# Heartbleed Openssl Bug

**URL:** https://forums.speedlife.net/t/heartbleed-openssl-bug/268950
**Category:** NYSpeed Off Topic
**Created:** [April 7, 2014, 5:26pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950 "2014-04-07T17:26:50Z")
**Posts on this page:** 20
**Page:** 3

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 9, 2014, 7:46am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/41 "2014-04-09T07:46:22Z")

</div>

> [@Mankthetank19](#):
>
> [Passwords vulnerable after security flaw found](http://www.usatoday.com/story/tech/2014/04/08/passwords-vulnerable-after-security-flaw-found/7486623/)
> 
> Companies that haven’t made improvements for some time are not as affected as companies who continue to update their encryption. This is why many of the larger tech companies are affected

That is such a bullshit statement.

“Bug was introduced to OpenSSL in December 2011 and has been out in the wild since OpenSSL release 1.0.1 on 14th of March 2012. OpenSSL 1.0.1g released on 7th of April 2014 fixes the bug.”

Most normal companies have a 3 year life cycle max and regular software maintenance/patching as part of vulnerability management.

It’s not like other companies haven’t gotten caught in similar situations its happened to Microsoft, Apple, and everyone else numerous times.

I figured with all the talent Yahoo has sitting around they would come up with some quick mitigation however it was vulnerable for an extremely long amount of time yesterday. It’s likely 100,000+ users have had credentials compromised if not more.

---

<div class="post-metadata">

### Author: ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)
#### Post date: [April 9, 2014, 7:58am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/42 "2014-04-09T07:58:57Z")

</div>

Well, I know that RHEL 5 and CentOS 5 are unaffected due to still running OpenSSL 0.9.8. RHEL 5 is still in support and will be for some time. 3 year life cycles work for some companies with large budgets, but I’m guessing that there are MANY companies out there still running OpenSSL 0.9.8.

I agree it’s a bullshit statement though. Saying, “we’re awesome because we’re running old software” is the biggest cop-out on the planet and in the bigger picture, you’re in worse shape than the companies affected by heartbleed.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 9, 2014, 8:05am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/43 "2014-04-09T08:05:55Z")

</div>

The amount of time it took to get a mitigation in place was my primary issue.

Running outdated software and accepting the risk while having mitigating controls is fine.

You could yank out hundreds of yahoo logins in a couple min from [mail.yahoo.com](http://mail.yahoo.com) yesterday and that is with 0 skill. If someone was more skilled they could use a memory leak like this to defeat a number of exploit mitigation techniques if they already had working exploit for code apache or other software.

---

<div class="post-metadata">

### Author: ![boxxa](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/boxxa/32/5045_2.png) [@boxxa](https://forums.speedlife.net/u/boxxa)
#### Post date: [April 9, 2014, 8:08am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/44 "2014-04-09T08:08:54Z")

</div>

Sorry your open source software failed you.

---

<div class="post-metadata">

### Author: ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)
#### Post date: [April 9, 2014, 8:21am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/45 "2014-04-09T08:21:16Z")

</div>

> [@LZ](#):
>
> The amount of time it took to get a mitigation in place was my primary issue.
> 
> Running outdated software and accepting the risk while having mitigating controls is fine.
> 
> You could yank out hundreds of yahoo logins in a couple min from [mail.yahoo.com](http://mail.yahoo.com) yesterday and that is with 0 skill. If someone was more skilled they could use a memory leak like this to defeat a number of exploit mitigation techniques if they already had working exploit for code apache or other software.

agreed

> [@boxxa](#):
>
> Sorry your open source software failed you.

this is kind-of a bummer to the open source community, but it was patched and released downstream VERY quickly.

---

<div class="post-metadata">

### Author: ![boxxa](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/boxxa/32/5045_2.png) [@boxxa](https://forums.speedlife.net/u/boxxa)
#### Post date: [April 9, 2014, 11:13am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/46 "2014-04-09T11:13:20Z")

</div>

> [@boardjnky4](#):
>
> this is kind-of a bummer to the open source community, but it was patched and released downstream VERY quickly.

This is just how things happen in open source communities and was pretty awesome if you think about it. How long do proprietary bugs take to get patched? A lot longer. People are complaining about this and aren’t realizing that software like this is free and actually works pretty awesome for a response to address this.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 9, 2014, 11:25am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/47 "2014-04-09T11:25:13Z")

</div>

So apparently you can hit people client side with this.

> **[Lekensteyn/pacemaker](https://github.com/Lekensteyn/pacemaker)**
>
> pacemaker - Heartbleed (CVE-2014-0160) client exploit

---

<div class="post-metadata">

### Author: ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)
#### Post date: [April 9, 2014, 1:14pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/48 "2014-04-09T13:14:22Z")

</div>

> [@boxxa](#):
>
> This is just how things happen in open source communities and was pretty awesome if you think about it. How long do proprietary bugs take to get patched? A lot longer. People are complaining about this and aren’t realizing that software like this is free and actually works pretty awesome for a response to address this.

agreed, 100%

---

<div class="post-metadata">

### Author: ![boxxa](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/boxxa/32/5045_2.png) [@boxxa](https://forums.speedlife.net/u/boxxa)
#### Post date: [April 9, 2014, 2:06pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/49 "2014-04-09T14:06:43Z")

</div>

> [@LZ](#):
>
> So apparently you can hit people client side with this.
> 
> [GitHub - Lekensteyn/pacemaker: Heartbleed (CVE-2014-0160) client exploit](https://github.com/Lekensteyn/pacemaker)

If you read the bug, you can hit anyone, even program that use OpenSSL if they implement the heartbeat. The app dumps memory in 64k chunks so you essentially can capture application keys and data, even Bitcoin private keys from wallets.

- 
  - 
    - Updated - - -

For the technical folk, this bug is really interesting.

[http://thread.gmane.org/gmane.os.openbsd.misc/211952/focus=211963](http://thread.gmane.org/gmane.os.openbsd.misc/211952/focus=211963)

> \> On Tue, Apr 08, 2014 at 15:09, Mike Small wrote:  
> \> \> nobody \<openbsd.as.a.desktop \<at\> [gmail.com](http://gmail.com)\> writes:  
> \> \>  
> \> \>\> “read overrun, so ASLR won’t save you”  
> \> \>  
> \> \> What if malloc’s “G” option were turned on? You know, assuming the  
> \> \> subset of the worlds’ programs you use is good enough to run with that.  
> \>  
> \> No. OpenSSL has exploit mitigation countermeasures to make sure it’s  
> \> exploitable.

> What Ted is saying may sound like a joke…

> So years ago we added exploit mitigations counter measures to libc  
> malloc and mmap, so that a variety of bugs can be exposed. Such  
> memory accesses will cause an immediate crash, or even a core dump,  
> then the bug can be analyed, and fixed forever.

> Some other debugging toolkits get them too. To a large extent these  
> come with almost no performance cost.

> But around that time OpenSSL adds a wrapper around malloc & free so  
> that the library will cache memory on it’s own, and not free it to the  
> protective malloc.

> You can find the comment in their sources …

> #ifndef OPENSSL\_NO\_BUF\_FREELISTS  
> /\* On some platforms, malloc() performance is bad enough that you can’t just

> OH, because SOME platforms have slow performance, it means even if you  
> build protective technology into malloc() and free(), it will be  
> ineffective. On ALL PLATFORMS, because that option is the default,  
> and Ted’s tests show you can’t turn it off because they haven’t tested  
> without it in ages.

> So then a bug shows up which leaks the content of memory mishandled by  
> that layer. If the memoory had been properly returned via free, it  
> would likely have been handed to munmap, and triggered a daemon crash  
> instead of leaking your keys.

> OpenSSL is not developed by a responsible team.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 9, 2014, 5:12pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/50 "2014-04-09T17:12:16Z")

</div>

I still don’t understand how they’re claiming fully recovery of private keys.

Just from messing around the memory that is being read in the heap isn’t near the private keys

Edit: [http://blog.erratasec.com/2014/04/why-heartbleed-doesnt-leak-private-key.html#.U0XjDfldXdA](http://blog.erratasec.com/2014/04/why-heartbleed-doesnt-leak-private-key.html#.U0XjDfldXdA)

---

<div class="post-metadata">

### Author: ![Mankthetank19](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/mankthetank19/32/5295_2.png) [@Mankthetank19](https://forums.speedlife.net/u/Mankthetank19)
#### Post date: [April 9, 2014, 5:51pm UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/51 "2014-04-09T17:51:46Z")

</div>

Yahoo has completed the patch to their whole portfolio.

[https://help.yahoo.com/kb/SLN24021.html](https://help.yahoo.com/kb/SLN24021.html)

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 10, 2014, 5:27am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/52 "2014-04-10T05:27:43Z")

</div>

https://player.vimeo.com/video/91425662?app_id=122963

---

<div class="post-metadata">

### Author: ![rugsr](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/rugsr/32/7474_2.png) [@rugsr](https://forums.speedlife.net/u/rugsr)
#### Post date: [April 10, 2014, 6:06am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/53 "2014-04-10T06:06:11Z")

</div>

How do you know if this effects you. I heard some sites arent effected.  
Wonder if certain bank sites were effected/fixed it.  
I called mine and they said they werent effected, but they could be lying to keep me happy

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 10, 2014, 6:07am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/54 "2014-04-10T06:07:58Z")

</div>

> **[The Heartbleed Hit List: The Passwords You Need to Change Right Now](https://mashable.com/2014/04/09/heartbleed-bug-websites-affected/)**
>
> Heartbleed: A look at which companies have issued a security patch to fix the Heartbleed bug.

---

<div class="post-metadata">

### Author: ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)
#### Post date: [April 10, 2014, 6:09am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/55 "2014-04-10T06:09:56Z")

</div>

Great video

Seeing a lot of active exploitation attempts after getting IDS rules loaded into Snort…

---

<div class="post-metadata">

### Author: ![rugsr](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/rugsr/32/7474_2.png) [@rugsr](https://forums.speedlife.net/u/rugsr)
#### Post date: [April 10, 2014, 6:40am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/56 "2014-04-10T06:40:30Z")

</div>

[https://github.com/musalbas/heartbleed-masstest/blob/master/top1000.txt](https://github.com/musalbas/heartbleed-masstest/blob/master/top1000.txt)

[http://filippo.io/Heartbleed/](http://filippo.io/Heartbleed/)

---

<div class="post-metadata">

### Author: ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)
#### Post date: [April 10, 2014, 7:20am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/57 "2014-04-10T07:20:15Z")

</div>

> [@rugsr](#):
>
> [https://github.com/musalbas/heartbleed-masstest/blob/master/top1000.txt](https://github.com/musalbas/heartbleed-masstest/blob/master/top1000.txt)
> 
> [Test your server for Heartbleed (CVE-2014-0160)](http://filippo.io/Heartbleed/)

Disclaimer: This scan was performed around April 8, 12:00 UTC. Websites listed  
as vulnerable may no longer be vulnerable. This list serves as a snapshot of  
vulnerable sites at the time of the scan.

Take the list with a grain of salt, it’s likely that a lot of patching has been done since then. The top 3 are all patched.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 10, 2014, 7:32am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/58 "2014-04-10T07:32:32Z")

</div>

I still want to someone fully recover a complete private key from a web server with actual traffic

---

<div class="post-metadata">

### Author: ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)
#### Post date: [April 10, 2014, 8:10am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/59 "2014-04-10T08:10:09Z")

</div>

> [@LZ](#):
>
> I still want to someone fully recover a complete private key from a web server with actual traffic

co-worker of mine had a good point, you’d have to exploit the server RIGHT as the httpd service is starting since that’s when the private key might be in that part of memory.

---

<div class="post-metadata">

### Author: ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)
#### Post date: [April 10, 2014, 8:27am UTC](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950/60 "2014-04-10T08:27:01Z")

</div>

You might be able to get it when a process forks

It’s just odd some security people are running around say all these private keys are lost

[Previous page](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950.md?page=2)

[Next page](https://forums.speedlife.net/t/heartbleed-openssl-bug/268950.md?page=4)
