Click here to close now.

Welcome!

Apache Authors: Carmen Gonzalez, Ruxit Blog, Roger Strukhoff, Elizabeth White, Pat Romanski

Blog Feed Post

Heartbleed, la plus grosse faille de l’Internet

Le 7 Avril 2014 a été décelé la plus sérieuse faille de sécurité de l’histoire d’internet, impactant l’intégrité de bases de données les plus sécurisées du monde. Cette brèche permet à un attaquant chevronné d’accéder à des informations sensibles incluant potentiellement les identifiants, mots de passe, numéros de cartes bancaires… et d’emporter la clé de sécurité du serveur qui héberge ces données.

Le moteur (OpenSSL) qui assure les connexions sécurisées et chiffrées entre un utilisateur et un site web est reconnaissable par un « https » dans la barre d’adresse ou un cadenas en bas à droite de votre navigateur. Une attaque Heartbleed ne laisse aucune trace sur le serveur, c’est pourquoi il est d’autant plus important de le combler. Car aucune attaque ne pourra être tracée, rendant une enquête impossible.

Les patchs de correction ont été livrés en 49 minutes. Mais l’ampleur des dégâts n’est pas encore connue car on ne sait pas si la faille a déjà été exploitée avant son identification. Vos mots de passe pourraient déjà avoir été dérobés. Facebook, Google, Gmail, Yahoo !, Dropbox, Pinterest, Instagram, Twitter, Tumblr … Aucuns de ces sites précisent avoir constatés des utilisations irrégulières de leurs services. Les éditeurs indiquent qu’ils ont évalués cette vulnérabilité et qu’ils recommandent toutefois aux utilisateurs de changer leurs mots de passe.

L’offre Microsoft de Provectio est-elle sensible à la faille HeartBleed ?

Les configurations par défaut de Windows ne comprennent pas OpenSSL, donc ne sont pas affectés par cette vulnérabilité. Windows est livré avec son propre composant de chiffrement appelé Secure Channel (aka SChannel ) , qui n’est pas sensible à la vulnérabilité Heartbleed . Cela s’applique à tous les systèmes d’exploitation Windows et IIS versions , jusqu’à et y compris IIS 8.5 fonctionnant sur tous les systèmes d’exploitation suivants : Windows Server 2003 et 2003R2, Windows Server 2008, Windows Server 2008R2, Windows Server 2012, Windows Server 2012R2. Les clients logiciels sur Windows qui utilisent OpenSSL au lieu de SChannel (livré dans Apache pour Windows) peuvent être vulnérables.

L’offre Linux de Provectio est-elle sensible à la faille HeartBleed ?

Les versions openssl impactés sont : 1.0.1 et 1.0.2-beta releases inclut aussi les versions 1.0.1f and 1.0.2-beta1. Sur notre plateforme OpenVPN nous exploitons la version OpenSSL 0.9.8k. Les distributions Linux Protection Suite, Linux Data Suite, Linux Virtual Hoster, Linux eMail Control ne sont pas impactés par cette faille de sécurité.

Nos éditeurs de sécurité déjà sur la brèche

Sophos, dont Provectio travaille sur l’obtention du statut Platinium, a d’ores et déjà commencé à déployer son patch de sécurité et documenté le sujet. L’ensemble du parc Sophos UTM de nos clients est déjà à jour.

Identification des services impactés

Toutefois, certains services hébergés par Provectio sont sensibles à cette faille, nous menons actuellement un programme de mise à niveau :

  •  VPN sites à sites et nomades : Nous déployons en ce moment les correctifs. Vous serez prévenu de prochaines interruptions de service momentanées si elles étaient nécessaires. Nous effectuerons le renouvellement des certificats pour les utilisateurs nomades du VPN. Nous vous contacterons pour effectuer la mise à jour sur vos postes de travail.
  • Serveurs Web hébergés : Renouvellement des certificats et changement de mot de passe.

En bon utilisateur, nous vous recommandons :

  1. Changez immédiatement les mots de passe des comptes Internet que vous considérez comme sensibles (par exemple votre banque, vos comptes email, votre compte PayPal, …) en générant des mots de passe forts et uniques
  2. Attendez 10 jours avant de changer vos autres mots de passe afin de laisser le temps aux différents sites web d’éliminer la faille Heartbleed. Il est inutile de changer vos autres mots de passe avant.
  3. Dans 10 jours, changez à nouveau les mots de passe de vos comptes sensibles en générant des mots de passe forts et uniques.
  4. Une fois l’étape 3 terminée, vous pouvez changer les mots de passe de vos comptes moins sensibles.

Nous vous recommandons l’utilisation d’un produit français Dashlane, pour la gestion sécurisée de vos mots de passe.

Le point le plus important est de vous assurer que vous utilisez des mots de passe différents sur chaque site, car si votre mot de passe est volé sur un site, il ne pourra pas être utilisé sur un autre ; c’était important avant Heartbleed et c’est devenu essentiel aujourd’hui.

 Si vous êtes vulnérable à ce type de failles et que votre prestataire ne vous suit pas, vous connaissez le chemin !

The post Heartbleed, la plus grosse faille de l’Internet appeared first on Provectio - Cloud Computing et Infogérance.

Read the original blog entry...

More Stories By Maxime Charlès

Maxime Charlès is co-founder and CEO of Provectio, a French organization dedicated to Cloud Computing, IT and Outsourcing. His motto : "to surround himself with the best without fear that they will exceed"

@ThingsExpo Stories
SYS-CON Media announced today that @WebRTCSummit Blog, the largest WebRTC resource in the world, has been launched. @WebRTCSummit Blog offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. @WebRTCSummit Blog can be bookmarked ▸ Here @WebRTCSummit conference site can be bookmarked ▸ Here
Temasys has announced senior management additions to its team. Joining are David Holloway as Vice President of Commercial and Nadine Yap as Vice President of Product. Over the past 12 months Temasys has doubled in size as it adds new customers and expands the development of its Skylink platform. Skylink leads the charge to move WebRTC, traditionally seen as a desktop, browser based technology, to become a ubiquitous web communications technology on web and mobile, as well as Internet of Things compatible devices.
SYS-CON Events announced today that robomq.io will exhibit at SYS-CON's @ThingsExpo, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. robomq.io is an interoperable and composable platform that connects any device to any application. It helps systems integrators and the solution providers build new and innovative products and service for industries requiring monitoring or intelligence from devices and sensors.
Docker is an excellent platform for organizations interested in running microservices. It offers portability and consistency between development and production environments, quick provisioning times, and a simple way to isolate services. In his session at DevOps Summit at 16th Cloud Expo, Shannon Williams, co-founder of Rancher Labs, will walk through these and other benefits of using Docker to run microservices, and provide an overview of RancherOS, a minimalist distribution of Linux designed expressly to run Docker. He will also discuss Rancher, an orchestration and service discovery platf...
SYS-CON Events announced today that Aria Systems, the leading innovator in recurring revenue, has been named “Bronze Sponsor” of SYS-CON's @ThingsExpo, which will take place on June 9–11, 2015, at the Javits Center in New York, NY. Proven by the world’s most demanding enterprises, including AAA NCNU, Constant Contact, Falck, Hootsuite, Pitney Bowes, Telekom Denmark, and VMware, Aria helps enterprises grow their recurring revenue businesses. With Aria’s end-to-end active monetization platform, global brands can get to market faster with a wider variety of products and services, while maximizin...
Sonus Networks introduced the Sonus WebRTC Services Solution, a virtualized Web Real-Time Communications (WebRTC) offer, purpose-built for the Cloud. The WebRTC Services Solution provides signaling from WebRTC-to-WebRTC applications and interworking from WebRTC-to-Session Initiation Protocol (SIP), delivering advanced real-time communications capabilities on mobile applications and on websites, which are accessible via a browser.
SYS-CON Events announced today that Vitria Technology, Inc. will exhibit at SYS-CON’s @ThingsExpo, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Vitria will showcase the company’s new IoT Analytics Platform through live demonstrations at booth #330. Vitria’s IoT Analytics Platform, fully integrated and powered by an operational intelligence engine, enables customers to rapidly build and operationalize advanced analytics to deliver timely business outcomes for use cases across the industrial, enterprise, and consumer segments.
SYS-CON Events announced today that Akana, formerly SOA Software, has been named “Bronze Sponsor” of SYS-CON's 16th International Cloud Expo® New York, which will take place June 9-11, 2015, at the Javits Center in New York City, NY. Akana’s comprehensive suite of API Management, API Security, Integrated SOA Governance, and Cloud Integration solutions helps businesses accelerate digital transformation by securely extending their reach across multiple channels – mobile, cloud and Internet of Things. Akana enables enterprises to share data as APIs, connect and integrate applications, drive part...
After making a doctor’s appointment via your mobile device, you receive a calendar invite. The day of your appointment, you get a reminder with the doctor’s location and contact information. As you enter the doctor’s exam room, the medical team is equipped with the latest tablet containing your medical history – he or she makes real time updates to your medical file. At the end of your visit, you receive an electronic prescription to your preferred pharmacy and can schedule your next appointment.
SYS-CON Events announced today that Solgenia will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY, and the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Solgenia is the global market leader in Cloud Collaboration and Cloud Infrastructure software solutions. Designed to “Bridge the Gap” between Personal and Professional Social, Mobile and Cloud user experiences, our solutions help large and medium-sized organizations dr...
SYS-CON Events announced today that Liaison Technologies, a leading provider of data management and integration cloud services and solutions, has been named "Silver Sponsor" of SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York, NY. Liaison Technologies is a recognized market leader in providing cloud-enabled data integration and data management solutions to break down complex information barriers, enabling enterprises to make smarter decisions, faster.
The WebRTC Summit 2014 New York, to be held June 9-11, 2015, at the Javits Center in New York, NY, announces that its Call for Papers is open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 16th International Cloud Expo, @ThingsExpo, Big Data Expo, and DevOps Summit.
SYS-CON Events announced today that CommVault has been named “Bronze Sponsor” of SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY, and the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. A singular vision – a belief in a better way to address current and future data management needs – guides CommVault in the development of Singular Information Management® solutions for high-performance data protection, universal availability and sim...
Cloud is not a commodity. And no matter what you call it, computing doesn’t come out of the sky. It comes from physical hardware inside brick and mortar facilities connected by hundreds of miles of networking cable. And no two clouds are built the same way. SoftLayer gives you the highest performing cloud infrastructure available. One platform that takes data centers around the world that are full of the widest range of cloud computing options, and then integrates and automates everything. Join SoftLayer on June 9 at 16th Cloud Expo to learn about IBM Cloud's SoftLayer platform, explore se...
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.
The list of ‘new paradigm’ technologies that now surrounds us appears to be at an all time high. From cloud computing and Big Data analytics to Bring Your Own Device (BYOD) and the Internet of Things (IoT), today we have to deal with what the industry likes to call ‘paradigm shifts’ at every level of IT. This is disruption; of course, we understand that – change is almost always disruptive.
SYS-CON Media announced today that 9 out of 10 " most read" DevOps articles are published by @DevOpsSummit Blog. Launched in October 2014, @DevOpsSummit Blog offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce softw...
Wearable technology was dominant at this year’s International Consumer Electronics Show (CES) , and MWC was no exception to this trend. New versions of favorites, such as the Samsung Gear (three new products were released: the Gear 2, the Gear 2 Neo and the Gear Fit), shared the limelight with new wearables like Pebble Time Steel (the new premium version of the company’s previously released smartwatch) and the LG Watch Urbane. The most dramatic difference at MWC was an emphasis on presenting wearables as fashion accessories and moving away from the original clunky technology associated with t...
The world's leading Cloud event, Cloud Expo has launched Microservices Journal on the SYS-CON.com portal, featuring over 19,000 original articles, news stories, features, and blog entries. DevOps Journal is focused on this critical enterprise IT topic in the world of cloud computing. Microservices Journal offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. Follow new article posts on Twitter at @MicroservicesE
SYS-CON Events announced today that Site24x7, the cloud infrastructure monitoring service, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Site24x7 is a cloud infrastructure monitoring service that helps monitor the uptime and performance of websites, online applications, servers, mobile websites and custom APIs. The monitoring is done from 50+ locations across the world and from various wireless carriers, thus providing a global perspective of the end-user experience. Site24x7 supports monitoring H...