Community First Credit Union's Heart Bleeds

1 view
Skip to first unread message

inkrypto

unread,
Apr 9, 2014, 10:55:29 AM4/9/14
to jax...@googlegroups.com
Yep Educational Community Credit Union or Community First or whatever they call it this week, fucking sucks. so don't log in from starbucks

Inline image 1

Jordan Wiens

unread,
Apr 9, 2014, 11:06:03 AM4/9/14
to jax...@googlegroups.com
It doesn't matter whether you login from starbucks or not. No matter where /you/ login, anyone else on the internet can steal your info if you're logged in at all and your session information/credentials happen to be in memory at the time they dump it. 

Only fix is for them to patch in the fix, recompile without heartbeats, or upgrade the packages that do that for them. 

It's a bad (fun) bug. 


On Wed, Apr 9, 2014 at 10:55 AM, inkrypto <inkr...@gmail.com> wrote:
Yep Educational Community Credit Union or Community First or whatever they call it this week, fucking sucks. so don't log in from starbucks

Inline image 1

--
You received this message because you are subscribed to the Google Groups "Jacksonville CTF" group.
To unsubscribe from this group and stop receiving emails from it, send an email to jaxctf+un...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

inkrypto

unread,
Apr 9, 2014, 11:10:30 AM4/9/14
to jax...@googlegroups.com
holy shit!

Ben Finke

unread,
Apr 9, 2014, 11:58:33 AM4/9/14
to jax...@googlegroups.com
Yeah, heartbleed stinks (if you're a blue teamer).  I wonder how many private keys have been compromised today alone?

-Ben

Ralph Figueroa

unread,
Apr 10, 2014, 7:35:33 AM4/10/14
to jax...@googlegroups.com

This is no surprise. However, the attention this is getting from the media means to me that we may have had a whole lot of breaches happen at once.

Alex Stanford

unread,
Apr 10, 2014, 8:34:21 PM4/10/14
to jax...@googlegroups.com

AND reissue the cert because the priv key may have already been compromised. Patching alone is not enough.

Alex Stanford

unread,
Apr 11, 2014, 9:12:48 AM4/11/14
to jax...@googlegroups.com

Also, be sure that the cert is revoked. Don't buy a new cert and forget to have the old one added to the CRL.

Gene Cronk

unread,
Apr 11, 2014, 9:28:53 AM4/11/14
to jax...@googlegroups.com
XKCD....excellent as always

http://xkcd.com/1354/

Ben Finke

unread,
Apr 11, 2014, 9:36:21 AM4/11/14
to jax...@googlegroups.com
Agreed, excellent as always!!
Reply all
Reply to author
Forward
0 new messages