. Almost exactly 10 years ago, I wrote this about the #Heartbleed attack and how we should do more to support #OSS, especially for important libraries. Sadly, almost all of what I wrote then is still relevant. web.archive.org/web/2014042013

  11. À quelques jours près, la découverte du code malicieux de #xz coïncide avec la découverte de #HeartBleed avec 10 ans d'écart. 🥳

    (J'ai l'impression que les choses n'ont pas tellement évoluée depuis 😓)

  12. The important role #OpenSSL plays in securing the Internet has never been matched by the financial resources devoted to maintaining it.
    The open source #cryptographic #software library secures hundreds of thousands of Web servers and many products sold by multi-billion-dollar companies,
    but it operates on a shoestring budget.
    OpenSSL Software Foundation President Steve Marquess wrote in a blog post last week that OpenSSL typically receives about $2,000 in donations a year
    and has just one employee who works full time on the open source code.

    Given that, perhaps we shouldn’t be surprised by the existence of #Heartbleed, a security flaw in OpenSSL that can expose user passwords and the private encryption keys needed to protect websites.

    OpenSSL’s bare-bones operations are in stark contrast to some other open source projects that receive sponsorship from corporations relying on their code.
    Chief among them is probably the #Linux operating system #kernel, which has a foundation with multiple employees and funding from HP, IBM, Red Hat, Intel, Oracle, Google, Cisco, and many other companies.
    Workers at some of these firms spend large amounts of their employers’ time writing code for the Linux kernel, benefiting everyone who uses it.
    That’s never been the case with OpenSSL, but the Linux Foundation wants to change that.
    ⭐️The foundation today is announcing a three-year initiative with at least $3.9 million to help under-funded open source projects⭐️
    —with OpenSSL coming first.
    Amazon Web Services, Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Qualcomm, Rackspace, and VMware have all pledged to commit 💥at least $100,000 a year for at least three years💥 to the “#Core #Infrastructure #Initiative,” Linux Foundation Executive Director Jim Zemlin told Ars.
    To be clear, the money will go to multiple open source projects
    —OpenSSL will get a portion of the funding but likely nowhere close to the entire $3.9 million.
    The initiative will identify important open source projects that need help in addition to OpenSSL.

    arstechnica.com/information-te

  13. @Bibobu

    Le pire, c'est que le débat autour des petits projets extrêmement utilisés et pourtant complètement sous-financés avait déjà eu lieu plusieurs fois ces dernières années, à la suite de failles mémorables telles que #Heartbleed.

    Sauf que ça s'agite un peu sur le moment, ça créé divers fonds pour financer le libre, mais une fois la tempête passée, on en entend plus parler et rien ne change ☹️

    next.ink/4883/cybersecurite-et

    #Linux #logiciellibre #FOSS #cybersecurity

  14. #Heartbleed was caused by a memory safety issue, friends, not by inexperienced programmers or an integration team that lacks basic scrutiny.

  15. @lauren @djb

    All in all, this seems like another wildly overblown security vulnerability #publicity tour. I'm only shocked it doesn't have its own website and professional logo like "#shellshock" or "#heartbleed".

    Signed,

    Long time qmail guy & #internet #mail #infrastructure consultant

    5/5

    #PRStunt #security #vulnerability #researcher #report #PR #stunt