Vulnerabilities / Threats
04:20 PM
Connect Directly

OpenSSL Says Breach Did Not Involve Corrupted Hypervisor

Hosting provider's compromised password system, not a hacked hypervisor, led to defacing of site, site reps say – after VMware cries foul.

Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View
User Rank: Moderator
1/7/2014 | 2:37:33 PM
Locking down the hypervisor
I sadly think we are going to see lots of these types of incidents as ports are left open in virtual environments, as well as faulty SSL policies.  The real threat to the hypervisor will probably come from an unsecured VM being accessed and somehow the hypervisor is accessed, or through the management console.  In a private environment it's a scary thought, but in a public environment where multiple companies share the same hypervisor, it's the stuff that would keep security folks up at night.
User Rank: Ninja
1/4/2014 | 6:24:06 PM
The Turkish hack was a just a dry run-
Next time, however, it is doubtful the next crop of hackers will be so warm/fuzzy.  Regardless, this is a breach that should underscore security is dynamic.  It is simply no longer enough to rest on the laurels of hard to hack 'nux distros and proclaim impregnability.
User Rank: Apprentice
1/3/2014 | 7:13:51 PM
First it was, then it wasn't
I like the speedy resolution of this issue. There's bound to be some questions at a site as sensitive as OpenSSL when an incident occurs, and the site administrators were on the right track when they pointed toward the hosting service server, VMware had the courage of its convictions to say no, it was not the hypervisor, when OpenSSL first pointed in that direction, and indeed, it was password management on the hosting site. Multiple parties looking at the problem came up with the right answers quickly and pretty transparently. Salud.
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-08
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Published: 2015-10-06
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 21335999.

Published: 2015-10-06
Bluetooth in Android before 5.1.1 LMY48T allows attackers to remove stored SMS messages via a crafted application, aka internal bug 22343270.

Published: 2015-10-06
mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22954006.

Published: 2015-10-06
The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23050463.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.