오늘은 아침부터 OpenSSL 취약점이 발생하여 그 동은 안전하게만 여겨졌던 SSL도 보안에 노출되어 정보 유출이 가능하다고 하네요.

테스트 사이트 및 간단한 점검방법 설명입니다.

※ 취약점 온라인 테스트

※ 전용 스캐너(GUI)


다운로드 :
http://www.rapid7.com/resources/free-security-software-downloads/openssl-heartbleed-vulnerability-scanner.jsp


※ Nmap 스캐닝 툴

nmap -p 443 --script ssl-heartbleed 점검사이트

- 필수 스크립트
https://svn.nmap.org/nmap/scripts/ssl-heartbleed.nse ← scripts 폴더에 복사
https://raw.githubusercontent.com/nmap/nmap/master/nselib/tls.lua ← nselib 폴더에 복사


※ 취약점 설명

The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs).

The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.

http://www.heartbleed.com 

Posted by n3015m
:
BLOG main image
'네오이즘'의 보안LAB 블로그입니다........... n3oism@gmail.com by n3015m

카테고리

분류 전체보기 (228)
[ HappyDevTool ] (29)
[ HappyToolRelease ] (4)
[Book] (6)
[ Security Studies ] (0)
- CII (2)
- BigData (2)
- Web Hacking (10)
- SQL Injection (25)
- Mobile Security (9)
- Network (6)
- OperatingSystem (4)
- Malware & Reversing (4)
- Phishing (5)
- Compliance (0)
- Programming (13)
- Tools (13)
- IoT (6)
- etc (21)
[Pentration Testing] (3)
[OS X] (4)
[ Security Trends ] (16)
[ Fixing Guideline ] (7)
My Way, My Life (34)
About Me (2)

최근에 올라온 글

최근에 달린 댓글

최근에 받은 트랙백

Total :
Today : Yesterday :