bk99.de entertain the web since 1997

Tracking down Heartbleed across several TLS services in the data centre

Summary

Manuel Schmitt describes an automated data centre scan for Heartbleed and the subsequent warning of affected customers. The scan covered HTTPS, IMAPS, POP3S, SMTP, submission, IMAP and POP3 with TLS. Affected customers were warned by email.

Ideas

  • A TLS bug affects not only HTTPS but also mail protocols with direct TLS or STARTTLS.
  • An installed update has no effect as long as vulnerable processes have not been restarted.
  • Providers can use their own view of the network to proactively alert customers to exposed services.

Insights

  • Vulnerability management only ends with running processes and renewed secrets.
  • A coordinated scan turns general security advisories into concrete information about who is affected.

Facts

  • In many of the responses, a missing service restart was the cause.

Recommendations

  • Take inventory of all processes that have loaded an affected library.
  • Restart services after the update and rotate potentially exposed keys and sessions.

References

Read the original article on Hostblogger

Search the Web Archive