Amazon ELBs are vulnerable to Heartbleed
forums.aws.amazon.com
forums.aws.amazon.com
as of now, support is unaware there is a fix being rolled out.
i would have been better served not speaking to them, let alone paying for aws support.
https://twitter.com/lox/status/453443517017100288 http://filippo.io/Heartbleed/#99designs.com
[1]http://blog.cloudflare.com/staying-ahead-of-openssl-vulnerab...
https://aws.amazon.com/security/security-bulletins/heartblee...
Wonder where this is even linked from?
Just used Zapier to set up a RSS-to-email trigger to get notified about things like this in the future, although Amazon really should be sending them out automatically to customers.
It detects new AWS security bulletin items and notifies you via Google Hangout.
./heartbleeder zapier.com
VULNERABLE - zapier.com:443 has the heartbeat extension enabled and is vulnerable to CVE-2014-0160
./heartbleeder zapier.com
SECURE - zapier.com:443 has the heartbeat extension enabled, but timed out after a malformed heartbeat (this likely means that it is not vulnerable)
When did you run your check? Do you have a recent binary of heartbleeder?When you combine Docker, buildpacks, and CoreOS[2], you get a scalable and flexible platform that you can run anywhere. It has taken people a long time to combine the simplicity of Heroku with the flexibility of bare metal, but the open source guys have finally put all the building blocks together.
[1] https://github.com/CenturyLinkLabs/building/
[2] http://www.centurylinklabs.com/building-your-first-app-on-co...
[1]: http://deis.io/
[2]: https://github.com/opdemand/deis/issues/530
[3]: http://docs.deis.io/en/latest/developer/dockerfile/#deploy-u...