{"id":100324,"date":"2014-04-09T16:11:15","date_gmt":"2014-04-09T14:11:15","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=100324"},"modified":"2014-04-09T22:00:14","modified_gmt":"2014-04-09T20:00:14","slug":"critical-security-bug-gets-sa-sites-hosts-scrambling","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/100324-critical-security-bug-gets-sa-sites-hosts-scrambling.html","title":{"rendered":"Critical security bug gets SA sites, hosts scrambling"},"content":{"rendered":"<p>A bug in the OpenSSL software library that has been dubbed \u201cHeartbleed\u201d by the researchers that discovered and reported it had websites and hosting companies, including many in South Africa, scrambling to deploy patches yesterday (Tuesday, 8 April 2014).<\/p>\n<p>However, the security concerns caused by the bug do not end once the library is patched.<\/p>\n<p>Heartbleed lets anyone, without any knowledge of a server or privileged access, obtain 64 kilobyte chunks of a server\u2019s heap memory remotely without leaving any indication that they have \u201chacked\u201d the server.<\/p>\n<p>According to the researchers, this memory may contain usernames and passwords, and even the private keys used to sign a site\u2019s certificate.<\/p>\n<p>While the bug doesn\u2019t affect all web servers, the majority (at least 66%, according Netcraft data) of sites on the web use software impacted by this bug.<\/p>\n<h3 class=\"my-4\">\u201cPretty serious\u201d<\/h3>\n<p>Asked about the seriousness of the bug, Chief technology officer for information security firm <a title=\"SensePost\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/313979-SensePost\">SensePost<\/a>, <a title=\"Dominic White\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/530068-Dominic-White\">Dominic White<\/a> said that it is \u201cpretty serious\u201d.<\/p>\n<p>White provided a link to a developer\u2019s program on Github which <a href=\"https:\/\/github.com\/musalbas\/heartbleed-masstest\" target=\"_blank\">scans Alexa\u2019s list of top sites<\/a> for the Heartbleed bug.<\/p>\n<p>At around 21:00 last night 1,258 (or 12%) of the top 10,629 sites tested as vulnerable.<\/p>\n<p>\u201cThat\u2019s 12% of some very big name sites that are vulnerable,\u201d White said. \u201cBut, that also means 88% of this list of big name sites aren\u2019t vulnerable.\u201d<\/p>\n<p>By the time of publication (around 16:00, 9 April 2014), the tool reported that the number had dropped to 627 sites that appeared vulnerable.<\/p>\n<p><a title=\"Yahoo.com\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/363118-Yahoo\">Yahoo.com<\/a> was among the vulnerable sites, and the web has been full of reports of security researchers who were able to get the usernames and passwords of Yahoo! Mail users due to the Heartbleed bug.<\/p>\n<p>While being able to get sensitive data such as usernames and passwords is a massive security concern, White said they haven\u2019t seen a proof of concept that actually exposes the private keys used to sign SSL certificates yet.<\/p>\n<p>\u201cThis doesn\u2019t mean it\u2019s not possible, or isn\u2019t coming, just that nobody has demonstrated it, despite numerous tools now existing,\u201d White said.<\/p>\n<p>If it is possible to get an SSL private key from the server memory in this way, White said that \u201ca bad guy could put up a fake site with the real SSL certificate, or potentially decrypt encrypted communications they were intercepting.\u201d<\/p>\n<p>In short, this means that even if servers are patched there are larger ramifications that would probably require website owners to revoke their security certificates and obtain new ones, as well as advise users to change their usernames and passwords.<\/p>\n<h3 class=\"my-4\">South African sites, hosts affected<\/h3>\n<p>Among the local sites confirmed to be affected by the bug were <a title=\"Bidorbuy\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/359610-Bidorbuy\">Bidorbuy<\/a> and <a title=\"Capitec Bank\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/370968-Capitec\">Capitec Bank<\/a>\u2019s corporate marketing website.<\/p>\n<p><strong>Bidorbuy<\/strong> CTO <a title=\"Gerd Naschenweng\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/554485-Gerd-Naschenweng\">Gerd Naschenweng<\/a> said yesterday that they had patched their servers and were waiting on advice from their certificate provider on how to proceed.<\/p>\n<p>\u201cWe received feedback from Verisign that we should also recycle private keys and [certificates], so we are in the process of doing this as well,\u201d Naschenweng told MyBroadband.<\/p>\n<p><strong>Kalahari.com<\/strong>\u2019s <a title=\"Kirby Gordon\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/609898-Kirby-Gordon\">Kirby Gordon<\/a> said that they are aware of the issue and are not affected.<\/p>\n<p><strong>WebAfrica<\/strong> CTO <a title=\"Alan Kirton\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/534223-Alan-Kirton\">Alan Kirton<\/a> said that a proportion of their Linux-based hosting environment was susceptible to Heartbleed.<\/p>\n<p>\u201cWe implemented all appropriate patches as soon as we became aware of the bug and we are busy advising our customers on the best ways to protect themselves,\u201d Kirton said.<\/p>\n<p><a title=\"Mweb\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/226947-MWeb\">Mweb<\/a> said that the majority of their environment are Windows-based and only a very small number (less than 5%) of their sites on Linux use OpenSSL.<\/p>\n<p>While the fix is relatively straight-forward and was being rolled out to their current managed server estate yesterday, Mweb said that there is no way of knowing whether a server has been exploited in the last two years since OpenSSL 1.0.1 was released.<\/p>\n<p>\u201cWe are addressing this by revoking and reissuing certificates after the version has been updated,\u201d Mweb said.<\/p>\n<p><strong>Update<\/strong>: At 21:46 on Wednesday, Afrihost let us know that the Afrihost and Axxess sites have been patched. Tests with online Heartbleed vulnerability checkers confirm that the sites at the root domains for the ISPs are no longer vulnerable. It is worth noting that at the original time of writing the Afrihost Clientzone and Axxess Customer Control Panel sites were not testing as vulnerable.<\/p>\n<div class=\"table-responsive\"><table class=\"table\" style=\"background-color: #f4f4f4; width: 100%;\" border=\"1\" cellpadding=\"5\">\n<tbody>\n<tr style=\"background-color: #002440; font-weight: bold; color: #fff;\">\n<td>Domain<\/td>\n<td colspan=\"2\">Heartbleed vulnerability<\/td>\n<\/tr>\n<tr style=\"background-color: #004276; font-weight: bold; color: #fff;\">\n<td>Online banking<\/td>\n<td>Currently vulnerable<\/td>\n<td>Previously vulnerable<\/td>\n<\/tr>\n<tr>\n<td>netbank.nedsecure.co.za<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>ib.absa.co.za<\/td>\n<td>No<\/td>\n<td>Unknown<\/td>\n<\/tr>\n<tr>\n<td>online.fnb.co.za<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>direct.capitecbank.co.za<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>encrypt.standardbank.co.za<\/td>\n<td>No<\/td>\n<td>Unknown<\/td>\n<\/tr>\n<tr style=\"background-color: #004276; font-weight: bold; color: #fff;\">\n<td>Banks<\/td>\n<td>Currently vulnerable<\/td>\n<td>Previously vulnerable<\/td>\n<\/tr>\n<tr>\n<td>absa.co.za<\/td>\n<td>No SSL<\/td>\n<td>No SSL<\/td>\n<\/tr>\n<tr>\n<td>capitecbank.co.za<\/td>\n<td>No<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>standardbank.co.za<\/td>\n<td>No<\/td>\n<td>Unknown<\/td>\n<\/tr>\n<tr>\n<td>fnb.co.za<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>nedbank.co.za<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<tr style=\"background-color: #004276; font-weight: bold; color: #fff;\">\n<td>E-commerce sites<\/td>\n<td>Currently vulnerable<\/td>\n<td>Previously vulnerable<\/td>\n<\/tr>\n<tr>\n<td>Kalahari<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>Takealot (secure.takealot.com)<\/td>\n<td>No<\/td>\n<td>Unknown<\/td>\n<\/tr>\n<tr>\n<td>OLX<\/td>\n<td>No SSL<\/td>\n<td>No SSL<\/td>\n<\/tr>\n<tr>\n<td>Gumtree (gumtree.co.za)<\/td>\n<td>No<\/td>\n<td>Unknown<\/td>\n<\/tr>\n<tr>\n<td>Bidorbuy (bidorbuy.co.za)<\/td>\n<td>No<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>Wantitall<\/td>\n<td>No<\/td>\n<td>Unknown<\/td>\n<\/tr>\n<tr>\n<td>Have2have<\/td>\n<td>No<\/td>\n<td>Unknown<\/td>\n<\/tr>\n<tr style=\"background-color: #004276; font-weight: bold; color: #fff;\">\n<td>Internet and hosting service providers<\/td>\n<td>Currently vulnerable<\/td>\n<td>Previously vulnerable<\/td>\n<\/tr>\n<tr>\n<td>afrihost.com<\/td>\n<td>No<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>clientzone.afrihost.com<\/td>\n<td>No<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>axxess.co.za<\/td>\n<td>No<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>ccp.axxess.co.za<\/td>\n<td>No<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>mweb.co.za<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>myaccount.mweb.co.za<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>telkom.co.za<\/td>\n<td>No SSL<\/td>\n<td>No SSL<\/td>\n<\/tr>\n<tr>\n<td>login.telkom.co.za<\/td>\n<td>No<\/td>\n<td>Unknown<\/td>\n<\/tr>\n<tr>\n<td>secureapp.telkom.co.za<\/td>\n<td>No<\/td>\n<td>Unknown<\/td>\n<\/tr>\n<tr>\n<td>webafrica.co.za<\/td>\n<td>No<\/td>\n<td>Unknown<\/td>\n<\/tr>\n<tr>\n<td>dsl.webafrica.co.za<\/td>\n<td>No<\/td>\n<td>Unknown<\/td>\n<\/tr>\n<tr style=\"background-color: #004276; font-weight: bold; color: #fff;\">\n<td>Other services<\/td>\n<td>Currently vulnerable<\/td>\n<td>Previously vulnerable<\/td>\n<\/tr>\n<tr>\n<td>DStv<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<tr>\n<td>Supersport<\/td>\n<td>No<\/td>\n<td>No<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<h3 class=\"my-4\">South African banks respond<\/h3>\n<p>A <strong>Capitec<\/strong> spokesperson told MyBroadband that their IT Risk department said that their corporate marketing website was patched yesterday morning and that their Internet banking is not vulnerable to Heartbleed.<\/p>\n<p>CEO for <strong>FNB<\/strong> Online Banking, <a title=\"Lee-Anne van Zyl\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/404857-Lee-Anne-van-Zyl\">Lee-Anne van Zyl<\/a>, said that they are not vulnerable to the bug as none of their public-facing sites use OpenSSL for encryption.<\/p>\n<p><strong>Nedbank<\/strong> provided a similar answer, saying that an all their critical transactional systems have been reviewed and found not to be vulnerable.<\/p>\n<p>\u201cWe are continuing our investigations on non-critical systems,\u201d Nedbank said. \u201cWhere vulnerabilities are highlighted, we will engage suppliers to provide the required mitigation in line with our standard processes.\u201d<\/p>\n<p><strong>Absa<\/strong> and <strong>Standard Bank<\/strong>\u2019s Internet banking system also do not appear to be vulnerable, but neither bank answered questions put to them on the matter.<\/p>\n<p><strong>Update:<\/strong> An Absa spokesperson has provided the following statement:<\/p>\n<blockquote><p>We have robust processes in place to manage any potential risk that may arise on our network and this third party vulnerability would be treated and handled as such.<\/p><\/blockquote>\n<h3 class=\"my-4\">Update! Even if you don\u2019t think you\u2019re vulnerable<\/h3>\n<p>White said that there are a few good tools out for checking if your server is vulnerable, but warned that many aren\u2019t complete.<\/p>\n<p>For this reason you should patch your servers even if these tools say they aren\u2019t vulnerable, White said.<\/p>\n<h3 id=\"related\">More information security news<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/100204-massive-security-bug-may-leave-sa-sites-vulnerable.html\"><strong>Massive security bug may leave SA sites vulnerable<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/99682-google-user-info-requests-for-sa-criminal-investigations.html\"><strong>Google user info requests for SA criminal investigations<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/99600-wi-fi-hacking-quadcopter-from-sa-security-firm.html\"><strong>Wi-Fi hacking quadcopter from SA security firm<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/99570-jolly-roger-malware-hits-sa-in-a-big-way.html\"><strong>Jolly Roger malware hits SA in a big way<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A serious bug in OpenSSL has South African websites and hosting companies scrambling<\/p>\n","protected":false},"author":15,"featured_media":100210,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[3636,5334,23159,1313,21069,35,24474,4562,213,1111,24464,19544,2508],"class_list":["post-100324","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-bidorbuy","tag-capitec","tag-dominic-white","tag-fnb","tag-gerd-naschenweng","tag-headline","tag-heartbleed","tag-kalahari","tag-mweb","tag-nedbank","tag-openssl","tag-sensepost","tag-webafrica"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/100324"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=100324"}],"version-history":[{"count":3,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/100324\/revisions"}],"predecessor-version":[{"id":100354,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/100324\/revisions\/100354"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/100210"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=100324"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=100324"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=100324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}