Vulnerabilities / Threats
1/3/2014
04:20 PM
Connect Directly
Twitter
RSS
E-Mail

OpenSSL Says Breach Did Not Involve Corrupted Hypervisor

Hosting provider's compromised password system, not a hacked hypervisor, led to defacing of OpenSSL.org site, site reps say – after VMware cries foul.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Stratustician
50%
50%
Stratustician,
User Rank: Moderator
1/7/2014 | 2:37:33 PM
Locking down the hypervisor
I sadly think we are going to see lots of these types of incidents as ports are left open in virtual environments, as well as faulty SSL policies.  The real threat to the hypervisor will probably come from an unsecured VM being accessed and somehow the hypervisor is accessed, or through the management console.  In a private environment it's a scary thought, but in a public environment where multiple companies share the same hypervisor, it's the stuff that would keep security folks up at night.
asksqn
50%
50%
asksqn,
User Rank: Ninja
1/4/2014 | 6:24:06 PM
The Turkish hack was a just a dry run-
Next time, however, it is doubtful the next crop of hackers will be so warm/fuzzy.  Regardless, this is a breach that should underscore security is dynamic.  It is simply no longer enough to rest on the laurels of hard to hack 'nux distros and proclaim impregnability.
cbabcock
50%
50%
cbabcock,
User Rank: Apprentice
1/3/2014 | 7:13:51 PM
First it was, then it wasn't
I like the speedy resolution of this issue. There's bound to be some questions at a site as sensitive as OpenSSL when an incident occurs, and the site administrators were on the right track when they pointed toward the hosting service server, VMware had the courage of its convictions to say no, it was not the hypervisor, when OpenSSL first pointed in that direction, and indeed, it was password management on the hosting site. Multiple parties looking at the problem came up with the right answers quickly and pretty transparently. Salud.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-2808
Published: 2015-04-01
The PRNG implementation in the DNS resolver in Bionic in Android before 4.1.1 incorrectly uses time and PID information during the generation of random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a rel...

CVE-2014-9713
Published: 2015-04-01
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.

CVE-2015-0259
Published: 2015-04-01
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.

CVE-2015-0800
Published: 2015-04-01
The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2...

CVE-2015-0801
Published: 2015-04-01
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.