Thursday, April 10, 2014

HeartBleed (bug) - Not just websites, extends beyond them?



More bad news 

Also, has a few slides to explain the issue.


According to the article:-

Leaked memory could give attackers hints at how to take the axe to other software, turning known bugs that are currently seen as “hard to exploit” into easy kills.

In the cloud. If you're running VMs in a cloud environment: admins must find their cloud machines and make sure their code base isn't Heartbleed vulnerable.

End-users are going to have to be trained to check certificate issue dates, to make sure that their trusted services (like the bank) have re-issued their certificates.

Thousands of “shoestring budget” VPN concentrators in smaller businesses that will be vulnerable and probably won't be updated




The link below has more information:-

No comments:

Post a Comment