- Portals
- The Current Year
- ED in the News
- Admins
- Help ED Rebuild
- Archive
- ED Bookmarklet
- Donate Bitcoin
Contact an admin on Discord or EDF if you want an account. Also fuck bots.
Heartbleed: Difference between revisions
imported>Uberfukken No edit summary |
imported>Uberfukken No edit summary |
||
Line 11: | Line 11: | ||
*[[Everything]] | *[[Everything]] | ||
[[File:Heartbleed.jpg|thumb|left|A+ for creativity.]] | [[File:Heartbleed.jpg|thumb|left|A+ for creativity.]] | ||
As with all security flaws exposed, an absolute mudslide of butthurt and IRL drama has ensued. | As with all security flaws exposed, an absolute mudslide of butthurt and IRL drama has ensued. In one instance, an attacker was able to hijack multiple VPN sessions by obtaining active tokens and then escalate their own privileges within the system [https://www.mandiant.com/blog/attackers-exploit-heartbleed-openssl-vulnerability-circumvent-multifactor-authentication-vpns/]. This was a few days '''after''' the patch was released, lamenting the continued carelessness of companies who promise to safeguard your privacy. | ||
{{stub}} | {{stub}} | ||
{{softwarez}} | {{softwarez}} |
Revision as of 03:11, 19 April 2014
Hey! | This article isn't lulz just yet, but its coverage can spark a lollercoaster. You can help by reverting people who delete shit, and vandalizing their user pages. See this article on Google? Want to add something? Join us! |
Heartbleed is a serious vulnerability within OpenSSL that allows a skilled hacker to steal passwords, usernames, e-mails, IMs, credit card numbers, private keys and other forms of information from any website that incorporates the software in their servers. The bug has existed since March 2012, and is currently estimated to affect 66% of servers worldwide. An incomplete list of major websites affected include:
As with all security flaws exposed, an absolute mudslide of butthurt and IRL drama has ensued. In one instance, an attacker was able to hijack multiple VPN sessions by obtaining active tokens and then escalate their own privileges within the system [1]. This was a few days after the patch was released, lamenting the continued carelessness of companies who promise to safeguard your privacy.
Heartbleed is part of a series on Visit the Softwarez Portal for complete coverage. |