More
The Heartbleed Bug: OpenSSL

The Heartbleed Bug: OpenSSL

08-04-2014 12:50:12
The Heartbleed Bug also known as CVE-2014-0160 is a vulnerability within the OpenSSL cryptographic software library that enables all the SSL/TLS protected information to be stolen under normal conditions. The Heartbleed Bug allows attackers to easily implement MITM, phishing and data theft. Unless something is done soon, Heartbleed could potentially devastate the reputation of the sixteen year old OpenSSL collaborative and cause millions of dollars worth of damage. 
 
The way the bug works is fairly simple, it allows anyone with internet access to read the memory of the systems protected by the vulnerable versions of the OpenSSL Software. This compromises the private keys being used and allows attackers to eavesdrop on what is supposed to be encrypted traffic. Considering the long exposure time and the large amount of jeopardized private keys this Bug should be taken very seriously. 
 
This is not a SSL/TLS Design flaw. The reason for these issues is related to a programming mistake on the behalf of OpenSSL. If you are currently using OpenSSL and you think that your secure connection has been compromised please contact us and we can help you find a better and more reliable solution.
 
Server vulnerability you can check with our tool: https://sslguru.com/heartbleed

Recent Posts

Comodo is now Sectigo
09-11-2018 12:54:30

According to previous announcements, a year after the acquisition of Comodo Group by Francisco Partners, on November 1 Comodo CA announced that from now on it is changing its brand to Sectigo [pronounced. sec-tee-go]. The goal of rebranding is consistency in company communication and better dedication to what Comodo is doing now.

Comodo is now Sectigo
European Cyber Security Month 2018
27-09-2018 10:46:21

The European Union Agency for Network and Information Security (ENISA), which is the center of knowledge about cyber security in Europe, organizes as every year in October the European Cyber Security Month. The campaign is starting in a few days. What is its purpose and how can you participate in it?

European Cyber Security Month 2018
GDPR and SSL certificate. Is encryption necessary for compliance with the GDPR?
18-05-2018 15:47:40

General Data Protection Regulation (GDPR) is a 99-article regulation meant to protect the private data of Europeans in IT systems. Announced in 2016, covers a broad variety of topics and will go into effect as a requirement on May 25, 2018. GDPR applies to any company doing business in Europe even if it is located elsewhere.

GDPR and SSL certificate. Is encryption necessary for compliance with the GDPR?
more posts