You probably know this web server blocks traffic from outside of Borty America. In the past few weeks, the number of hacking attempts to the web site have picked up dramatically.
Whether this means the Heartbleed flaw is working to actively compromise servers or whether script kiddies are being emboldened because Network Security folks are working overtime to lock down vulnerable servers isn’t clear.
I have yet to read a single news account pointing out that servers running Microsoft’s IIS are not vulnerable. They paid their own programmers to design, write, test and review the security of their own SSL implementation rather than relying in a German telecom programmer to add a new “feature” to this highly sensitive piece of software, with only one individual reviewing his work.
The entire premise of a keep alive message that echoes an arbitrary 64k payload seems like a tool to speed up the breaking of encryption keys. Fixing the “mistake” is not the only issue people need to think about. The open source “process” needs to be rethought. Unfortunately, it is likely the result will now be direct government oversight. The Internet has just become too important.
Too big to fail 🙂
Hmm, some IT folks told me I shouldn’t trust my web hosting server to IIS. That was 7 or 8 years ago and I’m still running it.
I don’t have the data in front of me, but I have the sense that most serious corporations use IIS. It’s not free and takes people with training to use, but it leaves someone they are paying responsible and not having to explain why your system was hacked because some unsupervised German programmer decided on New Years Eve to add a new “feature”
Saying 2/3 of servers might be affected is misleading. A large portion of Linux servers are not using the damaged version of OpenSSL, and another group doesn’t have SSL enabled – but if you look at it as a percentage of activity, especially sensitive applications like online banking, I’ll pretty much guarantee they aren’t running Fedora.
That said, it’s still a really big deal, as people can escalate privileges. If you find a userid and password of someone with global admin privileges, it is hard to be sure they don’t have a hook somewhere.
The last few months in Chicago was being available to support the network guys locking down the internal network. It isn’t good enough to just set up a DMZ between your Internet facing web servers – you need to monitor and control all of the connections on the internal network. Several of their third party software vendors have VPN access in to access and fix their systems, but they can,t just be allowed to roam the WAN. If the 3rd party had a lapse in their own security and an intruder compromised their VPN, it could spread through the VPN