Friday, April 18, 2014

Internet Security - Heartbleed bug: A downloadable Chrome extension & Mozilla/Firefox add-on to detect vulnerable sites

Displays a warning if the site you are browsing is affected by the Heartbleed
bug.  Also displays warnings on Google search results: the Heartbleed icon is added to Google search results where the site is still affected by the Heartbleed bug. -- Many HTTPS-secured sites on the internet use OpenSSL.  Unfortunately, a major vulnerability in OpenSSL was disclosed - known as the Heartbleed bug - yesterday that put hundreds of thousands of servers at risk of compromise. 

Whilst some servers have been patched already, many remain that have not been patched.  Chromebleed uses a web service developed by Filippo Valsorda ( https://filippo.io/Heartbleed/ ) and checks the URL of the page you have just loaded.  If it is affected by Heartbleed, then a Chrome notification will be displayed.  It's as simple as that!

Please note that, in some jurisdictions, site testing can only be carried out with the express permission of the site owner.  Please check what the law says in your local area before proceeding to download this extension. 

Download fromhttps://chrome.google.com/webstore/detail/chromebleed/eeoekjnjgppnaegdjbcafdggilajhpic

An add-on download for Mozilla/Firefox: https://addons.mozilla.org/ro/firefox/addon/heartbleed_monitor/

Without visiting a web site directly, you can test its server (or any web host URL) for the Heartbleed (CVE-2014-0160) vulnerability/bug by visiting the website address shown below where you can enter a web server's URL to be tested:
https://filippo.io/Heartbleed/

No comments:

Post a Comment

Please, avoid posting advertisements. Content comments are welcomed, including anonymous. Posts with profanity will not be published.