Heartbleed bug is a fault in Open SSL, the open source encryptionstandard that is used by a large number of sites on the web to transmit data safely and securely. It actually provides you a secure line when you are sending emails or messages.
It is important to know that Heartbleed is not a virus but a mistake in Open SSL. This mistake makes it possible for the hackers to extract data from the large database, which include username, passwords, and other confidential information.
How does Heartbleed bug work?
OpenSSL Heartbleed vulnerability lets a hacker access up to 64 kilobytes of server memory and carries out the attack again and again to gather lots of information. This means the hacker will not just know the username and password but also the cookie data that is used by the web servers and browsers to identify a person and allow log in.
If the attack is being done repeatedly then the site’s private SSL key could also be at risk which means that the hacker may use that key to create a fake website and steal different kind of information that includes credit card details, bank details, and other private messages.
Conditions when Heartbleed can’t infect you.
Although OpenSSL is the most used one but there are other SSL options too. Also some web sites use an older uninfluenced version of the OpenSSL. All these web sites are not affected by the Heartbleed or you may say
You are not vulnerable to Heartbleed if you are:
· Not using Open SSL
· Using OpenSSL without the Heartbeat function enabled
· Using OpenSSL 1.0.0 or some other older version
How to do a Heartbleed bug check?
If you are using OpenSSL and you want to know whether you are infected with the Heartbleed bug you may use the Trend Micro test Tool to check the bug. You may also run a full vulnerability scan of Trend Micro Deep security web apps on your web applications to check for the Heartbleed bug.