Showing posts with label heartbleed. Show all posts
Showing posts with label heartbleed. Show all posts

Tuesday, April 29, 2014

19-Year-Old Student Arrested for Exploiting Heartbleed Bug to Steal Data

Heartbleed vulnerability which was headlines from last two weeks have once again made a new headline. A 19 years old, Stephen Arthuro Solis-Reyes an computer science student of Western University have been arrested by the Royal Canadian Mounted Police (RCMP). He is been charged with the unauthorized access of the computer and criminal mischief in relation to the data breach of taxpayer’s private information from the Canada Revenue Agency (CRA) website.

Assistant Commissioner Gilles Michaud said in a statement-

    “The RCMP treated this breach of security as a high priority case and mobilized the necessary resources to resolve the matter as quickly as possible,”

After the public disclosure of the  Hearbleed, Stephen have exploited the vulnerability present on the Canada Revenue Agency (CRA) website and extract the private and sensitive information, including the social insurance numbers from the company’s system, before the computers were patched.

“Investigators from National Division, along with our counterparts in ‘Ontario’ Division have been working tirelessly over the last four days analyzing data, following leads, conducting interviews, obtaining and executing legal authorizations and liaising with our partners,” Assistant Commissioner  added.

 Heartbleed is one of the critical and biggest vulnerability in the recent history, that was found in the OpenSSL's implementation of the TLS/DTLS heartbeat extension. This vulnerability allows the hackers  to steal major credentials data from the affected server.

Exploiting the Heartbleed bug itself rarely leaves any traces, unless the attacker is not sending millions of heartbeats continuously from his own IP addresses. "The fact that they were able to trace it back to someone implies that it is not the work of organized crime or a professional hacker. It would be someone of very low skill." said Mark Nunnikhoven, Trend Micro.

Stephen Arthuro was arrested at his residence without incident on April 15 and is scheduled to appear in court in Ottawa on July 17, 2014, RCMP reported. The police also seized computer equipment from his residence, while the investigation is ongoing.

Obamacare website flagged in Heartbleed review - Heartbleed programming flaw

People who have accounts on the enrollment website for President Barack Obama's signature health care law are being told to change their passwords following an administration-wide review of the government's vulnerability to the confounding Heartbleed Internet security flaw.
Senior administration officials said there is no indication that the HealthCare.gov site has been compromised and the action is being taken out of an abundance of caution. The government's Heartbleed review is ongoing, the officials said, and users of other websites may also be told to change their passwords in the coming days, including those with accounts on the popular WhiteHouse.gov petitions page.

The Heartbleed programming flaw has caused major security concerns across the Internet and affected a widely used encryption technology that was designed to protect online accounts. Major Internet services have been working to insulate themselves against the problem and are also recommending that users change their website passwords.

Officials said the administration was prioritizing its analysis of websites with heavy traffic and the most sensitive user information. A message that will be posted on the health care website starting Saturday reads: "While there's no indication that any personal information has ever been at risk, we have taken steps to address Heartbleed issues and reset consumers' passwords out of an abundance of caution."

The health care website became a prime target for critics of the Obamacare law last fall when the opening of the insurance enrollment period revealed widespread flaws in the online system. Critics have also raised concerns about potential security vulnerabilities on a site where users input large amounts of personal data.

The website troubles were largely fixed during the second month of enrollment and sign-ups ultimately surpassed initial expectations. Obama announced this week that about 8 million people had enrolled in the insurance plans.

The full extent of the damage caused by the Heartbleed is unknown. The security hole exists on a vast number of the Internet's Web servers and went undetected for more than two years. Although it's conceivable that the flaw was never discovered by hackers, it's difficult to tell.

The White House has said the federal government was not aware of the Heartbleed vulnerability until it was made public in a private sector cyber security report earlier this month. The federal government relies on the encryption technology that is impacted - OpenSSL - to protect the privacy of users of government websites and other online services.

The Homeland Security Department has been leading the review of the government's potential vulnerabilities. The Internal Revenue Service, a widely used website with massive amounts of personal data on Americans, has already said it was not impacted by Heartbleed.

"We will continue to focus on this issue until government agencies have mitigated the vulnerability in their systems," Phyllis Schneck, DHS deputy undersecretary for cybersecurity and communications, wrote in a blog post on the agenda website. "And we will continue to adapt our response if we learn about additional issues created by the vulnerability."

Officials wouldn't say how government websites they expect to flag as part of the Heartbleed security review, but said it's likely to be a limited number. The officials insisted on anonymity because they were not authorized to discuss the security review by name.

Read more: http://www.cbsnews.com/news/obamacare-website-flagged-in-heartbleed-review/

Heartbleeding Out: Internet Security Bug Even Worse Than First Believed

Warnings from Cisco and Juniper suggest the encryption bug is much more widespread—and potentially catastrophic—than initially thought as the networking companies check the vulnerability of their browsers

The Heartbleed Internet security bug is shaping up to be worse than researchers first realized, possibly compromising routers and other networking infrastructure for a variety of companies.

Cisco, one of the world’s top networking equipment manufacturers, confirmed Thursday that it’s investigating dozens of its routers and video teleconferencing devices and software for the Heartbleed vulnerability. Juniper Networks, another top networking company, has also alerted clients some of its equipment has been compromised by Heartbleed. A message posted to Juniper’s service website Friday said many of its systems would be offline through Saturday while the company performs maintenance.

Cisco and Juniper have warned that detecting and closing the Heartbleed vulnerability in their equipment won’t happen overnight, leaving the companies’ clients in a state of anxious limbo as they work to determine if any of their data has been compromised.

The Heartbleed vulnerability takes advantage of a flaw in OpenSSL, a free encryption protocol used by thousands of websites around the world to protect visitors’ sensitive data, such as usernames and passwords. Heartbleed essentially lets hackers get an undetectable look at the data transmitted between a user and a server after it’s been decrypted.

Heartbleed was introduced to OpenSSL about two years ago, but only became public knowledge this week. That disclosure forced many companies to scramble to patch their code before hackers could take advantage of the flaw. Many experts first believed Heartbleed’s impact might be limited to web servers, but Cisco’s and Juniper’s announcements suggest the bug is much more widespread—and potentially catastrophic—than initially thought.

The Department of Homeland Security said Friday that public-facing federal websites aren’t affected by the Heartbleed vulnerability. The government is also “continuing to coordinate across agencies” to keep federal websites protected from the bug, DHS said.

Read more: http://time.com/59390/heartbleed-internet-security-routers/

Heartbleed hackers target Mumsnet users

A leading UK site for parents and the Canadian tax authority have both announced they have had data stolen by hackers exploiting the Heartbleed bug.
Mumsnet, which says it has 1.5 million registered members, said that it believed that the cyber thieves may have obtained passwords and personal messages before it patched its site.
The Canada Revenue Agency said that 900 people's social insurance numbers had been stolen.
The BBC's Rory Cellan-Jones said the advice was to change passwords as soon as possible.