Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

How can I identify EMERGING THREAT – OpenSSL “HeartBleed” Vulnerability in our Linux servers

Posted on 2014-04-09
3
Medium Priority
?
332 Views
Last Modified: 2014-07-29
Please let me know the commands to verify if OpenSSL versions 1.0.1 through 1.0.1f are installed, running or being use in my Linux servers.I have 200 Linux servers and vm's
0
Comment
Question by:oo_tatang
3 Comments
 
LVL 48

Expert Comment

by:Tintin
ID: 39990667
To check the package versions depends on which Linux distro you are using.

To check the openssl version, just run

openssl version
0
 
LVL 31

Expert Comment

by:serialband
ID: 39990734
You can scan your server here:  http://filippo.io/Heartbleed/

There's more information about Heartbleed here: http://heartbleed.com/

Here's a howto:
http://www.howtoforge.com/find_out_if_server_is_affected_from_openssl_heartbleed_vulnerability_cve-2014-0160_and_how_to_fix

Just because you have the version, doesn't mean you are vulnerable.  You may be patched, if your distro released a compiled version without the heartbeat..  You can probably just grep for the variable in the lib to see if it exists or not.
egrep dtls1_process_heartbeat libssl.so.1.0.0

http://www.experts-exchange.com/OS/Linux/Q_28402987.html#a39987838
0
 
LVL 22

Accepted Solution

by:
Brian Utterback earned 1500 total points
ID: 39993964
Keep in mind that outgoing connections are potentially vulnerable too. Any process that uses OpenSSL to implement its SSL client functions is also vulnerable. And sometimes a package will include a private copy of OpenSSL so it may not be obvious that a particular packe is vulnerable and needs patching. You need to do an audit of your incoming and outgoing network connections and then identify the products making those connections and determine their risk. If your servers only accept incoming connections then your task is much easier. But if they connect to other systems on occasion, then you need to look at those client processes too.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Little introduction about CP: CP is a command on linux that use to copy files and folder from one location to another location. Example usage of CP as follow: cp /myfoder /pathto/destination/folder/ cp abc.tar.gz /pathto/destination/folder/ab…
In part one, we reviewed the prerequisites required for installing SQL Server vNext. In this part we will explore how to install Microsoft's SQL Server on Ubuntu 16.04.
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
Suggested Courses
Course of the Month11 days, 6 hours left to enroll

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question