Heartbleed Flaw Said Used in Hospital Hacking
bloomberg.com
bloomberg.com
> "Community Health ... disclosed yesterday that Chinese hackers stole patients’ Social Security numbers, names and addresses, without revealing how the hackers got in."
And then...
> “We never had any tangible proof of an attack until now,” said David Kennedy, founder of TrustedSec LLC, a security consulting company based in Cleveland, Ohio, who first reported Heartbleed was used to attack Community Health on his company’s website.
Here's the report: https://www.trustedsec.com/august-2014/chs-hacked-heartbleed... -- but I still wonder how it was detected.
[1] http://www.cvedetails.com/vulnerability-list/vendor_id-874/y...
[2] https://en.wikipedia.org/wiki/Junos
[3] http://www.cvedetails.com/cve/CVE-2014-3816/
http://www.cvedetails.com/cve/CVE-2014-3412/
Luckily we were not running the latest Version Tree of the firmware so we were still on an older openssl version.
I dont think Juniper Devices have more or less culnerabilities than other vendors. Its highly developed stuf (chasing technical advances, bringing new firmwares every other month).
You just shouldnt use .0-1 Versions of new Release Trees like with every Vendor...
And for Heartbleed: Nearly Everyone based on linux/Openssl was affected somehow.
It is utterly amazing to me how we view the Chinese people as such an evil "other".
I'd love to know how they determined that this was Chinese hackers, which doesn't appear in the Trusted Sec report, and from my amateur eyes would seem near impossible to determine with certainty. But if it was the case, why the first thought is that it was an action on behalf of the government instead of a couple Chinese kids messing about. Count the "Chinese hackers" in the article.
If the vulnerability was public at the beginning of April, how were there attacks made in June?
Hard to believe they actually asked the embassy if they knew about the attack. The embassy's reaction was understandable.
There were many complaints before and since of how difficult it is to get bugs patched and especially their idiosyncratic approach to development. In essence, they duplicated OS functionality even when unnecessary and had a large swath of code that was fundamentally redundant and/or broken.
They supported everything. For example, they supported a variety of flavors of MD5. (Apparently bloat that LibreSSL has gotten rid of, or so I've heard).
The whole package had around 300,000 lines of code. Even with funding it'd be difficult to maintain.