6
Heartbleed Is your website vulnerable? By https://twitter.com/SylvainKalache

Heartbleed breach - Is your website vulnerable?

Embed Size (px)

DESCRIPTION

A security breach named "Heartbleed" has put passwords, credit cards and other sensitive data at risk. It affects OpenSSL versions 1.0.1 through 1.0.1f which concern 2/3 of the Web. Put in simple words, any encrypted traffic going over HTTPS is now totally unsecured.

Citation preview

Page 1: Heartbleed breach - Is your website vulnerable?

Heartbleed Is your website vulnerable?

By https://twitter.com/SylvainKalache

Page 2: Heartbleed breach - Is your website vulnerable?

On April 7th, 2014 a vulnerability was discovered in TLS implementations of OpenSSL 1.0.1

impacting 2/3 of the web.

Page 3: Heartbleed breach - Is your website vulnerable?

If you do not patch your web servers anyone can access encrypted traffic that could contain passwords & credit card numbers

Page 4: Heartbleed breach - Is your website vulnerable?

Fixing the issue happens in 2 steps: 1. Patching OpenSSL

2. Changing your certificate

Page 5: Heartbleed breach - Is your website vulnerable?

To check if you are vulnerable

go to http://filippo.io/Heartbleed/

Page 6: Heartbleed breach - Is your website vulnerable?

For more information about heart bleed: Technical explanation : https://www.schneier.com/blog/

archives/2014/04/heartbleed.html Is your favorite website safe: http://mashable.com/2014/04/09/heartbleed-bug-websites-affected/?utm_cid=mash-com-Tw-

main-link