Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

4/11/2014
10:00 AM
Connect Directly
Google+
Twitter
RSS
E-Mail

Free Heartbleed-Checker Released for Firefox Browser

Browser plug-ins arrive for Firefox and Chrome that scan websites for Heartbleed risk

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Randy Naramore
50%
50%
Randy Naramore,
User Rank: Ninja
4/14/2014 | 4:18:47 PM
Re: Great tools
Chrome Checker is doing well for me also.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/14/2014 | 9:11:54 AM
Re: Different Solutions
I second Ryan's question about where other DR community members are in their remediation efforts for Heartbleed. We've collected some data in our online flash poll (see column on the far right or click here). But so far about 65 percent of respondents have installed or in the process of installing the update and 40 percent are replacing digital certificates. 

If you haven't taken the poll, check it out. And also let's talk about what you are (or aren't doing about it) in the the comments. 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/11/2014 | 6:13:59 PM
Different Solutions
These checkers are very nifty. From a corporate standpoint, my company ran vulnerability scans to check and see if any of our servers were running the OpenSSL with the HeartBeat extension. What are other methods people have been using and what steps were taken to remediate?
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
4/11/2014 | 10:58:41 AM
Great tools
I just tried the Chromebleed checker. Very cool! Thanks Kelly for reportng this and also to Jamie Hoyle (Chromebleed) and Tom Brennan (Firefox) for developing these tools. 
Greater Focus on Privacy Pays Off for Firms
Robert Lemos, Contributing Writer,  1/27/2020
Average Ransomware Payments More Than Doubled in Q4 2019
Jai Vijayan, Contributing Writer,  1/27/2020
Emerging Long-Range WAN Networks Vulnerable to Hacking, Compromise
Jai Vijayan, Contributing Writer,  1/28/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Physical Security Privilege Escalation
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-3719
PUBLISHED: 2020-01-29
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2020-3758
PUBLISHED: 2020-01-29
Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2020-8432
PUBLISHED: 2020-01-29
In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity was introduced when attempting to fix a memory leak identifi...
CVE-2020-3710
PUBLISHED: 2020-01-29
Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
CVE-2020-3711
PUBLISHED: 2020-01-29
Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.