Heartbleed: Serious OpenSSL zero day vulnerability revealed

Discussion in 'privacy technology' started by ronjor, Apr 7, 2014.

  1. MrBrian

    MrBrian Registered Member

  2. emmjay

    emmjay Registered Member

    Tnx Page42. I am going to install it too as this PC is a family computer.
    I assume the scam emails have links in them. Had to warn the family not to click on any links in emails for password resets even if they think the email is from a genuine source. We have not received any password reset emails as yet.
     
  3. Dermot7

    Dermot7 Registered Member

  4. siljaline

    siljaline Registered Member

  5. Page42

    Page42 Registered Member

    Yer welcome. I may install it as well. Post back here or on the extension thread what your experiences are with Chromebleed, if you would.
     
  6. lotuseclat79

    lotuseclat79 Registered Member

  7. emmjay

    emmjay Registered Member

    It works. I checked out a few sites that I have accounts with. One govt. site which is vulnerable is not accepting payments. One family member opened a news site (sunnewsnetwork) to see what they have to say about the local situation (local utilities, banks, ISPs etc.) and got an alert on the news site. Their website if vulnerable. :eek: . We do not have an account with them. Still checking all the utilities sites as we converted over to e-billing over the past year.
     
  8. TheWindBringeth

    TheWindBringeth Registered Member

    Has anyone come across 1) a perl based reverse/client test script, and/or 2) A webserver known to be vulnerable and meant for testing?
     
  9. MrBrian

    MrBrian Registered Member

    2) cloudflarechallenge.com
     
  10. MrBrian

    MrBrian Registered Member

  11. TheWindBringeth

    TheWindBringeth Registered Member

    Thanks MrBrian, I suppose I should have read more about the challenge when I heard of it ;)
     
  12. MrBrian

    MrBrian Registered Member

  13. MrBrian

    MrBrian Registered Member

  14. TomAZ

    TomAZ Registered Member

    Just added the FoxBleed extension to firefox, but not sure it's working (supposedly similar to Chromebleed). Anyone know a vulnerable site that it could be tested on?
     
  15. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    The current version of the Qupzilla browser is vulnerable to Heartbleed!
    (V1.6.3 uses OpenSSL 1.0.1g)
     
  16. lotuseclat79

    lotuseclat79 Registered Member

  17. ronjor

    ronjor Global Moderator

  18. siljaline

    siljaline Registered Member

    Heartbleed hackers grab 900 SIN numbers off Canadian Revenue Agency servers
    http://montreal.ctvnews.ca/heartbleed-hackers-grab-900-sin-numbers-1.1774699
     
  19. siljaline

    siljaline Registered Member

    Linky if you want the extension of Firefox although I probably would not put too much stock in it. https://addons.mozilla.org/en-US/firefox/addon/foxbleed/
     
  20. ronjor

    ronjor Global Moderator

    http://www.bbc.com/news/technology-27020256
     
  21. ronjor

    ronjor Global Moderator

  22. Dermot7

    Dermot7 Registered Member

    BBC News - Heartbleed hacks hit Mumsnet and Canada's tax agency
     
  23. lotuseclat79

    lotuseclat79 Registered Member

  24. Dermot7

    Dermot7 Registered Member

  25. JRViejo

    JRViejo Super Moderator

    Removed Posts. Before Posting, Please Search First. Thank You.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice