Vulnerabilities / Threats
1/3/2014
04:20 PM
Connect Directly
Twitter
RSS
E-Mail

OpenSSL Says Breach Did Not Involve Corrupted Hypervisor

Hosting provider's compromised password system, not a hacked hypervisor, led to defacing of OpenSSL.org site, site reps say – after VMware cries foul.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Stratustician
50%
50%
Stratustician,
User Rank: Moderator
1/7/2014 | 2:37:33 PM
Locking down the hypervisor
I sadly think we are going to see lots of these types of incidents as ports are left open in virtual environments, as well as faulty SSL policies.  The real threat to the hypervisor will probably come from an unsecured VM being accessed and somehow the hypervisor is accessed, or through the management console.  In a private environment it's a scary thought, but in a public environment where multiple companies share the same hypervisor, it's the stuff that would keep security folks up at night.
asksqn
50%
50%
asksqn,
User Rank: Apprentice
1/4/2014 | 6:24:06 PM
The Turkish hack was a just a dry run-
Next time, however, it is doubtful the next crop of hackers will be so warm/fuzzy.  Regardless, this is a breach that should underscore security is dynamic.  It is simply no longer enough to rest on the laurels of hard to hack 'nux distros and proclaim impregnability.
cbabcock
50%
50%
cbabcock,
User Rank: Apprentice
1/3/2014 | 7:13:51 PM
First it was, then it wasn't
I like the speedy resolution of this issue. There's bound to be some questions at a site as sensitive as OpenSSL when an incident occurs, and the site administrators were on the right track when they pointed toward the hosting service server, VMware had the courage of its convictions to say no, it was not the hypervisor, when OpenSSL first pointed in that direction, and indeed, it was password management on the hosting site. Multiple parties looking at the problem came up with the right answers quickly and pretty transparently. Salud.
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7052
Published: 2014-10-19
The sahab-alkher.com (aka com.tapatalk.sahabalkhercomvb) application 2.4.9.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7056
Published: 2014-10-19
The Yeast Infection (aka com.wyeastinfectionapp) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7070
Published: 2014-10-19
The Air War Hero (aka com.dev.airwar) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7075
Published: 2014-10-19
The HAPPY (aka com.tw.knowhowdesign.sinfonghuei) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7079
Published: 2014-10-19
The Romeo and Juliet (aka jp.co.cybird.appli.android.rjs) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.