当前位置:网站首页>Analysis and protection of heart blood dripping vulnerability (cve-2014-0160)
Analysis and protection of heart blood dripping vulnerability (cve-2014-0160)
2022-06-26 13:03:00 【Qianli ZLP】
One 、 Vulnerability profile
2014 year 4 month 7 Japan ,OpenSSL Issue safety bulletins , stay OpenSSL1.0.1 Version to OpenSSL1.0.1f Beta1 There is a vulnerability in the version , The Chinese name of the vulnerability is heart blood drop , English name is HeartBleed. among Heart This means that the vulnerability lies on the heartbeat protocol ,Bleed Because this vulnerability will cause data leakage . namely HeartBleed Is a data leak vulnerability in the heartbeat protocol ,OpenSSL The heartbeat protocol is used in the library .HeartBleed It mainly exists in OpenSSL Of 1.0.1 Version to 1.0.1f edition .
Heartbleed Loopholes allow Internet Anyone on the read by OpenSSL System memory protected by vulnerable versions of software . This undermines the ability to identify service providers and encrypt traffic 、 User name and password as well as the key of the actual content . This allows attackers to eavesdrop on communications , Steal data directly from services and users , And pretend to be a service and a user .SSL/TLS by Web、 E-mail 、 Instant messaging (IM) And some virtual private networks (VPN) And other applications Internet Communication security and privacy on .
Reference link :
https://heartbleed.com/
https://filippo.io/Heartbleed
Two 、 scope
边栏推荐
- 机组实践实验8——使用CMStudio设计基于基本模型机微程序指令(1)
- map 取值
- 心脏滴血漏洞(CVE-2014-0160)分析与防护
- Adobe Acrobat阻止30款安全软件查看PDF文件 或存在安全风险
- 国标GB28181协议EasyGBS视频平台TCP主动模式拉流异常情况修复
- Deeply analyze the differences between dangbei box B3, Tencent Aurora 5S and Xiaomi box 4S
- Goto statement to realize shutdown applet
- System tasks (display / print class) in Verilog - $display, $write, $strobe, $monitor
- Solution of Splunk iowait alarm
- 倍福TwinCAT通过Emergency Scan快速检测物理连接和EtherCAT网络
猜你喜欢
软件测试报告应该包含的内容?面试必问
Adobe Acrobat阻止30款安全软件查看PDF文件 或存在安全风险
倍福TwinCAT3 NCI在NC轴界面中的基本配置和测试
Redis learning - 05 node JS client operation redis and pipeline pipeline
MySQL 自定义函数时:This function has none of DETERMINISTIC, NO SQL 解决方案
软件测试 - 基础篇
[esp32-C3][RT-THREAD] 基于ESP32C3运行RT-THREAD bsp最小系统
processing 函数translate(mouseX, mouseY)学习
倍福PLC选型--如何看电机是多圈绝对值还是单圈绝对值编码器
Xiaobai lazy special-win10-win11 one click installation version
随机推荐
Echart堆叠柱状图:色块之间添加白色间距效果设置
Basic principle and application routine of Beifu PLC rotary cutting
UVA10341 solve it 二分
深度解析当贝盒子B3、腾讯极光5S、小米盒子4S之间的区别
Xiaobai lazy special-win10-win11 one click installation version
Electron official docs series: Get Started
Openlayers drawing dynamic migration lines and curves
LeetCode_栈_中等_150. 逆波兰表达式求值
微信小程序测试点总结
国标GB28181协议EasyGBS级联宇视平台,保活消息出现403该如何处理?
ES6:迭代器
Don't mess with full_ Case and parallel_ CASE
轻流完成与「DaoCloud Enterprise 云原生应用云平台」兼容性认证
HDU1724[辛普森公式求积分]Ellipse
Unit practice experiment 8 - using cmstudio to design microprogram instructions based on basic model machine (1)
倍福TwinCAT通过Emergency Scan快速检测物理连接和EtherCAT网络
KVM video card transparent transmission -- the road of building a dream
HDU 3555 Bomb
Redis learning - 02 common data types, operation commands and expiration time
P2393 yyy loves Maths II