Page 1 of 1

Heartbleed vulnerability checking site

PostPosted: Apr 10th, '14, 17:40
by zxr250cc
Hi all,

I have been looking at the various web sites that I log into on a daily basis and have been using the HeartBleed checking site to see if they are vulnerable to that issue. So far every site I used is vulnerable, including this one. :shock:

Site: mageia.org
Server software: Apache/2.2.23 (Mageia/PREFORK-1.mga1)
Vulnerable: Definitely (known use OpenSSL)
SSL Certificate: Unsafe (created 1 year ago at Feb 7 00:00:00 2013 GMT)
Assessment: Wait for the site to update before changing your password

As we are all advised we need to change passwords in our sites, but to wait until they are patched before doing so, I am wondering if anyone is doing this for this site?

Link to checking site: https://lastpass.com/heartbleed/

This is not a promotion of that site and I only offer it since it shows useful info when used.

cheers

zxr250cc

Re: Heartbleed vulnerability checking site

PostPosted: Apr 10th, '14, 19:03
by isadora
Mageia seems to be okay right now:
All good, forums.mageia.org:443 seems fixed or unaffected!


I agree, noticed this yesterday and informed sysadmin.

Re: Heartbleed vulnerability checking site

PostPosted: Apr 10th, '14, 23:57
by zxr250cc
Yes, I was referring to using the site checking link at the lastpass site that checks for the vulnerability. The link I listed in my original post.

cheers all

Re: Heartbleed vulnerability checking site

PostPosted: Apr 11th, '14, 17:28
by jiml8
This site seems to be more comprehensive:

https://www.ssllabs.com/ssltest/index.html

It rates mageia.org as a "C" for ssl security, showing one vulnerabilty to exploits.

https://www.ssllabs.com/ssltest/analyze ... 70.188.116
https://www.ssllabs.com/ssltest/analyze ... 85.158.146

Re: Heartbleed vulnerability checking site

PostPosted: Apr 13th, '14, 19:31
by zxr250cc
I agree that this seems to be a more useful site. Thanks for the link.

What does a C grade mean?

cheers all

Re: Heartbleed vulnerability checking site

PostPosted: Apr 17th, '14, 21:59
by wilcal
Updates:
openssl-1.0.1e-1.5.mga3.i586.rpm dated 7 April 2014
openssl-1.0.1e-1.5.mga3.x86_64.rpm dated 7 April 2014
openssl-1.0.1e-8.2.mga4.i586.rpm dated 7 April 2014
openssl-1.0.1e-8.2.mga4.x86_64.rpm dated 7 April 2014
All included a heartbleed fix backported from openssl-1.0.1g

Re: Heartbleed vulnerability checking site

PostPosted: Apr 19th, '14, 10:11
by micjustin33
on a related note this page : https://www.ssllabs.com/ssltest/

will test your SSL settings to make sure that you have all the old insecure protocols disabled.

It also tests for BEAST attack and would imagine they will add support for Heartbleed bug soon'ish

Re: Heartbleed vulnerability checking site

PostPosted: Apr 19th, '14, 19:27
by doktor5000
Was already mentioned three posts before ;)