Solved

OpenSSL Heart Bleed Bug

Posted on 2014-04-09
10
606 Views
Last Modified: 2014-04-15
im not sure what it means and in which way it affects an enterprise?
0
Comment
Question by:DukewillNukem
  • 5
  • 4
10 Comments
 
LVL 54

Assisted Solution

by:McKnife
McKnife earned 500 total points
ID: 39988374
You mean all the articles that can be found in various news are not well-written, not understandable?

If you use openssl in the version mentioned, you need to install updates immediately, that's all. Otherwise you are vulnerable to various serious attacks via internet.
0
 

Author Comment

by:DukewillNukem
ID: 39988386
which articles?where do i get the updates from?
0
 
LVL 54

Expert Comment

by:McKnife
ID: 39988395
Duke, are you affected, do you run open ssl? In what version do you run it?
0
The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

 

Author Comment

by:DukewillNukem
ID: 39988434
we mainly use Windows servers. however,we do have a few Linux appliances,stuff like ESX,Cisco Unified Personal Communicator. no my SQL.
0
 
LVL 54

Expert Comment

by:McKnife
ID: 39988481
But you don't use open ssl, right?
0
 

Author Comment

by:DukewillNukem
ID: 39988501
no
0
 
LVL 54

Accepted Solution

by:
McKnife earned 500 total points
ID: 39988517
And...why do you care, then :) ?
0
 

Assisted Solution

by:DukewillNukem
DukewillNukem earned 0 total points
ID: 39991297
i dont know ;-)
but again,we have centos,suse,red hat,ubuntu,etc.
i just want to make sure we dont have to worry about stuff like that. thinking  about to implement a Vulnerability Management Tool (VIM) for 3rd party Software
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 39996059
IIS is not affected: http://blogs.technet.com/b/erezs_iis_blog/archive/2014/04/09/information-about-heartbleed-and-iis.aspx
But Apache + OpenSSL is. If your running redhat you are likely affected if it's the latest instance of open-ssl (1.0.1 thru 1.0.1f) http://www.kb.cert.org/vuls/id/720951
Here is a pretty good list of vendors press releases that specify versions of software that are and are not affected, like cisco etc...
https://isc.sans.edu/diary/Heartbleed+vendor+notifications/17929
-rich
0
 

Author Closing Comment

by:DukewillNukem
ID: 40001137
found a solution
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Gmail Account risks 4 91
Domain admin accounts get locked out 35 60
Connecting a New Subnet to Network 4 29
exchange, activesync 2 9
As technology users and professionals, we’re always learning. Our universal interest in advancing our knowledge of the trade is unmatched by most industries. It’s a curiosity that makes sense, given the climate of change. Within that, there lies a…
February 24, 2017 — On February 23, Travis Ormandy, a vulnerability researcher at Google, reported on Twitter (https://twitter.com/taviso/status/834900838837411840) that massive stores of data have been leaked by CloudFlare, a company that provide…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question