• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Where to address Heartbeat issue (openssl)

Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
5 Posts 3 Posters 1.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jahlives
    last edited by Apr 10, 2014, 7:22 PM

    Hi

    I'm not sure if this really is an issue to solve by pfsense so please forgive me if I'm wrong :-)

    I have the nanonbsd pfsense 4GB image for amd64 with serial output. Latest version 2.1.1
    The problem is that the openssl used in that image is vulnerable for the Heartbeat (Heartbleed) attack on openssl. Although openssl is in version 0.9.8y I can get 64K of the servers RAM. When I "fetch" the block short after login as admin via the webinterface I can even get the admins password in the response!
    The timeframe for getting the password is quite small but the other request headers, which contain for example session id or cookies, appear almost every time

    So my main question is to whom to address the issue to. Is it pfsense or nanobsd?

    1 Reply Last reply Reply Quote 0
    • C
      cmb
      last edited by Apr 10, 2014, 7:23 PM

      2.1.2 release is now available to address that.

      1 Reply Last reply Reply Quote 0
      • J
        JeGr LAYER 8 Moderator
        last edited by Apr 10, 2014, 7:32 PM

        Besides the usefulness of that post and the joy of celebrating 2.1.2 release (awesome work), why is that post in the german sub-section? ;)

        Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

        If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

        1 Reply Last reply Reply Quote 0
        • J
          jahlives
          last edited by Apr 10, 2014, 8:04 PM

          @JeGr:

          Besides the usefulness of that post and the joy of celebrating 2.1.2 release (awesome work), why is that post in the german sub-section? ;)

          very good question :-) I just saw it after posting. I'm german speaking but wanted to post in the english part. No idea why I have not seen it before.

          @pfsense Team
          thanks a lot for that quick fix. Will try it and test again

          Cheers

          tobi

          1 Reply Last reply Reply Quote 0
          • J
            jahlives
            last edited by Apr 10, 2014, 8:34 PM

            I just finished the update and it works (or not depending on the point of view  ;) )

            
            Connecting...
            Sending Client Hello...
            Waiting for Server Hello...
             ... received message: type = 22, ver = 0302, length = 58
             ... received message: type = 22, ver = 0302, length = 2331
             ... received message: type = 22, ver = 0302, length = 525
             ... received message: type = 22, ver = 0302, length = 4
            Sending heartbeat request...
            Unexpected EOF receiving record header - server closed connection
            No heartbeat response received, server likely not vulnerable
            
            

            as it should be

            Again thanks for the fast fix and happy 2.1.2

            tobi

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received