Main Restorations Software Audio/Jukebox/MP3 Everything Else Buy/Sell/Trade
Project Announcements Monitor/Video GroovyMAME Merit/JVL Touchscreen Meet Up Retail Vendors
Driving & Racing Woodworking Software Support Forums Consoles Project Arcade Reviews
Automated Projects Artwork Frontend Support Forums Pinball Forum Discussion Old Boards
Raspberry Pi & Dev Board controls.dat Linux Miscellaneous Arcade Wiki Discussion Old Archives
Lightguns Arcade1Up Try the site in https mode Site News

Unread posts | New Replies | Recent posts | Rules | Chatroom | Wiki | File Repository | RSS | Submit news

  

Author Topic: Vulnerable to Heartbleed Bug :(  (Read 3978 times)

0 Members and 1 Guest are viewing this topic.

CthulhuLuke

  • Trade Count: (+1)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 556
  • Last login:January 18, 2024, 06:42:43 pm
  • old school
    • CthulhuLuke's Arcade Parodius
Vulnerable to Heartbleed Bug :(
« on: April 10, 2014, 03:28:29 pm »
Hey guys, been lurking here a loooooooong time.

Anyway, just wanted to let you know that arcadecontrols.com is vulnerable to the Heartbleed bug :( Someone who has the ability needs to update the server software on here to get a non-vulnerable OpenSSL server.

Louis Tully

  • Trade Count: (+5)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1800
  • Last login:February 13, 2015, 09:41:03 pm
Re: Vulnerable to Heartbleed Bug :(
« Reply #1 on: April 10, 2014, 03:31:01 pm »
.
« Last Edit: February 12, 2015, 05:02:47 pm by Louis Tully »

bochi

  • Trade Count: (0)
  • Jr. Member
  • **
  • Offline Offline
  • Posts: 8
  • Last login:April 10, 2014, 04:20:18 pm
Re: Vulnerable to Heartbleed Bug :(
« Reply #2 on: April 10, 2014, 03:36:22 pm »
Its bad :(

(This is CthulhuLuke, I can't see any passwords but you get cookie dumps :/ :/ )

404

  • Trade Count: (+3)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1019
  • Last login:August 04, 2015, 10:19:10 pm
Re: Vulnerable to Heartbleed Bug :(
« Reply #3 on: April 10, 2014, 06:10:55 pm »
yep, just tested it myself. Admins need to update asap.

yotsuya

  • Trade Count: (+21)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 19956
  • Last login:Yesterday at 12:09:56 am
  • 2014 UCA Winner, 2014, 2015, 2016 ZapCon Winner
    • forum.arcadecontrols.com/index.php/topic,137636.msg1420628.html
Re: Vulnerable to Heartbleed Bug :(
« Reply #4 on: April 10, 2014, 06:12:18 pm »
Looks like the bug affected your signature file line.

If this gets Tapatalk fixed, go for it!
***Build what you dig, bro. Build what you dig.***

saint

  • turned to the Dark Side
  • Supreme Chancellor
  • Trade Count: (+6)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 6144
  • Last login:Yesterday at 01:43:29 pm
  • I only work in cyberspace...
    • Build Your Own Arcade Controls
Re: Vulnerable to Heartbleed Bug :(
« Reply #5 on: April 11, 2014, 08:13:15 am »
I've updated the OpenSSL. 

I didn't realize anyone was using https to access the forum though. Are folks?

CthulhuLuke, 404 - still seeing vulnerabilities?
--- John St.Clair
     Build Your Own Arcade Controls FAQ
     http://www.arcadecontrols.com/
     Project Arcade 2!
     http://www.projectarcade2.com/
     saint@arcadecontrols.com

wp34

  • Trade Count: (+3)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 4794
  • Last login:April 10, 2022, 09:48:19 pm
Re: Vulnerable to Heartbleed Bug :(
« Reply #6 on: April 11, 2014, 08:39:16 am »
I've updated the OpenSSL. 

I didn't realize anyone was using https to access the forum though. Are folks?

CthulhuLuke, 404 - still seeing vulnerabilities?

I assumed that the login page was https but it is not.  Is it an option to require SSL for the login page?

404

  • Trade Count: (+3)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1019
  • Last login:August 04, 2015, 10:19:10 pm
Re: Vulnerable to Heartbleed Bug :(
« Reply #7 on: April 11, 2014, 08:43:07 am »
I've updated the OpenSSL. 

I didn't realize anyone was using https to access the forum though. Are folks?

CthulhuLuke, 404 - still seeing vulnerabilities?

Still reports as vulnerable but this time around i couldn't dump cookies.

saint

  • turned to the Dark Side
  • Supreme Chancellor
  • Trade Count: (+6)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 6144
  • Last login:Yesterday at 01:43:29 pm
  • I only work in cyberspace...
    • Build Your Own Arcade Controls
Re: Vulnerable to Heartbleed Bug :(
« Reply #8 on: April 11, 2014, 09:03:23 am »
Thank you - what tool are you using to assess the vulnerability?
--- John St.Clair
     Build Your Own Arcade Controls FAQ
     http://www.arcadecontrols.com/
     Project Arcade 2!
     http://www.projectarcade2.com/
     saint@arcadecontrols.com

404

  • Trade Count: (+3)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1019
  • Last login:August 04, 2015, 10:19:10 pm
Re: Vulnerable to Heartbleed Bug :(
« Reply #9 on: April 11, 2014, 09:27:24 am »
^^ heartbleeder
https://github.com/titanous/heartbleeder

Although i think the biggest issue here is that your cert was signed over 2 years ago. I'd try to get a new cert (your host should be more than accommodating during this situation)Best method to patch this up is to tweak settings and then just use some of the more common, online testers to check your settings as you go along.

http://filippo.io/Heartbleed/
https://lastpass.com/heartbleed/

If you happen to have a cert by geotrust, they have created a quick form that allows you to get a new cert very fast
https://products.geotrust.com/orders/orderinformation/authentication.do

saint

  • turned to the Dark Side
  • Supreme Chancellor
  • Trade Count: (+6)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 6144
  • Last login:Yesterday at 01:43:29 pm
  • I only work in cyberspace...
    • Build Your Own Arcade Controls
Re: Vulnerable to Heartbleed Bug :(
« Reply #10 on: April 11, 2014, 09:38:28 am »
That's the thing I have to puzzle out - I don't have a cert that I'm aware of :) I may have a self-signed cert, sirwoogie may have set something up, but I've never purchased a cert for the server here.
--- John St.Clair
     Build Your Own Arcade Controls FAQ
     http://www.arcadecontrols.com/
     Project Arcade 2!
     http://www.projectarcade2.com/
     saint@arcadecontrols.com

404

  • Trade Count: (+3)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1019
  • Last login:August 04, 2015, 10:19:10 pm
Re: Vulnerable to Heartbleed Bug :(
« Reply #11 on: April 11, 2014, 10:01:47 am »
That's the thing I have to puzzle out - I don't have a cert that I'm aware of :) I may have a self-signed cert, sirwoogie may have set something up, but I've never purchased a cert for the server here.

yeah, I would ask sirwoogie to get more details on the cert situation. There is definitely something there but it is definitely old.  Also make sure the heartbeat extension is enabled.

CthulhuLuke

  • Trade Count: (+1)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 556
  • Last login:January 18, 2024, 06:42:43 pm
  • old school
    • CthulhuLuke's Arcade Parodius
Re: Vulnerable to Heartbleed Bug :(
« Reply #12 on: April 11, 2014, 10:29:13 am »
fox_heartbleedtest.py says you are no longer vulnerable.  ( http://foxitsecurity.files.wordpress.com/2014/04/fox_heartbleedtest.zip )

That is what I used to get bochi's cookie, you could basically set it up in a loop dumping memory and looking for cookies that contain SMF20=

Your certificate is definitely self-signed. The issuer is sirwoogie@gmail.com.

404

  • Trade Count: (+3)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 1019
  • Last login:August 04, 2015, 10:19:10 pm
Re: Vulnerable to Heartbleed Bug :(
« Reply #13 on: April 11, 2014, 11:54:43 am »
fox_heartbleedtest.py says you are no longer vulnerable.  ( http://foxitsecurity.files.wordpress.com/2014/04/fox_heartbleedtest.zip )

That is what I used to get bochi's cookie, you could basically set it up in a loop dumping memory and looking for cookies that contain SMF20=

Your certificate is definitely self-signed. The issuer is sirwoogie@gmail.com.

strange. when i checked earlier this morning it was showing up as still vulnerable. Now i just checked with heartbleeder and it times out.  ???

PL1

  • Global Moderator
  • Trade Count: (+1)
  • Full Member
  • *****
  • Offline Offline
  • Posts: 9406
  • Last login:Yesterday at 10:58:35 pm
  • Designated spam hunter
Re: Vulnerable to Heartbleed Bug :(
« Reply #14 on: April 11, 2014, 12:14:49 pm »
Does the wiki need to be patched, too?


Scott

yotsuya

  • Trade Count: (+21)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 19956
  • Last login:Yesterday at 12:09:56 am
  • 2014 UCA Winner, 2014, 2015, 2016 ZapCon Winner
    • forum.arcadecontrols.com/index.php/topic,137636.msg1420628.html
Re: Vulnerable to Heartbleed Bug :(
« Reply #15 on: April 11, 2014, 06:14:15 pm »
What does all this have to do with Tapatalk????  >:D
***Build what you dig, bro. Build what you dig.***