Bitcoin Forum
May 10, 2024, 10:41:38 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Is this server vulnerable to Heartbleed OpenSSL vulnerability?  (Read 1111 times)
LightRider (OP)
Legendary
*
Offline Offline

Activity: 1500
Merit: 1021


I advocate the Zeitgeist Movement & Venus Project.


View Profile WWW
April 08, 2014, 12:05:36 PM
 #1

www.heartbleed.com

Bitcoin combines money, the wrongest thing in the world, with software, the easiest thing in the world to get wrong.
Visit www.thevenusproject.com and www.theZeitgeistMovement.com.
Activity + Trust + Earned Merit == The Most Recognized Users on Bitcointalk
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715337698
Hero Member
*
Offline Offline

Posts: 1715337698

View Profile Personal Message (Offline)

Ignore
1715337698
Reply with quote  #2

1715337698
Report to moderator
dserrano5
Legendary
*
Offline Offline

Activity: 1974
Merit: 1029



View Profile
April 08, 2014, 12:21:13 PM
 #2


http://filippo.io/Heartbleed/#bitcointalk.org
EFS
Staff
Legendary
*
Offline Offline

Activity: 3724
Merit: 2078


Crypto Swap Exchange


View Profile
April 08, 2014, 01:13:39 PM
 #3

Quote
All good, bitcointalk.org seems not affected!

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
BitPappa
Sr. Member
****
Offline Offline

Activity: 431
Merit: 261



View Profile WWW
April 08, 2014, 07:04:23 PM
 #4


I'm wondering, does this just test if the bug is present? If so, that means if the file with the bug is updated, but the certificate is not updated, it might give a false negative… I'm just theorizing generally, not assuming that's the case with BitcoinTalk.

I think the filippo site is drowning right now, I haven't got it to give me any results lately.

Bit_Happy
Legendary
*
Offline Offline

Activity: 2100
Merit: 1040


A Great Time to Start Something!


View Profile
April 08, 2014, 10:15:26 PM
 #5

Yes, we need to know if the cert was changed after the server was updated.

Blaater
Sr. Member
****
Offline Offline

Activity: 462
Merit: 262


View Profile
April 08, 2014, 10:22:49 PM
 #6

Quote
All good, bitcointalk.org seems not affected!

I am getting:
Quote

bitcointalk.org IS VULNERABLE.
Bit_Happy
Legendary
*
Offline Offline

Activity: 2100
Merit: 1040


A Great Time to Start Something!


View Profile
April 08, 2014, 10:30:12 PM
 #7


That site wants the hostname of a server (i.e. server1.domain.com) not just a domain name.

DeathAndTaxes
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
April 08, 2014, 10:32:19 PM
 #8


Um you do know that bitcoin.og is both a domian name and a host name.   Most sites use a null or naked domain as their host.  There is very likely no something.bitcointalk.org.

Now if the site was forum.bitcointalk.org you couldn't enter just bitcointalk.org.

Quote
Retrieving DNS records for bitcointalk.org...
DNS servers
dns2.registrar-servers.com [208.64.122.242]
dns5.registrar-servers.com [208.64.122.242]
dns1.registrar-servers.com [173.245.58.17]
dns4.registrar-servers.com [173.245.58.17]
dns3.registrar-servers.com [69.197.21.28]

Answer records
bitcointalk.org      A   109.201.133.195   7200s

Yup only A record points to bitcointalk.org not something.bitcointalk.org
Bit_Happy
Legendary
*
Offline Offline

Activity: 2100
Merit: 1040


A Great Time to Start Something!


View Profile
April 09, 2014, 02:14:25 AM
 #9

...
Um you do know that bitcoin.og is both a domian name and a host name....


Thanks, I had it confused with the Linux hostname command which gives server1.example.com.
I used to set up servers "way too often", but I found a reliable VPS and haven't had to move and rebuild for almost 2.5 years.  Smiley

NLNico
Legendary
*
hacker
Offline Offline

Activity: 1876
Merit: 1289


DiceSites.com owner


View Profile WWW
April 09, 2014, 02:29:26 AM
 #10

I'm wondering, does this just test if the bug is present?
Yes.

If so, that means if the file with the bug is updated, but the certificate is not updated, it might give a false negative…
Not really a false negative because the vulnerability is not any more there. But yeh if your server was once vulnerable, you should consider the private key of the certificate as stolen and potentially even users' cookies/passwords. That's why I assume bitcointalk.org never had this vulnerability because I am sure theymos would have made a topic about it then (with a warning to change our passwords to be sure.)

LightRider (OP)
Legendary
*
Offline Offline

Activity: 1500
Merit: 1021


I advocate the Zeitgeist Movement & Venus Project.


View Profile WWW
April 15, 2014, 12:50:38 AM
 #11

Hmm... I thought that the leaked memory would only include OpenSSL-specific stuff, but I did some more research and I think you're right: user passwords could have possibly been leaked, though it would have been difficult.

I'll log everyone out and add this info to the header.

Bitcoin combines money, the wrongest thing in the world, with software, the easiest thing in the world to get wrong.
Visit www.thevenusproject.com and www.theZeitgeistMovement.com.
Justin00
Legendary
*
Offline Offline

Activity: 910
Merit: 1000


★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
April 15, 2014, 01:06:30 AM
 #12

that site does not actually check correctly.
it reported a number of sites not vulnerable that were vulnerable.
do not trust it, to check anyways.

This one which another user posted up is good and actually accurate - https://www.ssllabs.com/ssltest/analyze.html?d=bitcointalk.org

alternatively if you have a unix box with python 2.7 (if i recall correctly) just download the python script and test yourself.




Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!