Heartbleed Bug Outline
Heartbleed Bug was firstly found on the last Friday when Antti Karjalainen and other colleagues were updating the functionality of Codenomicon’s test components. Heartbleed bug belongs to zero day exploit, which indicates that the bug has long been existent or known by some technicians who are paid to find some man-made bug for Internet companies.
The moment Heartbleed bug was reportedly to be found, concerns over information security are aroused among the mass as more and more people become prone to store important documents online – Cloud. And now professionals and Internet operation staff are working hard to repair and fix heartbleed bug before hackers develop it. Meanwhile, Codenomicon company has bought the URL “heartbleed.com” to offer some detail information and the latest report on the OpenSSL Exploit.
Some Security Issues about Heartbleed Bug
In sum, Heartbleed bug occurs in the implementation code when OpenSSL is compiling TLS(Transport Layer Security)’s RFC6520. Due to the omissions in bounds checking, the hacker/attacker is enabled to access and quest, without privilege or authentication, for the data that can be up to 64KB stored someplace besides in memory.
The data can be:
