Critical severity Famous Malware

Heartbleed

A 2014 OpenSSL bug that let anyone read server memory, including private keys.

Overview

CVE-2014-0160 failed to bounds-check a heartbeat request, so a client could ask the server to echo back far more memory than it had sent.\nAny TLS private key, session cookie or credential resident in that memory was potentially exposed, and nothing in the logs showed it happening.\nIt forced a global certificate-revocation and reissue effort.

Indicators of Compromise

Signals that suggest this is present on a system.

  • OpenSSL 1.0.1 through 1.0.1f in service
  • Certificates issued before April 2014 never rotated
  • Heartbeat extension enabled

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used