OpenSSL 'Heartbleed' vulnerability lets attackers spy on secure Web traffic

Advertisement
By NDTV Correspondent | Updated: 8 April 2014 15:48 IST
OpenSSL 'Heartbleed' vulnerability lets attackers spy on secure Web traffic
A serious flaw in the implementation of OpenSSL, a fundamental security measure used by millions of websites, could expose sensitive information to attackers, including private messages, login credentials and credit card details. The vulnerability, officially tagged CVE-2014-0160 but also known as "Heartbleed", potentially allows attackers to retrieve entire OpenSSL decryption keys from an affected server, allowing them to decrypt secure communications without leaving any sign of brute-force intrusion.

In addition to stealing names, passwords, and message contents, attackers could also disguise themselves as legitimate users, thus eavesdropping and stealing all data flowing in and out of a vulnerable service.

The flaw is not in the encryption method itself, but rather in the way the OpenSSL implementation manages memory. If an attacker sends a deliberately malformed request to the server, it automatically responds with up to 64kB of data that might contain sensitive information.

The problem was known internally and a fix was being prepared, but security firm CloudFlare published information about it before the fix was ready for general release, in an attempt to promote a fix for their own OpenSSL implementation. Web administrators who rely on OpenSSL might not have time to apply the fix before attackers decide to put the flaw into practice.

OpenSSL versions 1.01 and 1.02 beta are affected. Administrators running 1.01f or earlier are advised to upgrade to 1.01g. A 1.02 beta 2 release will fix the vulnerability in the beta channel, when it is released. Security firm Codeomnicon estimates that at least 66 percent of active sites on the Internet could be affected, in addition to a massive number of email, instant message, virtual private network and various other services.

There is no known evidence of a successful attack on any person or organisation due to the Heartbleed vulnerability.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: Ground Zero, Detective Sherdil, Found S2, and More
  2. Oppo Reno 14 5G Series Teased to Launch in India Soon
  3. Vivo Y400 Pro 5G India Launch Today: All You Need to Know
  4. Samsung Galaxy M36 5G India Launch Date and Key Features Revealed
  5. Nothing Phone 3 to Get New Glyph Matrix Interface on the Rear Panel
  6. Poco F7 5G to Be Equipped With a Snapdragon 8s Gen 4 SoC
  7. BSNL Announces Name of Its 5G Service in India
  8. Realme Buds Air 7 Pro Review: Eye-Catching Design, Thumping Bass
  9. Vodafone Idea to Bring Direct-to-Device Satellite Connectivity to India
  1. Vivo Y400 Pro 5G Launching Today: Price in India, Expected Features and Specifications
  2. Fast Radio Bursts Reveal Universe’s Missing Matter Hidden in Cosmic Intergalactic Fog
  3. Apollo Astronauts Found Orange Glass Beads on the Moon, Scientists Now Know Why
  4. World’s Oldest Tailored Dress Found in Egyptian Tomb Dates Back Over 5,000 Years
  5. Ancient Footprints in White Sands Confirm Humans Reached America 23,000 Years Ago
  6. Humanoid Robot Achieves Controlled Flight Using Jet Propulsion and AI Systems
  7. Curiosity Rover Reaches Uyuni Quad, Begins New Mars Mapping and Surface Analysis Campaign
  8. NASA to Gather Reentry Imagery of European Commercial Capsule Using High-Altitude Aircraft
  9. ESA's Proba-3 Unveils First-Ever Artificial Solar Eclipse Images from Precision Satellite Formation
  10. My Hero Academia Final Season OTT Release Date Revealed: Everything You Need to Know
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.