#heartbleed — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #heartbleed, aggregated by home.social.
-
CVE-2014-0160 Heartbleed exploit using OpenSSL s_client with -tlsextdebug flag to extract up to 64KB of server heap memory per heartbeat request. Tested on Ubuntu 22.04, Debian 12, Kali Linux. #cve #heartbleed #ValtersIT
https://www.valtersit.com/vault/cve20140160-heartbleed-memory-dump-extraction-via-openssl-ffe2d0/
-
Exploit Heartbleed (CVE-2014-0160) with OpenSSL s_client: send a malformed heartbeat request with oversized payload length to extract up to 64KB of heap memory. Use -no_ssl3 -no_tls1 for TLS 1.0/1.1, -msg to capture leaked data. #cve #snippet #heartbleed #cve-2014-0160 #ValtersIT
https://www.valtersit.com/vault/heartbleed-memory-extraction-via-openssl-sclient-80ed4a/
-
“Wie alt bin ich", #kritis Edition
Weißt du, wo du warst bei
- #Heartbleed
- #log4j
- #gsmr Ausfall 1
- #gsmr Ausfall 2
- #WannaCry
- #solarWinds
- #NotPetya
?Zähle deine “Ja”-Antworten und du erfährst dein biologisches Alter:
(0-1) frische 16
(2-4) junge 25
(4-6) bedenkliche 42
(7) oh oh.. -
#Sudo, #Heartbleed, and the Lessons We Still Haven’t Learned
https://fossforce.com/2026/02/sudo-heartbleed-and-the-lessons-we-still-havent-learned/
-
#Sudo, #Heartbleed, and the Lessons We Still Haven’t Learned
https://fossforce.com/2026/02/sudo-heartbleed-and-the-lessons-we-still-havent-learned/
-
@carlamelee @AwetTesfaiesus
Volle Zustimmung zur literarischen Knoblauchsauce! Letztens erklären wollen wieso ich zu #FOSS beitrage, zusammenfassung war: weil es mir wichtig ist. Mehr Motivationen wären wichtig, insbesondere wenn jetzt die Aufmerksamkeit steigt und der öffentliche Diskurs in diese Richtung gehen soll, wäre zumindest eine Anerkennung der Gemeinnützigkeit sinnvoll.Eigentlich hätte uns bei #heartbleed schonmal auffallen müssen, dass freie Software gefördert werden muss (1v2)
-
@carlamelee @AwetTesfaiesus
Volle Zustimmung zur literarischen Knoblauchsauce! Letztens erklären wollen wieso ich zu #FOSS beitrage, zusammenfassung war: weil es mir wichtig ist. Mehr Motivationen wären wichtig, insbesondere wenn jetzt die Aufmerksamkeit steigt und der öffentliche Diskurs in diese Richtung gehen soll, wäre zumindest eine Anerkennung der Gemeinnützigkeit sinnvoll.Eigentlich hätte uns bei #heartbleed schonmal auffallen müssen, dass freie Software gefördert werden muss (1v2)
-
MongoBLEED - La faille critique qui fait fuir la mémoire de votre MongoDB
https://fed.brid.gy/r/https://korben.info/mongobleed-faille-mongodb-memoire.html
-
Aus Softwarefehlern lernen – Teil 6: Eine Zeile Code mit fatalen Auswirkungen
Minimale Fehler in einer Zeile können schwere Sicherheitslücken aufreißen – die Heartbleed- und Apples goto-fail-Schwachstelle haben es der Welt gezeigt.
#Heartbleed #IT #Programmierung #Sicherheitslücken #Softwareentwicklung #news
-
Aus Softwarefehlern lernen – Teil 6: Eine Zeile Code mit fatalen Auswirkungen
Minimale Fehler in einer Zeile können schwere Sicherheitslücken aufreißen – die Heartbleed- und Apples goto-fail-Schwachstelle haben es der Welt gezeigt.
#Heartbleed #IT #Programmierung #Sicherheitslücken #Softwareentwicklung #news
-
New Study Warns Several Free iOS and Android VPN Apps Leak Data https://hackread.com/studyfree-ios-android-vpn-apps-leak-data/ #Cybersecurity #Vulnerability #Heartbleed #Zimperium #Security #Privacy #Android #zLabs #MITM #iOS #VPN
-
New Study Warns Several Free iOS and Android VPN Apps Leak Data https://hackread.com/studyfree-ios-android-vpn-apps-leak-data/ #Cybersecurity #Vulnerability #Heartbleed #Zimperium #Security #Privacy #Android #zLabs #MITM #iOS #VPN
-
Thinking about #InfoSec organizational behaviors derived from cognitive bias. In particular, availability bias from things that are memorable.
#Log4j #Heartbleed #SolarWinds #ShellShock #Spectre #Meltdown #SQLSlammer
-
Thinking about #InfoSec organizational behaviors derived from cognitive bias. In particular, availability bias from things that are memorable.
#Log4j #Heartbleed #SolarWinds #ShellShock #Spectre #Meltdown #SQLSlammer
-
CitrixBleed II – kolejny błąd powodujący, że serwer zwraca więcej danych niż powinien
Większość naszych Czytelników zapewne kojarzy krytyczną podatność OpenSSL – Heartbleed, która stała się niemal książkowym przykładem błędu, który dotyka bardzo szerokiego grona użytkowników. Za sprawą błędnej obsługi rozmiaru przesyłanego bufora w nowo dodanym rozszerzeniu TLS/DTLS Heartbeat, możliwe było zdalne odczytanie aż do 64k bajtów pamięci klienta lub serwera. Zdarzało się,...
#WBiegu #Citrix #Heartbleed #Netscaler #OutOfBoundRead #Podatność
-
CitrixBleed II – kolejny błąd powodujący, że serwer zwraca więcej danych niż powinien
Większość naszych Czytelników zapewne kojarzy krytyczną podatność OpenSSL – Heartbleed, która stała się niemal książkowym przykładem błędu, który dotyka bardzo szerokiego grona użytkowników. Za sprawą błędnej obsługi rozmiaru przesyłanego bufora w nowo dodanym rozszerzeniu TLS/DTLS Heartbeat, możliwe było zdalne odczytanie aż do 64k bajtów pamięci klienta lub serwera. Zdarzało się,...
#WBiegu #Citrix #Heartbleed #Netscaler #OutOfBoundRead #Podatność
-
20 Jahre #Melani: Die grössten Fälle - inside-it.ch https://www.inside-it.ch/20-jahre-melani-die-groessten-faelle-20241219 #Hacking #CyberCrime #Malware #Ransomware #DDoS #log4j #HeartBleed #Emotet #NotPetya #Stuxnet #WannaCry
-
How to make #opensource #software more secure
The #xz attack, which followed other well-known cybersecurity incidents involving open source software like #Heartbleed, #Shellshock, and #Log4j, was another stark reminder that open source software, given how widespread it is, can pose significant #security risks.
https://techcrunch.com/2024/11/01/how-to-make-open-source-software-more-secure/ #itsec -
How to make #opensource #software more secure
The #xz attack, which followed other well-known cybersecurity incidents involving open source software like #Heartbleed, #Shellshock, and #Log4j, was another stark reminder that open source software, given how widespread it is, can pose significant #security risks.
https://techcrunch.com/2024/11/01/how-to-make-open-source-software-more-secure/ #itsec -
Als ich meinte, wir brauchen mal wieder richtige Bugs, meinte ich nicht dieses auf #Wish bestellte #Heartbleed …
https://jbp.io/2024/06/27/cve-2024-5535-openssl-memory-safety.html
-
Heartbleed: When Is It Good to Name a Vulnerability? – Source: www.darkreading.com https://ciso2ciso.com/heartbleed-when-is-it-good-to-name-a-vulnerability-source-www-darkreading-com/ #rssfeedpostgeneratorecho #DarkReadingSecurity #CyberSecurityNews #Vulnerability #DARKReading #heartbleed
-
Heartbleed: When Is It Good to Name a Vulnerability? – Source: www.darkreading.com https://ciso2ciso.com/heartbleed-when-is-it-good-to-name-a-vulnerability-source-www-darkreading-com/ #rssfeedpostgeneratorecho #DarkReadingSecurity #CyberSecurityNews #Vulnerability #DARKReading #heartbleed
-
Este parasitismo provoca precariedad, agotamiento y hartazgo en desarrolladores y lleva a problemas de seguridad global como #Heartbleed
Por eso nuestras autoridades se plantean obligar a las BigTech a contribuir… ¡NO! Se plantean obligar a voluntarios a darles mantenimiento 🤯
-
Este parasitismo provoca precariedad, agotamiento y hartazgo en desarrolladores y lleva a problemas de seguridad global como #Heartbleed
Por eso nuestras autoridades se plantean obligar a las BigTech a contribuir… ¡NO! Se plantean obligar a voluntarios a darles mantenimiento 🤯
-
Today marks the 10th anniversary of the #Heartbleed vulnerability in OpenSSL. It had the same ultimate root cause as recent #XZUtils backdoor incident. This underscores the importance of public funding to protect vital open source projects that underpin our internet infrastructure. Learn more: https://optimizedbyotto.com/post/what-heartbleed-xz-utils-had-in-common/ #OpenSource #Security
-
Today marks the 10th anniversary of the #Heartbleed vulnerability in OpenSSL. It had the same ultimate root cause as recent #XZUtils backdoor incident. This underscores the importance of public funding to protect vital open source projects that underpin our internet infrastructure. Learn more: https://optimizedbyotto.com/post/what-heartbleed-xz-utils-had-in-common/ #OpenSource #Security
-
¿Pero cómo que han pasado ya diez años de #heartbleed? WTF!!
https://www.securityweek.com/heartbleed-is-10-years-old-farewell-heartbleed-hello-quantumbleed/
-
¿Pero cómo que han pasado ya diez años de #heartbleed? WTF!!
https://www.securityweek.com/heartbleed-is-10-years-old-farewell-heartbleed-hello-quantumbleed/
-
Thinking a lot about the #xz backdoor this week. Almost exactly 10 years ago, I wrote this about the #Heartbleed attack and how we should do more to support #OSS, especially for important libraries. Sadly, almost all of what I wrote then is still relevant. https://web.archive.org/web/20140420132336/https://mashable.com/2014/04/14/heartbleed-open-source/
-
Thinking a lot about the #xz backdoor this week. Almost exactly 10 years ago, I wrote this about the #Heartbleed attack and how we should do more to support #OSS, especially for important libraries. Sadly, almost all of what I wrote then is still relevant. https://web.archive.org/web/20140420132336/https://mashable.com/2014/04/14/heartbleed-open-source/
-
À quelques jours près, la découverte du code malicieux de #xz coïncide avec la découverte de #HeartBleed avec 10 ans d'écart. 🥳
(J'ai l'impression que les choses n'ont pas tellement évoluée depuis 😓)
-
À quelques jours près, la découverte du code malicieux de #xz coïncide avec la découverte de #HeartBleed avec 10 ans d'écart. 🥳
(J'ai l'impression que les choses n'ont pas tellement évoluée depuis 😓)
-
The important role #OpenSSL plays in securing the Internet has never been matched by the financial resources devoted to maintaining it.
The open source #cryptographic #software library secures hundreds of thousands of Web servers and many products sold by multi-billion-dollar companies,
but it operates on a shoestring budget.
OpenSSL Software Foundation President Steve Marquess wrote in a blog post last week that OpenSSL typically receives about $2,000 in donations a year
and has just one employee who works full time on the open source code.Given that, perhaps we shouldn’t be surprised by the existence of #Heartbleed, a security flaw in OpenSSL that can expose user passwords and the private encryption keys needed to protect websites.
OpenSSL’s bare-bones operations are in stark contrast to some other open source projects that receive sponsorship from corporations relying on their code.
Chief among them is probably the #Linux operating system #kernel, which has a foundation with multiple employees and funding from HP, IBM, Red Hat, Intel, Oracle, Google, Cisco, and many other companies.
Workers at some of these firms spend large amounts of their employers’ time writing code for the Linux kernel, benefiting everyone who uses it.
That’s never been the case with OpenSSL, but the Linux Foundation wants to change that.
⭐️The foundation today is announcing a three-year initiative with at least $3.9 million to help under-funded open source projects⭐️
—with OpenSSL coming first.
Amazon Web Services, Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Qualcomm, Rackspace, and VMware have all pledged to commit 💥at least $100,000 a year for at least three years💥 to the “#Core #Infrastructure #Initiative,” Linux Foundation Executive Director Jim Zemlin told Ars.
To be clear, the money will go to multiple open source projects
—OpenSSL will get a portion of the funding but likely nowhere close to the entire $3.9 million.
The initiative will identify important open source projects that need help in addition to OpenSSL. -
The important role #OpenSSL plays in securing the Internet has never been matched by the financial resources devoted to maintaining it.
The open source #cryptographic #software library secures hundreds of thousands of Web servers and many products sold by multi-billion-dollar companies,
but it operates on a shoestring budget.
OpenSSL Software Foundation President Steve Marquess wrote in a blog post last week that OpenSSL typically receives about $2,000 in donations a year
and has just one employee who works full time on the open source code.Given that, perhaps we shouldn’t be surprised by the existence of #Heartbleed, a security flaw in OpenSSL that can expose user passwords and the private encryption keys needed to protect websites.
OpenSSL’s bare-bones operations are in stark contrast to some other open source projects that receive sponsorship from corporations relying on their code.
Chief among them is probably the #Linux operating system #kernel, which has a foundation with multiple employees and funding from HP, IBM, Red Hat, Intel, Oracle, Google, Cisco, and many other companies.
Workers at some of these firms spend large amounts of their employers’ time writing code for the Linux kernel, benefiting everyone who uses it.
That’s never been the case with OpenSSL, but the Linux Foundation wants to change that.
⭐️The foundation today is announcing a three-year initiative with at least $3.9 million to help under-funded open source projects⭐️
—with OpenSSL coming first.
Amazon Web Services, Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Qualcomm, Rackspace, and VMware have all pledged to commit 💥at least $100,000 a year for at least three years💥 to the “#Core #Infrastructure #Initiative,” Linux Foundation Executive Director Jim Zemlin told Ars.
To be clear, the money will go to multiple open source projects
—OpenSSL will get a portion of the funding but likely nowhere close to the entire $3.9 million.
The initiative will identify important open source projects that need help in addition to OpenSSL. -
Le pire, c'est que le débat autour des petits projets extrêmement utilisés et pourtant complètement sous-financés avait déjà eu lieu plusieurs fois ces dernières années, à la suite de failles mémorables telles que #Heartbleed.
Sauf que ça s'agite un peu sur le moment, ça créé divers fonds pour financer le libre, mais une fois la tempête passée, on en entend plus parler et rien ne change ☹️
-
Le pire, c'est que le débat autour des petits projets extrêmement utilisés et pourtant complètement sous-financés avait déjà eu lieu plusieurs fois ces dernières années, à la suite de failles mémorables telles que #Heartbleed.
Sauf que ça s'agite un peu sur le moment, ça créé divers fonds pour financer le libre, mais une fois la tempête passée, on en entend plus parler et rien ne change ☹️
-
#Heartbleed was caused by a memory safety issue, friends, not by inexperienced programmers or an integration team that lacks basic scrutiny.
-
#Heartbleed was caused by a memory safety issue, friends, not by inexperienced programmers or an integration team that lacks basic scrutiny.
-
All in all, this seems like another wildly overblown security vulnerability #publicity tour. I'm only shocked it doesn't have its own website and professional logo like "#shellshock" or "#heartbleed".
Signed,
Long time qmail guy & #internet #mail #infrastructure consultant
5/5
#PRStunt #security #vulnerability #researcher #report #PR #stunt
-
All in all, this seems like another wildly overblown security vulnerability #publicity tour. I'm only shocked it doesn't have its own website and professional logo like "#shellshock" or "#heartbleed".
Signed,
Long time qmail guy & #internet #mail #infrastructure consultant
5/5
#PRStunt #security #vulnerability #researcher #report #PR #stunt
-
I don't see any nickname for the upcoming #curl #vulnerability yet. You can make some suggestions here:
-
CW: Long thread/36
But as open source projects have learned the hard way, the fact that anyone *can* audit your widely used, high-stakes code doesn't mean that anyone *will*.
The #Heartbleed vulnerability in #OpenSSL was a wake-up call for the open source movement - a bug that endangered every secure webserver connection in the world, which had hidden in plain sight for years.
36/
-
Etwas früh dran zum runden Jubiläum hat K2 jetzt #Heartbleed Gedächtnisturnschuhe. 😍 https://de.m.wikipedia.org/wiki/Heartbleed
-
How easy or difficult it is to exploit older SSL/TLS protocols?
https://security.stackexchange.com/questions/269269/how-easy-or-difficult-it-is-to-exploit-older-ssl-tls-protocols
#heartbleed #exploit #attacks #tls -
@dekkzz76 The argument is not that #opensource means 100% secure & proven code.
The argument is that closed source can't be checked by interested parties.
So #FOSS has a chance to be checked. Closed source can't be checked.
The fact that #heartbleed was detected & fixed in a short-term period is actually a great argument for FOSS. If #OpenSSL had been closed source, we probably would still run insecure code all over the world because of this issue without noticing except maybe some bad guys.
-
Firmen sollten sich nicht auf ihren Spenden an Open-Source-Communities ausruhen, fordert Josep Prat: Sie wissen oft gar nicht, wie abhängig sie von ihnen sind.
Drei Fragen und Antworten: Bei Open Source mit anpacken, nicht nur spenden