We're Hiring!
Take the next step in your career and work on diverse technology projects with cross-functional teams.
LEARN MORE
Mountain West Farm Bureau Insurance
office workers empowered by business technology solutions
BLOG
5
7
2014

OpenSSL Vulnerability: Heartbleed Bug | Green House Data Blog

Last updated:
9.16.2020
No items found.

What is Heartbleed?
This vulnerability takes advantage of a memory configuration within the ever-popular OpenSSL software library. The TLS heartbeat extension (RFC 6520) on an exploited version of OpenSSL allows an attacker to view up to 64k of what is in memory with each “heartbeat.” Thus, a multitude of information can be obtained unnoticed. It is important to note that this exploit is found in OpenSSL's implementation of SSL/TLS, not within the TLS protocol itself.

OpenSSL Vulnerability: Heartbleed Bug

Why is this important?
SSL/TLS is the cornerstone of the Internet's means of encrypted transmission of data. We rely on websites to implement proper security measures when working with private information, e.g. bank accounts, medical records, social security numbers, and so on. OpenSSL is a widely used set of libraries that provides cryptographic services to many of these web servers. What makes this particular exploit interesting and very dangerous is that:

 
Whom does this affect?
So far, any company that provides services using non-patched OpenSSL to encrypt data can be vulnerable if proper measures of updating are not followed. Examples of this might include:

What is at stake?

  1. Private Encryption Keys – The most sought-after bounty! An attacker with these keys can decrypt any past and future data.
  2. Leaked Secondary Key Material – Usernames/Passwords that have access to internal systems or services.
  3. Leaked Protected Content – Any data that are meant to be encrypted, such as:

How does this affect Green House Data's services?
We are actively pursuing efforts to mitigate any presence of vulnerable systems within Green House Data's cloud infrastructure. From what we have seen so far, these efforts are primarily focused on systems using OpenSSL to encrypt TLS connections. Green House Data provides service and customer portals that use SSL and have taken the necessary actions to secure our systems.

Those who take advantage of our managed services will be automatically patched during the regular patching cycle. We also provide proactive scanning of clients' systems for vulnerabilities and will notify if and when issues are found. We consider data security and integrity a high priority with every service we provide.

What steps can be taken to fix this?

  1. If possible, remove any vulnerable device from the public Internet until it is patched.
  2. Update any system using OpenSSL version 1.0.1f and earlier to the latest and patched version, 1.0.1g.
  3. Those who used a non-patched version of OpenSSL to generate private keys for a certificate signing request (CSR) should take the necessary steps to generate a new pair of keys through the newly patched system. Most certificate authorities (CA) will not require that you purchase a new certificate. Please note that these keys should be generated after you have patched your system.
  4. Change any usernames and passwords that may have been leaked.
  5. Use a variety of tools to test your external web server against this bug. Some are provided in the links below.


References and Further Reading

General:

To test your server against the bug:

Posted by: Systems Administrator Alex Kirby

Recent Blog Posts

lunavi logo alternate white and yellow
3.13.2025
3
.
12
.
2025
Unlocking the Power of Azure Managed Services with Lunavi

Cloud computing has become the backbone of modern business, offering agility, scalability, and cost efficiency. But managing cloud environments while keeping costs under control and security airtight? That’s a challenge. Azure Managed Services streamline cloud operations, helping businesses optimize spending, enhance security, and future-proof applications. Lunavi provides the expertise and tools to make it happen—so you can focus on growth instead of IT headaches.

Learn more
lunavi logo alternate white and yellow
2.11.2025
2
.
7
.
2025
The Future of Test Automation: Key Trends Shaping 2025 and Beyond

Software testing has gone from a chore to a game-changer, thanks to automation. But in 2025, sticking to old methods means falling behind. Stay ahead by embracing the future of test automation—let’s explore the key trends shaping what’s next.

Learn more
lunavi logo alternate white and yellow
2.11.2025
1
.
23
.
2025
The Importance of Cross Browser Testing

Making sure users have a smooth experience across all these platforms is crucial for businesses to stay competitive. Cross-browser testing is now a key part of modern development. It helps teams find and fix problems like layout issues, broken features, or slow performance before users are affected. Let’s look at why cross-browser testing matters and explore tools that make it easier to get the job done.

Learn more