any info on the OpenSSL Heartbleed vuln?

Need help? Post your questions here.

Moderator: moderators

any info on the OpenSSL Heartbleed vuln?

Postby envoy510 » Tue Apr 08, 2014 4:53 pm

I have my server behind https. On a Mac. The server is "jetty-6.1.x, java 1.6.0_65, Mac OS X". Is it vulnerable?
envoy510
 
Posts: 38
Joined: Sun Dec 18, 2011 2:10 am

Re: any info on the OpenSSL Heartbleed vuln?

Postby daneren2005 » Tue Apr 08, 2014 5:47 pm

Jetty (the servlet Subsonic uses) either uses OpenSSL and is vulnerable until the system is patched, or it uses it's own implementation and is probably fine. Either way though there is nothing you are any of us can do about it.
Developer of DSub for Android
daneren2005
 
Posts: 1709
Joined: Fri Jul 06, 2012 7:52 pm

Re: any info on the OpenSSL Heartbleed vuln?

Postby daneren2005 » Tue Apr 08, 2014 6:33 pm

Use http://filippo.io/Heartbleed/ to test if you are vulnerable. I am behind a nginx proxy so I can't tell (which was until the patch that went out yesterday).
Developer of DSub for Android
daneren2005
 
Posts: 1709
Joined: Fri Jul 06, 2012 7:52 pm

Re: any info on the OpenSSL Heartbleed vuln?

Postby envoy510 » Tue Apr 08, 2014 7:27 pm

daneren2005 wrote:Use http://filippo.io/Heartbleed/ to test if you are vulnerable. I am behind a nginx proxy so I can't tell (which was until the patch that went out yesterday).


I got "seems not affected"... thanks.
envoy510
 
Posts: 38
Joined: Sun Dec 18, 2011 2:10 am

Re: any info on the OpenSSL Heartbleed vuln?

Postby snohio » Wed Apr 09, 2014 12:10 am

Thanks for the link!

Both my windows and Ubuntu servers got-
Uh-oh, something went wrong: tls: oversized record received with length 20527

(My Windows instance is retiring since it is on XP, so seems like as good time as any!)
snohio
 
Posts: 6
Joined: Wed Apr 27, 2011 11:13 am

Re: any info on the OpenSSL Heartbleed vuln?

Postby HerrNilsson » Wed Apr 09, 2014 11:50 am

Seems like my tomcat7 Ubuntu Server is vulnerable. I've patched Ubuntu Server, any ideas what i should patch to secure this?
HerrNilsson
 
Posts: 60
Joined: Fri Aug 17, 2012 5:13 am

Re: any info on the OpenSSL Heartbleed vuln?

Postby daneren2005 » Wed Apr 09, 2014 2:24 pm

Looking at http://security.stackexchange.com/quest ... omcat-nati makes it seem like you should just need to restart Tomcat after updating (all affected versions of Ubuntu except 13.04, which is unsupported, should be patched at this point if you update). I would just restart the entire computer though since it's almost impossible to know all the services which depend on OpenSSL, and they will all need to be restarted.
Developer of DSub for Android
daneren2005
 
Posts: 1709
Joined: Fri Jul 06, 2012 7:52 pm

Re: any info on the OpenSSL Heartbleed vuln?

Postby HerrNilsson » Thu Apr 10, 2014 7:09 am

Correct. Patched and restarted and now it's safe.
Time to replace all certificates.
HerrNilsson
 
Posts: 60
Joined: Fri Aug 17, 2012 5:13 am


Return to Help

Who is online

Users browsing this forum: No registered users and 88 guests