X
Settings
Language

Country

Framework language
Choose the country,language and framework settings
Privacy
HTTPS + POST : An encrypted SSL(HTTPS) connection ensuring your privacy. The search variables like keywords, etc. are encrypted and masked.
HTTPS + GET : The data transfer is enrypted but search variables displayed in the URL.
HTTP + GET : Non encrypted datatransfer
SSL key exchange / Cipher
Chromium based browsers might not work with the STRONG+ cipher set! You need to delete your settings cookie if you cannot build up an SSL connection. Try the STRONG cipher set instead.
The FAST cipher set is only recommended for outdated browser which are still using SSL3 or do only support weak ciphers for the key exchange. Do not use this cipher set if you are using software which is up to date!
Session key extension

Bind Session to IP
These two settings will improve the security of your session. By giving an additional session salt and/or binding your session to your current IP address your new session will be secured individually making it almost 100% unbreakable for any random hacking attempt and man in the middle attacks! If you change one of those values your current session will be reinitiated! This means you will be logged out if you are logged in right now. Check your session security settings (user details), if you want to kill remaining sessions. It is not recommended to bind your IP to your session if you are using a VPN/PROXY/ISP Network with altering outbound IPs since you will be logged out everytime your IP changes.
World Wide Web:
primary
secondary
Images:
primary
secondary
Thumbnails
Show external thumbnails and images.
Count of search results per page
Content filter

Violence
Filter adult material


Parental lock: with setting a password you are activating the parental lock. You are able to reset it by typing in the correct password clicking reset and saving the settings. To use the child protection properly you need to create a separate system account for your child with no write access to cookies

Length of descriptions
Activate social platform plugins
With activating this option social plugins embed to this website will get loaded automatically. You will automatically accept all terms of used social plugin hosters by setting activated. Please reconsider our terms and links to related terms and datasecurity for more information
Advertisements
Color style
MENU:
INPUT/SELECT BG:
INPUT/SELECT TEXT-COLOR:
HEADINGS:
LINK TEXT-COLOR:
CONTENT TEXT-COLOR:
Background Image
Save Settings
Close Settings
🗙

Blog

  • Whussup.net
  • Blog
Heartbleed - OpenSSL TLS Heartbeat Bug
Translations: en

Der Heartbleed OpenSSL Bug betrifft nicht nur Linux Nutzer, auch Server von Konzernen, Banken, etc., die die anfälligen OpenSSL Versionen nutzen sind betroffen.

Kurz gesagt ermöglicht dieser Bug dem Angreifer das Wiederherstellen der Primären und sekundären Schlüssel, die zum Aufbau der Verbindung und zum Verschlüsseln des Inhalts genutzt werden. Hat der Angreifer die Schlüssel reproduziert, kann er ohne Problem jede folgende Verbindung entschlüsseln oder auch den Server/Client mimen, sprich Man-In-The-Middle Attacken ausführen, um Schadcode einzuschleusen oder an weitere Daten zu gelangen.

Die Passwörter zu ändern und für jeden Dienst ein separates Passwort anzulegen bleibt generell anzuraten.

Ob ein Server von dem Problem betroffen ist, kann man mit einem online Tool testen: https://www.ssllabs.com/ssltest/analyze.html

Die betroffenen OpenSSL Versionen:

 - OpenSSL 1.0.1 bis inklusive 1.0.1f

 betroffenen Betriebssysteme:

- Debian Wheezy (stable), OpenSSL 1.0.1e-2+deb7u4

- Ubuntu 12.04.4 LTS, OpenSSL 1.0.1-4ubuntu5.11

- CentOS 6.5, OpenSSL 1.0.1e-15

- Fedora 18, OpenSSL 1.0.1e-4

- OpenBSD 5.3 (OpenSSL 1.0.1c 10 May 2012) and 5.4 (OpenSSL 1.0.1c 10 May 2012)

- FreeBSD 10.0 - OpenSSL 1.0.1e 11 Feb 2013

- NetBSD 5.0.2 (OpenSSL 1.0.1e)

- OpenSUSE 12.2 (OpenSSL 1.0.1c)

- Android OS Jelly Bean 4.1.1

 

Wie man dieses Problem behebt:

Das OpenSSL Update auf 1.0.1.g  bzw der Patch vom 07.04.2014 behebt den Heartbeat Bug; https://github.com/openssl/openssl/commit/731f431497f463f3a2a97236fe0187b11c44aead

Die meisten Distributionen haben die OpenSSL Version mittlerweile gepatcht, daher genügt ein Update des OpenSSL Pakets und aller abhängiger Pakete über den jeweiligen Paketmanager. Ein Downgrade auf 0.98 wäre ebenfalls möglich.

Debian Wheezy:

die folgenden repos der /etc/apt/sources.list  hinzufügen:

deb http://security.debian.org/ wheezy/updates main
deb-src http://security.debian.org/ wheezy/updates main

Packete updaten :

#/bin/bash
apt-get update
apt-get upgrade

Gentoo Linux:

#/bin/bash
emerge --ask --oneshot --verbose >=dev-libs/openssl-1.0.1g

Nachdem man die openssl libs und bins upgedatet hat, muss man alle Dienste, die davon abhängig sind neu starten.

 

 

 

Quellen:

https://github.com/openssl/openssl/commit/731f431497f463f3a2a97236fe0187b11c44aead

http://heartbleed.com/

Posted at 2014-04-08 06:06:31
( updated at 2014-05-02 23:33:12 )
in securityBash

Tags:
OpenSSLHeartbeatHeartbleedBug
  • all entries
  • Messages
  • Manuals
  • security

  • Whussup.net
    • Home
    • General Information
    • Contact
    • Blog
    • Campaigns
    • Data Protection & Terms Of Use

  • Donations
Paypal

    • Tools
      • Github
      • Check IP Address
    0
    Guest
    • Whussup.net
      • Home
      • General Information
      • Contact
      • Blog
      • Campaigns
      • Data Protection & Terms Of Use
      • Login
      • Logout
      • User Details
      • Create User Account
      • Settings
    • GAMES
    gear
    Language:
    Sort:
    Filter:
    Geolocation:
    Country:
    Google Domain:
    Simplified Chinese:
    AND search query:
    Search in URL:
    Search in URL - Filter:
    Contained search queries:
    Excluded search queries:
    OR search queries:
    related URL:
    Date:
    File type (Extension):
    Image size:
    Image type:
    Color:
    Dominant color:
    Copyright:



    Filter:
    Alternative Search Query
    Show All Indexes
    HD 3D game language-Filter country-Filter
    minimal length
    Maximal Length
    Free shippingSorting
    Condition
    Min.:

    Max.:
    Sorting:
    Title:Original Title:Description:Year: - Release Date:Genre:Language:Spoken Languages:Country:Duration: - Colour Mode:Dimensions:Soundtrack:Production Companies:Production Countries:
    ----------------------------------------
    Actors:Thanks:Literary:Art:Camera:Casting:Cinematography:Costume:Decoration:Directing:Directing (art):Directing (assistant):Editing:Lighting:Location:Makeup:Music:Other:Producing:Producing (design):Producing (management):Sound Technology And Electrics:Special Effects:Stunts:Logistics:Visual Effects:Literary:
    Suggestions
    Manual
    Plugin Name:generate
    >>
    *: