9 ms·
Heartleech: Automated OpenSSL private key extraction tool using Heartbleed
- chronid 12y agoWell, with the exploits for this vulnerability now showing up everywhere i almost feel bad for the people that still have not-patched servers lying around.
- jhardcastle 12y agoFeel no pity whatsoever for the sysadmins. Feel pity for the users, who are unwittingly using a vulnerable service.
- danielweber 12y agoMaybe the sysadmin took a vacation. Fuck him, why should he spend time with his family?
- aroch 12y agoWell if you're the only sysadmin for a company and they let you travel without the ability to both contact you and have emergency work done, you're pretty lucky. I would hope no company would let their one and only fulltime sysadmin take a vacation without having backup personnel on-hand
- danielweber 12y agoNot every company in the world has sysadmins three levels deep. Lots of companies don't even have sysadmins one level deep.
- neals 12y agoI have a few ubuntu servers. When I do a "check for heartbleed" check with various tools, it says they are not vulnerable. However, these servers were installed 6 months ago and not updated for at least 2 months. How can they not be vulnerable?
- slashdotaccount 12y agoMaybe they use the GNU TLS library.
- fit2rule 12y agoYou might want to rely on some other tool to determine if you are vulnerable or not. Or, just fix it yourself: http://www.ansoncheunghk.info/article/3-simple-steps-update-ubuntu-fix-heartbleed-ssl-bug http://www.ansoncheunghk.info/article/3-simple-steps-update-...
- neals 12y agoI ran some of the exploits that were floating around against my own servers and against known vulnerable servers. I got nothing from mine, but lots of scary stuff from the others.
- VeejayRampay 12y agoI am not an expert on the topic by any means, but one possibility is that older versions of impacted software are simply not vulnerable.
- deleted 12y ago[deleted]
- warp 12y agoAs I understand 13.04 is just as vulnerable, but not mentioned in that security notice because it is unsupported (end of life).
- danielweber 12y agoThis should be a useful tool on its own, but I wrote it primarily because the pattern-matching rules for Snort are inadequate. IDS vendors won't fix their stuff until I can prove they are inadequate. Ugh. In the old days the mantra of full-disclosure was "well, if we don't make exploit tools, then the vendors won't issue patches." And then it became "well, if we don't make exploit tools, then the sysadmins won't patch." Apparently the bar has sunk so low that people personally pushing out Snort rules on snort-users aren't actually catching all instances of the bug is the justification for releasing tools to steal private keys. In reality, lots of people in the security community just like seeing chaos in the world, because it makes for even more news headlines and in their mind this increases the status of the security community. Then it's time for the post hoc justifications for their behavior.
- eli 12y agoI would imagine the motivation is less about money and more about having fun breaking stuff (and bragging rights). I agree though. Hard to argue that this particular security issue needed any extra attention in order to get it fixed.
- danielweber 12y agoOne of the biggest root causes of problems in the security industry is that often the only way to make a name for yourself is to cause pain to others. (It's not too hard to convince yourself that those others deserved it.) If you went back in time two years and fixed the Heartbleed bug, no one would be writing newspaper articles about you.
- nitrogen 12y agoIf you invented time travel people would definitely be writing about it.
- vezzy-fnord 12y agoIf you went back in time two years and fixed the Heartbleed bug, no one would be writing newspaper articles about you. This is hardly something isolated to the security industry. It's human nature. Some person sealing a hole is nowhere near as attention-gathering as a hole leading to a catastrophic flood due to no one realizing that it needs to be sealed. The potential for something bad to happen doesn't raise anywhere near as much eyebrows as the bad thing actually happening, especially for something as invisible to the average person as a software vulnerability.
- happyscrappy 12y agoWill these automated tools work on vulnerable Android devices? If so this seems a little irresponsible, I mean it is one thing to stick it to lazy sysadmins but making it easy to exploit peoples phones seems evil.
- Pxtl 12y agoI'm confused how openSSL on Android is a problem... isn't openSSL a server technology? Do the clients use a heartbeat for something? Or is this only relevant when you're running a server on your client device? Is OpenSSL always running as a server on Android?
- larrysilverman 12y agoAndroid 4.1.1 is the vulnerable version. Google says only 4.1.1 is vulnerable. There are a handful of services on Android that use openssl and, I suppose, could present open ports for there to be an attack vector. See http://www.pcmag.com/article2/0,2817,2456507,00.asp http://www.pcmag.com/article2/0,2817,2456507,00.asp
- mikeash 12y agoYou can also MITM outgoing SSL connections and use heartbleed on them. The vulnerability is accessible before the certificate checks are completed, so the standard MITM prevention measures don't help you there.
- eli 12y agoHeartbeat goes both ways. If you can be tricked to accessing a malicious HTTPS server, it can extract data from the client. http://blog.meldium.com/home/2014/4/10/testing-for-reverse-heartbleed http://blog.meldium.com/home/2014/4/10/testing-for-reverse-h...
- Pxtl 12y ago... wow, the media firestorm around heartbleed was so fixated on the server-side issue that this completely slipped by me. I guess it's only relevant to one particular Android version and a handful of Linux-based versions where patching is expected to occur automatically and quickly, and nobody cares about desktop Linux.
- uuid_to_string 12y agoIt could be just my perception but it seems like the authors of Heartbleed exploit code are focusing on www and email servers. Doesn't OpenVPN use OpenSSL?
- trebor 12y agoI believe so, yes. It often provides a certificate with the configuration settings. Many screen sharing and remote access tools use some form of TLS/SSL too.
- jameshart 12y agoWhile I know private keys are important and you really don't want to leak them, I have to wonder if the security community's focus on the private keys as the crown jewels that heartbleed accesses is a little misplaced. If someone can steal your private key, yes, they can now impersonate your SSL server. For HTTPS, they'll need to actually perform a DNS spoof or similar to truly exploit that change, though. I guess there might be more of a concern about things like DKIM keys being stolen. We have to be a little less trusting of SSL certs to verify identity. But in all this fuss about the keys, we seem to be forgetting that the heartbleed vulnerability allowed attackers to sniff random cleartext as it passed through OpenSSL. Session identities, usernames, passwords, sure - but again, the security industry focuses on credentials being stolen as the worst case scenario. But what about all the other private data going across the SSL connection? This reminds me a little of the focus on operating system security preventing privilege escalation, while ignoring the risk of malware trashing all of a user's own data - you might lose all your photographs, but at least the device drivers will be safe. When it comes to heartbleed, users might legitimately fear that data they sent over SSL could have been eavesdropped by anybody; but the security industry doesn't seem to care about that as much as it does about whether the private key could have been compromised.
- deeviant 12y ago"If someone can steal your private key, yes, they can now impersonate your SSL server." I don't understand this comment. If they steal your private key, they can impersonate the client and do everything the client can do. I don't understand the "impersonate the SSL server". If they steal the public key, then they can impersonate the server.
- nitrogen 12y agoNo, you can't do anything with a public key. Public keys are meant to be public. You might be confusing session keys, public keys, and private keys.
- lstamour 12y agoNot an expert, but I'll attempt an answer: "your private key" refers to the server's key. The public key is already available. What gives a connection the lock icon is the verification of the public key by verifying signatures to recognize that the correct private key was used. In this diagram, the private key we refer to is the red key symbol on the far right: http://upload.wikimedia.org/wikipedia/commons/9/96/Usage-of-Digital-Certificate.svg http://upload.wikimedia.org/wikipedia/commons/9/96/Usage-of-... In this diagram, ignoring TLS for the moment, what we care about is the purple box. That represents the kind of verification we have of a server's web traffic -- the purple box is the response from the server. The public key is shared and anyone can get a copy by asking, that's how they know where the certificate came from -- that it came from a valid CA -- the problem is that if anyone can get access to the red key (or the green key from earlier), they can impersonate a certificate because to the encryption, they are valid, the signatures match. It's like someone stealing your password or PIN code. The private key just happens to be much longer than that.