Heart bleed Vulnerability - testing tool

By : Administrator
Published 9th April 2014 |
Read latest comment - 1st May 2014

You've probably seen or heard about the current security exploit that Google and a Finnish security company have found.

If not, you can read the details here:

Heartbleed Bug: Public urged to reset all passwords

 

 

 

 

Your ISP should be patching your servers if they haven't already, but here is a handy testing tool to see if your website is affected:

https://www.ssllabs.com/ssltest/index.html


Steve Richardson
Gaffer of My Local Services
My Local Services | Me on LinkedIn
Comments

Well our infrastructure and servers were patched last, and have a clean bill of health. So that means there are no security vulnerabilities or issues with any directory or forum members accounts.

Annoying not to have an A+ We've been marked down due to not supporting forward secrecy to Microsoft Browser Internet Explorer Version 6 

Anyone still using IE 6 - throw it in the bin, it's time to upgrade! Latest version of IE is now 11.

Remember if you want to test your own or someone else's website, then here's the testing tool:

https://www.ssllabs.com/ssltest


Steve Richardson
Gaffer of My Local Services
My Local Services | Me on LinkedIn

saw netmums got caught out with this. Shouldn't their hosting company have dealt with this? 

anyone else had any problems?


Clive

Unless you have been living under a rock, you will have heard about the website security flaw called Heartbleed.

It seems the message still hasn't got out to a lot of websites, and numerous sites big and large are still exposed, weeks after the issue was first flagged, putting them at serious risk.

Norton Antivirus has released a simple and straightforward checker, which you can test either your own website, or anyone else's if you are concerned about security.

http://safeweb.norton.com/heartbleed


Steve Richardson
Gaffer of My Local Services
My Local Services | Me on LinkedIn

dont know if anybody saw this coming, i certainly didn't.

i was thinking, which was more serious; heartbleed or goto-fail. on reflection, the heartbleed is CONSIDERABLY worse.

for those who dont know: goto-fail (the apple ssl bug) meant that basically any ssl cert would pass, so it would be relatively easy to dupe a site and collect information. fairly targeted and specific to apple devices.

heartbleed though, would allow an attacker to breach server security and obtain all of the information in memory on the server. get that information, and you can get anything; personal details, files, access logs, anything essentially.


Thanks,
CD2 Solutions

There is a lot of confusion with this or maybe its me  if this was the security breach of the decade, should we change all of our passwords or not? Or we would know by now if our data or details were stolen?


Shakester

This Thread is now closed for comments