Solved

How can I identify EMERGING THREAT – OpenSSL “HeartBleed” Vulnerability in our Linux servers

Posted on 2014-04-09
3
319 Views
Last Modified: 2014-07-29
Please let me know the commands to verify if OpenSSL versions 1.0.1 through 1.0.1f are installed, running or being use in my Linux servers.I have 200 Linux servers and vm's
0
Comment
Question by:oo_tatang
3 Comments
 
LVL 48

Expert Comment

by:Tintin
ID: 39990667
To check the package versions depends on which Linux distro you are using.

To check the openssl version, just run

openssl version
0
 
LVL 28

Expert Comment

by:serialband
ID: 39990734
You can scan your server here:  http://filippo.io/Heartbleed/

There's more information about Heartbleed here: http://heartbleed.com/

Here's a howto:
http://www.howtoforge.com/find_out_if_server_is_affected_from_openssl_heartbleed_vulnerability_cve-2014-0160_and_how_to_fix

Just because you have the version, doesn't mean you are vulnerable.  You may be patched, if your distro released a compiled version without the heartbeat..  You can probably just grep for the variable in the lib to see if it exists or not.
egrep dtls1_process_heartbeat libssl.so.1.0.0

http://www.experts-exchange.com/OS/Linux/Q_28402987.html#a39987838
0
 
LVL 22

Accepted Solution

by:
blu earned 500 total points
ID: 39993964
Keep in mind that outgoing connections are potentially vulnerable too. Any process that uses OpenSSL to implement its SSL client functions is also vulnerable. And sometimes a package will include a private copy of OpenSSL so it may not be obvious that a particular packe is vulnerable and needs patching. You need to do an audit of your incoming and outgoing network connections and then identify the products making those connections and determine their risk. If your servers only accept incoming connections then your task is much easier. But if they connect to other systems on occasion, then you need to look at those client processes too.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I promised to write further about my project, and here I am.  First, I needed to setup the Primary Server.  You can read how in this article: Setup FreeBSD Server with full HDD encryption (http://www.experts-exchange.com/OS/Unix/BSD/FreeBSD/A_3660-S…
Using 'screen' for session sharing, The Simple Edition Step 1: user starts session with command: screen Step 2: other user (logged in with same user account) connects with command: screen -x Done. Both users are connected to the same CLI sessio…
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now