Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

OpenSSL Heart Bleed Bug

Posted on 2014-04-09
10
Medium Priority
?
616 Views
Last Modified: 2014-04-15
im not sure what it means and in which way it affects an enterprise?
0
Comment
Question by:DukewillNukem
  • 5
  • 4
10 Comments
 
LVL 57

Assisted Solution

by:McKnife
McKnife earned 1500 total points
ID: 39988374
You mean all the articles that can be found in various news are not well-written, not understandable?

If you use openssl in the version mentioned, you need to install updates immediately, that's all. Otherwise you are vulnerable to various serious attacks via internet.
0
 

Author Comment

by:DukewillNukem
ID: 39988386
which articles?where do i get the updates from?
0
 
LVL 57

Expert Comment

by:McKnife
ID: 39988395
Duke, are you affected, do you run open ssl? In what version do you run it?
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 

Author Comment

by:DukewillNukem
ID: 39988434
we mainly use Windows servers. however,we do have a few Linux appliances,stuff like ESX,Cisco Unified Personal Communicator. no my SQL.
0
 
LVL 57

Expert Comment

by:McKnife
ID: 39988481
But you don't use open ssl, right?
0
 

Author Comment

by:DukewillNukem
ID: 39988501
no
0
 
LVL 57

Accepted Solution

by:
McKnife earned 1500 total points
ID: 39988517
And...why do you care, then :) ?
0
 

Assisted Solution

by:DukewillNukem
DukewillNukem earned 0 total points
ID: 39991297
i dont know ;-)
but again,we have centos,suse,red hat,ubuntu,etc.
i just want to make sure we dont have to worry about stuff like that. thinking  about to implement a Vulnerability Management Tool (VIM) for 3rd party Software
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 39996059
IIS is not affected: http://blogs.technet.com/b/erezs_iis_blog/archive/2014/04/09/information-about-heartbleed-and-iis.aspx
But Apache + OpenSSL is. If your running redhat you are likely affected if it's the latest instance of open-ssl (1.0.1 thru 1.0.1f) http://www.kb.cert.org/vuls/id/720951
Here is a pretty good list of vendors press releases that specify versions of software that are and are not affected, like cisco etc...
https://isc.sans.edu/diary/Heartbleed+vendor+notifications/17929
-rich
0
 

Author Closing Comment

by:DukewillNukem
ID: 40001137
found a solution
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
Ransomware - Defeated! Client opened the wrong email and was attacked by Ransomware. I was able to use file recovery utilities to find shadow copies of the encrypted files and make a complete recovery.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
This video Micro Tutorial shows how to password-protect PDF files with free software. Many software products can do this, such as Adobe Acrobat (but not Adobe Reader), Nuance PaperPort, and Nuance Power PDF, but they are not free products. This vide…

782 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question