
Summary
The Heartbleed bug (http://en.wikipedia.org/wiki/Heartbleed_bug) is a serious vulnerability in OpenSSL 1.0.1 through 1.0.1.f.
This vulnerability allows an attacker to read chunks of memory from servers and clients that connect using SSL through a flaw in OpenSSL's implementation of the heartbeat extension.
OpenSSL provides critical functionality in the internet ecosystem, and therefore vulnerabilities, such as Heartbleed, have a significant impact on digital communications and their integrity.
What does this mean for Aldeg TECHNOLOGIES installations?
SSL is an important protocol for securing web traffic, and thus securing web requests for logins, order transactions, etc.. Aldeg TECHNOLOGIES, like all web applications, must rely on web servers to correctly implement the SSL protocol. Aldeg TECHNOLOGIES as a web application cannot patch the Heartbleed vulnerability, nor can we mitigate its effects. However as a member of the internet community, we feel it's important to raise awareness of the risk and ensure that our users check that their server is protected.
How do I check if my server is protected?
Essentially, there are three ways you can verify if your server is protected:
1) You can open a support ticket with your hosting provider.
2) You can leverage a third party scanning tool via the web.
Below are three such sites that the community deems reputable and trustworthy. You simply enter your website and it will let you know:
3) You can run a scanning tool locally on your server. One such tool is:
https://github.com/n8whnp/ssltest-stls/blob/master/ssltest-stls.py
What do I do if my server is not protected?
Once I have patched my server, is there anything else I need to do?
How has Aldeg TECHNOLOGIES servers and my account been affected by Heartbleed?
The Heartbleed bug has had a profound impact on the transmission of secure data throughout the Internet. It is for that reason that we are encouraging our customers to reset their member area passwords at their earliest convenience as a matter of common password maintenance. Please remember to always make your passwords unique, random, and periodically rotate them.
Aldeg TECHNOLOGIES is in the process of emailing all active clients to inform them of this blog post. That email also contains a direct link to the aldegtechnologies.com password reset function as a precautionary measure.
Friday, April 11, 2014
Powered by WHMCompleteSolution