Click here to close now.

Welcome!

Apache Authors: Pat Romanski, Bob Gourley, Elizabeth White, Mark R. Hinkle, Carmen Gonzalez

Blog Feed Post

Heartbleed, la plus grosse faille de l’Internet

Le 7 Avril 2014 a été décelé la plus sérieuse faille de sécurité de l’histoire d’internet, impactant l’intégrité de bases de données les plus sécurisées du monde. Cette brèche permet à un attaquant chevronné d’accéder à des informations sensibles incluant potentiellement les identifiants, mots de passe, numéros de cartes bancaires… et d’emporter la clé de sécurité du serveur qui héberge ces données.

Le moteur (OpenSSL) qui assure les connexions sécurisées et chiffrées entre un utilisateur et un site web est reconnaissable par un « https » dans la barre d’adresse ou un cadenas en bas à droite de votre navigateur. Une attaque Heartbleed ne laisse aucune trace sur le serveur, c’est pourquoi il est d’autant plus important de le combler. Car aucune attaque ne pourra être tracée, rendant une enquête impossible.

Les patchs de correction ont été livrés en 49 minutes. Mais l’ampleur des dégâts n’est pas encore connue car on ne sait pas si la faille a déjà été exploitée avant son identification. Vos mots de passe pourraient déjà avoir été dérobés. Facebook, Google, Gmail, Yahoo !, Dropbox, Pinterest, Instagram, Twitter, Tumblr … Aucuns de ces sites précisent avoir constatés des utilisations irrégulières de leurs services. Les éditeurs indiquent qu’ils ont évalués cette vulnérabilité et qu’ils recommandent toutefois aux utilisateurs de changer leurs mots de passe.

L’offre Microsoft de Provectio est-elle sensible à la faille HeartBleed ?

Les configurations par défaut de Windows ne comprennent pas OpenSSL, donc ne sont pas affectés par cette vulnérabilité. Windows est livré avec son propre composant de chiffrement appelé Secure Channel (aka SChannel ) , qui n’est pas sensible à la vulnérabilité Heartbleed . Cela s’applique à tous les systèmes d’exploitation Windows et IIS versions , jusqu’à et y compris IIS 8.5 fonctionnant sur tous les systèmes d’exploitation suivants : Windows Server 2003 et 2003R2, Windows Server 2008, Windows Server 2008R2, Windows Server 2012, Windows Server 2012R2. Les clients logiciels sur Windows qui utilisent OpenSSL au lieu de SChannel (livré dans Apache pour Windows) peuvent être vulnérables.

L’offre Linux de Provectio est-elle sensible à la faille HeartBleed ?

Les versions openssl impactés sont : 1.0.1 et 1.0.2-beta releases inclut aussi les versions 1.0.1f and 1.0.2-beta1. Sur notre plateforme OpenVPN nous exploitons la version OpenSSL 0.9.8k. Les distributions Linux Protection Suite, Linux Data Suite, Linux Virtual Hoster, Linux eMail Control ne sont pas impactés par cette faille de sécurité.

Nos éditeurs de sécurité déjà sur la brèche

Sophos, dont Provectio travaille sur l’obtention du statut Platinium, a d’ores et déjà commencé à déployer son patch de sécurité et documenté le sujet. L’ensemble du parc Sophos UTM de nos clients est déjà à jour.

Identification des services impactés

Toutefois, certains services hébergés par Provectio sont sensibles à cette faille, nous menons actuellement un programme de mise à niveau :

  •  VPN sites à sites et nomades : Nous déployons en ce moment les correctifs. Vous serez prévenu de prochaines interruptions de service momentanées si elles étaient nécessaires. Nous effectuerons le renouvellement des certificats pour les utilisateurs nomades du VPN. Nous vous contacterons pour effectuer la mise à jour sur vos postes de travail.
  • Serveurs Web hébergés : Renouvellement des certificats et changement de mot de passe.

En bon utilisateur, nous vous recommandons :

  1. Changez immédiatement les mots de passe des comptes Internet que vous considérez comme sensibles (par exemple votre banque, vos comptes email, votre compte PayPal, …) en générant des mots de passe forts et uniques
  2. Attendez 10 jours avant de changer vos autres mots de passe afin de laisser le temps aux différents sites web d’éliminer la faille Heartbleed. Il est inutile de changer vos autres mots de passe avant.
  3. Dans 10 jours, changez à nouveau les mots de passe de vos comptes sensibles en générant des mots de passe forts et uniques.
  4. Une fois l’étape 3 terminée, vous pouvez changer les mots de passe de vos comptes moins sensibles.

Nous vous recommandons l’utilisation d’un produit français Dashlane, pour la gestion sécurisée de vos mots de passe.

Le point le plus important est de vous assurer que vous utilisez des mots de passe différents sur chaque site, car si votre mot de passe est volé sur un site, il ne pourra pas être utilisé sur un autre ; c’était important avant Heartbleed et c’est devenu essentiel aujourd’hui.

 Si vous êtes vulnérable à ce type de failles et que votre prestataire ne vous suit pas, vous connaissez le chemin !

The post Heartbleed, la plus grosse faille de l’Internet appeared first on Provectio - Cloud Computing et Infogérance.

Read the original blog entry...

More Stories By Maxime Charlès

Maxime Charlès is co-founder and CEO of Provectio, a French organization dedicated to Cloud Computing, IT and Outsourcing. His motto : "to surround himself with the best without fear that they will exceed"

@ThingsExpo Stories
SYS-CON Events announced today that SafeLogic has been named “Bag Sponsor” of SYS-CON's 16th International Cloud Expo® New York, which will take place June 9-11, 2015, at the Javits Center in New York City, NY. SafeLogic provides security products for applications in mobile and server/appliance environments. SafeLogic’s flagship product CryptoComply is a FIPS 140-2 validated cryptographic engine designed to secure data on servers, workstations, appliances, mobile devices, and in the Cloud.
SYS-CON Events announced today that StorPool Storage will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. StorPool is distributed storage software that allows service providers, enterprises and other cloud builders to run data storage on standard x86 servers, instead of using expensive and inefficient storage arrays (SAN).
SYS-CON Events announced today that Site24x7, the cloud infrastructure monitoring service, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Site24x7 is a cloud infrastructure monitoring service that helps monitor the uptime and performance of websites, online applications, servers, mobile websites and custom APIs. The monitoring is done from 50+ locations across the world and from various wireless carriers, thus providing a global perspective of the end-user experience. Site24x7 supports monitoring H...
SYS-CON Events announced today that B2Cloud, a provider of enterprise resource planning software, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. B2cloud develops the software you need. They have the ideal tools to help you work with your clients. B2Cloud’s main solutions include AGIS – ERP, CLOHC, AGIS – Invoice, and IZUM
SYS-CON Events announced today that Intelligent Systems Services will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Established in 1994, Intelligent Systems Services Inc. is located near Washington, DC, with representatives and partners nationwide. ISS’s well-established track record is based on the continuous pursuit of excellence in designing, implementing and supporting nationwide clients’ mission-critical systems. ISS has completed many successful projects in Healthcare, Commercial, Manufacturing, ...
SYS-CON Events announced today that Vicom Computer Services, Inc., a provider of technology and service solutions, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. They are located at booth #427. Vicom Computer Services, Inc. is a progressive leader in the technology industry for over 30 years. Headquartered in the NY Metropolitan area. Vicom provides products and services based on today’s requirements around Unified Networks, Cloud Computing strategies, Virtualization around Software defined Data Ce...
SYS-CON Events announced today that Optimal Design, an Internet of Things solution provider, will exhibit at SYS-CON's Internet of @ThingsExpo, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Optimal Design is an award winning product development firm offering industrial design and engineering services to the consumer, medical, and defense markets.
SYS-CON Events announced today that Tufin, the market-leading provider of Security Policy Orchestration Solutions, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. As the market leader of Security Policy Orchestration, Tufin automates and accelerates network configuration changes while maintaining security and compliance. Tufin's award-winning Orchestration Suite™ gives IT organizations the power and agility to enforce security policy across complex, multi-vendor enterprise networks. With more than 1...
SYS-CON Events announced today that MangoApps will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY., and the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. MangoApps provides private all-in-one social intranets allowing workers to securely collaborate from anywhere in the world and from any device. Social, mobile, and easy to use. MangoApps has been named a "Market Leader" by Ovum Research and a "Cool Vendor" by Gartner...
SYS-CON Events announced today that Cloudian, Inc., the leading provider of hybrid cloud storage solutions, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Cloudian, Inc., is a Foster City, California - based software company specializing in cloud storage software. The main product is Cloudian, an Amazon S3-compliant cloud object storage platform, the bedrock of cloud computing systems, that enables cloud service providers and enterprises to build reliable, affordable and scalable cloud storage solu...
SYS-CON Events announced today that Gridstore™, the leader in hyper-converged infrastructure purpose-built to optimize Microsoft workloads, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Gridstore™ is the leader in hyper-converged infrastructure purpose-built for Microsoft workloads and designed to accelerate applications in virtualized environments. Gridstore’s hyper-converged infrastructure is the industry’s first all flash version of HyperConverged Appliances that include both compute and storag...
SYS-CON Events announced today that Creative Business Solutions will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Creative Business Solutions is the top stocking authorized HP Renew Distributor in the U.S. Based out of Long Island, NY, Creative Business Solutions offers a one-stop shop for a diverse range of products including Proliant, Blade and Industry Standard Servers, Networking, Server Options and Care Packs. As a trusted supplier, CBS guarantees quality controlled stock levels thanks to an Auto...
How is unified communications transforming the way businesses operate? In his session at WebRTC Summit, Arvind Rangarajan, Director of Product Marketing at BroadSoft, will discuss how to extend unified communications experience outside the enterprise through WebRTC. He will also review use cases across different industry verticals. Arvind Rangarajan is Director, Product Marketing at BroadSoft. He has over 19 years of experience in the telecommunications industry in various roles such as Software Development, Product Management and Product Marketing, applied across Wireless, Unified Communic...
SYS-CON Events announced today that IDenticard will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. IDenticard™ is the security division of Brady Corp (NYSE: BRC), a $1.5 billion manufacturer of identification products. We have small-company values with the strength and stability of a major corporation. IDenticard offers local sales, support and service to our customers across the United States and Canada. Our partner network encompasses some 300 of the world's leading systems integrators and security s...
What exactly is a cognitive application? In her session at 16th Cloud Expo, Ashley Hathaway, Product Manager at IBM Watson, will look at the services being offered by the IBM Watson Developer Cloud and what that means for developers and Big Data. She'll explore how IBM Watson and its partnerships will continue to grow and help define what it means to be a cognitive service, as well as take a look at the offerings on Bluemix. She will also check out how Watson and the Alchemy API team up to offer disruptive APIs to developers.
The IoT Bootcamp is coming to Cloud Expo | @ThingsExpo on June 9-10 at the Javits Center in New York. Instructor. Registration is now available at http://iotbootcamp.sys-con.com/ Instructor Janakiram MSV previously taught the famously successful Multi-Cloud Bootcamp at Cloud Expo | @ThingsExpo in November in Santa Clara. Now he is expanding the focus to Janakiram is the founder and CTO of Get Cloud Ready Consulting, a niche Cloud Migration and Cloud Operations firm that recently got acquired by Aditi Technologies. He is a Microsoft Regional Director for Hyderabad, India, and one of the f...
The 17th International Cloud Expo has announced that its Call for Papers is open. 17th International Cloud Expo, to be held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, APM, APIs, Microservices, Security, Big Data, Internet of Things, DevOps and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportunity. Submit your speaking proposal today!
With IoT exploding, massive data will transform businesses with opportunities to monetize almost anything that can be measured. In this C-Level Roundtable Discussion at @ThingsExpo, Brendan O’Brien, Aria Systems Co-founder and Chief Evangelist, will lead an expert panel of consultants, thought leaders and practitioners who will look at these new monetization trends, discuss the implications, and detail lessons learned from their collective experience. Finally, the panel will point the way forward for enterprises who wish to leverage the resulting complex recurring revenue models, adding valu...
SYS-CON Events announced today that Ciqada will exhibit at SYS-CON's @ThingsExpo, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Ciqada™ makes it easy to connect your products to the Internet. By integrating key components - hardware, servers, dashboards, and mobile apps - into an easy-to-use, configurable system, your products can quickly and securely join the internet of things. With remote monitoring, control, and alert messaging capability, you will meet your customers' needs of tomorrow - today! Ciqada. Let your products take flight. For more inform...
SYS-CON Events announced today that ActiveState, the leading independent Cloud Foundry and Docker-based PaaS provider, has been named “Silver Sponsor” of SYS-CON's DevOps Summit New York, which will take place June 9-11, 2015, at the Javits Center in New York City, NY. ActiveState believes that enterprises gain a competitive advantage when they are able to quickly create, deploy and efficiently manage software solutions that immediately create business value, but they face many challenges that prevent them from doing so. The Company is uniquely positioned to help address these challenges thro...