Heartbleed bug is a fault in Open SSL, the open source encryptionstandard that is used by a large number of sites on the web to transmit data safely and securely. It actually provides you a secure line when you are sending emails or messages.
It is important to know that Heartbleed is not a virus but a mistake in Open SSL. This mistake makes it possible for the hackers to extract data from the large database, which include username, passwords, and other confidential information.
How does Heartbleed bug work?
OpenSSL Heartbleed vulnerability lets a hacker access up to 64 kilobytes of server memory and carries out the attack again and again to gather lots of information. This means the hacker will not just know the username and password but also the cookie data that is used by the web servers and browsers to identify a person and allow log in.
If the attack is being done repeatedly then the site’s private SSL key could also be at risk which means that the hacker may use that key to create a fake website and steal different kind of information that includes credit card details, bank details, and other private messages.
Conditions when Heartbleed can’t infect you.
Although OpenSSL is the most used one but there are other SSL options too. Also some web sites use an older uninfluenced version of the OpenSSL. All these web sites are not affected by the Heartbleed or you may say
You are not vulnerable to Heartbleed if you are:
· Not using Open SSL
· Using OpenSSL without the Heartbeat function enabled
· Using OpenSSL 1.0.0 or some other older version
How to do a Heartbleed bug check?
If you are using OpenSSL and you want to know whether you are infected with the Heartbleed bug you may use the Trend Micro test Tool to check the bug. You may also run a full vulnerability scan of Trend Micro Deep security web apps on your web applications to check for the Heartbleed bug.
Shellshock: Bash Bug Vs Heartbleed - Which one is bigger attack?
Shellshock: Bash Bug Vs Heartbleed – Which one is bigger attack?
Shellshock (Bash Bug) Vs HeartBleed
The ‘Bash bug’, an acronym for Bourne Again Shell also known as Shellshock, is located in the command-line shell used in many Linux and Unix operating systems, leaving websites and devices power by these operating systems open to attack.
These are almost 25 years old vulnerability and is related to the processing of what are known as “environment variables” in…
Google has joined the groups of companies which have issued Strict warnings about their products being vulnerable to exploitation thanks to the massively found Heartbleed Vulnerability. Google has now Announce that users of all Android versions except specifically 4.1.1 are SAFE.
Hahahahahaha…
"...We think the stealing private keys on most NGINX servers is at least extremely hard and, likely, impossible. Even with Apache, which we think may be slightly more vulnerable, and we do not use at CloudFlare, we believe the likelihood of private SSL keys being revealed with the Heartbleed vulnerability is very low. That’s about the only good news of the last week."
Answering the Critical Question: Can You Get Private SSL Keys Using Heartbleed? | CloudFlare Blog