{"id":38873,"date":"2014-04-25T09:52:58","date_gmt":"2014-04-25T09:52:58","guid":{"rendered":"http:\/\/blog.open-e.com\/?p=38873"},"modified":"2025-07-07T10:49:13","modified_gmt":"2025-07-07T10:49:13","slug":"is-your-heartbleeding","status":"publish","type":"post","link":"https:\/\/www.open-e.com\/blog\/is-your-heartbleeding\/","title":{"rendered":"Is your Heartbleeding?"},"content":{"rendered":"<p style=\"text-align: left;\">The Heartbleed bug, officially referenced as CVE-2014-0160, is already being coined as one of the biggest security threats since the mass adoption of the Internet &#8211; affecting millions of websites and services, including credit-card numbers, email accounts and a wide range of online commerce.<\/p>\n<div style=\"border: 1px solid #FF0000; padding: 5px; float: center; margin: 2px; font-size: 11px; width: 500px; text-align: justify;\">Heartbleed is a security bug in the OpenSSL cryptography library, which is widely used to secure Internet sites and applications. The OpenSSL &#8220;Heartbleed&#8221; vulnerability allows hackers to steal information protected by the SSL\/TLS encryption (it provides communication privacy and security on the Internet when it comes to email, web, IM or virtual private networks).<\/div>\n<p>Shortly speaking, Heartbleed shares the memory of a system protected by OpenSSL to anyone on the Internet.<\/p>\n<div style=\"border: #999999 1px solid; float: right; padding: 5px; margin: 2px; font-size: 10px; width: 190px; text-align: left; margin-left: 15px;\">\n<p>Dr Seggelmann, of M\u00fcnster in Germany, said the bug which introduced the flaw was &#8220;unfortunately&#8221; missed by him and a reviewer when it was introduced into the open source OpenSSL encryption protocol over two years ago.<\/p>\n<div style=\"font-size: 10px; text-align: left;\"><strong>Source: <a href=\"https:\/\/www.smh.com.au\/it-pro\/security-it\/man-who-introduced-serious-heartbleed-security-flaw-denies-he-inserted-it-deliberately-20140410-zqta1.html\" target=\"_blank\" rel=\"noopener noreferrer\">The Sydney Morning Herald<\/a><\/strong><\/div>\n<\/div>\n<p><b>Who reported it?<\/b><\/p>\n<p>According to<a title=\"OpenSSL\" href=\"https:\/\/www.openssl.org\/news\/secadv_20140407.txt\"> OpenSSL<\/a>, it was Neel Mehta from Google&#8217;s security team that reported the problem in the beginning of April. What&#8217;s really scary is that the bug slipped under the radar for so long.<\/p>\n<p>&nbsp;<\/p>\n<p><b>Am I affected by Heartbleed?<\/b><\/p>\n<p>To check if your website or application is vulnerable you can use <a href=\"https:\/\/community.rapid7.com\/community\/metasploit\/blog\/2014\/04\/09\/metasploits-heartbleed-scanner-module-cve-2014-0160\" target=\"_blank\" rel=\"noopener noreferrer\">Metasploit&#8217;s Brand New Heartbleed Scanner Module<\/a>.<\/p>\n<p>If you would like to check Open-E DSS V7, here&#8217;s an example of how to <a href=\"https:\/\/www.darkoperator.com\/installing-metasploit-in-ubunt\/\" target=\"_blank\" rel=\"noopener noreferrer\">install Metasploit Framework on Ubuntu<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p><b>Is Open-E software safe?<\/b><\/p>\n<p>Our team of developers tested the products with Metasploit&#8217;s Brand New Heartbleed Scanner Module and guarantee that all Open-E <a href=\"https:\/\/www.open-e.com\/products\/data-storage-software-v7\/\" target=\"_blank\" rel=\"noopener noreferrer\">Data Storage Software<\/a> products are secure. There is no need to update software or change passwords.<\/p>\n<p>&nbsp;<\/p>\n<div style=\"width: 609px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/imgs.xkcd.com\/comics\/heartbleed_explanation.png \"><img loading=\"lazy\" decoding=\"async\" class=\" \" src=\"https:\/\/imgs.xkcd.com\/comics\/heartbleed_explanation.png \" alt=\"\" width=\"599\" height=\"1277\" \/><\/a><p class=\"wp-caption-text\">CC Image courtesy of xkcd.com<\/p><\/div>\n<p>&nbsp;<\/p>\n<p><strong>Read more about the OpenSSL &#8220;Heartbleed&#8221; Vulnerbility:<\/strong><\/p>\n<p><a href=\"https:\/\/heartbleed.com\/\">https:\/\/heartbleed.com\/<\/a><\/p>\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Heartbleed\">https:\/\/en.wikipedia.org\/wiki\/Heartbleed<\/a>\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Heartbleed bug, officially referenced as CVE-2014-0160, is already being coined as one of the biggest security threats since the mass adoption of the Internet &#8211; affecting millions of websites&nbsp;&#8230;<\/p>\n","protected":false},"author":11,"featured_media":55884,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[29],"tags":[75,229,310,329,396,590,631],"class_list":["post-38873","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection","tag-attack","tag-dss-v7","tag-heartbleed","tag-https","tag-memory-leak","tag-security","tag-ssl"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.open-e.com\/blog\/wp-json\/wp\/v2\/posts\/38873","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.open-e.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.open-e.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.open-e.com\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.open-e.com\/blog\/wp-json\/wp\/v2\/comments?post=38873"}],"version-history":[{"count":1,"href":"https:\/\/www.open-e.com\/blog\/wp-json\/wp\/v2\/posts\/38873\/revisions"}],"predecessor-version":[{"id":55238,"href":"https:\/\/www.open-e.com\/blog\/wp-json\/wp\/v2\/posts\/38873\/revisions\/55238"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.open-e.com\/blog\/wp-json\/wp\/v2\/media\/55884"}],"wp:attachment":[{"href":"https:\/\/www.open-e.com\/blog\/wp-json\/wp\/v2\/media?parent=38873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.open-e.com\/blog\/wp-json\/wp\/v2\/categories?post=38873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.open-e.com\/blog\/wp-json\/wp\/v2\/tags?post=38873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}