Heartbleed

This forum will probably suffice for this category.
Protagonist
Level 2
Posts: 65
Joined: Wed 22 Jan, 2014 4:57 am
Location: My House

Heartbleed

Postby Protagonist » Thu 10 Apr, 2014 4:26 am

I am not really good with code and comptuer security. So I have to ask, is this site effected by the whole heartbleed vulnerability? What about Gamesreplays? Steam? Does anyone know?

For context, this is heartbleed:
http://www.washingtonpost.com/news/morn ... -internet/
User avatar
Lulgrim
Admin
Posts: 1311
Joined: Sun 03 Feb, 2013 9:44 pm
Location: Grimdark
Contact:

Re: Heartbleed

Postby Lulgrim » Thu 10 Apr, 2014 5:07 am

I understand fuck all about all that tbh. But as for Steam, http://www.incgamers.com/2014/04/heartb ... -say-valve
Uncle Milty
Shoutcaster
Posts: 84
Joined: Sat 27 Jul, 2013 3:51 pm
Location: Germany

Re: Heartbleed

Postby Uncle Milty » Thu 10 Apr, 2014 4:13 pm

only OpenSSL. OpenSSL provides a open source SSL version basically which is used for https. No https on this site afaik. User login should be using hash functions on the php authentication framework that doesn't transmit your login data plaintext-ly.
User avatar
Nuclear Arbitor
Level 5
Posts: 1106
Joined: Tue 12 Feb, 2013 2:56 am

Re: Heartbleed

Postby Nuclear Arbitor » Thu 10 Apr, 2014 8:04 pm

some of the newest versions of OpenSSL, 1.0.1 and 1.0.2, released in 2012, have some problems that enable 64kb of memory to be retrieved.

wikipedia has a decent overview of it.
User avatar
Lulgrim
Admin
Posts: 1311
Joined: Sun 03 Feb, 2013 9:44 pm
Location: Grimdark
Contact:

Re: Heartbleed

Postby Lulgrim » Fri 11 Apr, 2014 7:19 pm

User avatar
BaptismByLoli
Level 4
Posts: 830
Joined: Fri 28 Feb, 2014 8:20 am
Location: The Place Where Wishes Come True

Re: Heartbleed

Postby BaptismByLoli » Fri 11 Apr, 2014 7:28 pm

So basically, Heartbleed causes the server to go HAL 9000 and start spilling information about everything?
Image
Uncle Milty
Shoutcaster
Posts: 84
Joined: Sat 27 Jul, 2013 3:51 pm
Location: Germany

Re: Heartbleed

Postby Uncle Milty » Fri 11 Apr, 2014 8:44 pm

yes, as long as the SSL connection needs to be kept alive. Got fixed on newer versions tho and not all old versions were affected. really stupid bug

Return to “Random Stuff”



Who is online

Users browsing this forum: No registered users and 0 guests