14
CloudStack and “HeartBleed”

CloudStack and the HeartBleed vulnerability

Embed Size (px)

DESCRIPTION

Slides from my talk about how the HeartBleed OpenSSL vulnerability affects Apache CloudStack and how to mitigate the vulnerability. From CloudStack Collaboration Conference 2014 in Denver, CO

Citation preview

Page 1: CloudStack and the HeartBleed vulnerability

CloudStack and “HeartBleed”

Page 2: CloudStack and the HeartBleed vulnerability

We’re here to talk about…

Page 3: CloudStack and the HeartBleed vulnerability

What is Vulnerable• Apache CloudStack 4.2 – 4.3• SystemVMs have vulnerable version of OpenSSL installed• In particular, SSVM is running vulnerable services

Page 4: CloudStack and the HeartBleed vulnerability

FRIENDS DON’T LET FRIENDS USE REALHOSTIP

Page 5: CloudStack and the HeartBleed vulnerability

Status• Apache CloudStack has issued patch instructions

• We’re working on updated SystemVM templates

Page 6: CloudStack and the HeartBleed vulnerability

How to patch• ssh to SystemVM• apt-get update• apt-get install openssl libssl1.0.0 • /etc/init.d/apache2 restart

Page 7: CloudStack and the HeartBleed vulnerability

How to verifydpkg -l|grep ssl

ii libssl1.0.0:i386 1.0.1e-2+deb7u6 i386 SSL shared librariesii openssl 1.0.1e-2+deb7u6 i386 Secure Socket Layer (SSL) binary

Page 9: CloudStack and the HeartBleed vulnerability

HoneypotUsing http://packetstormsecurity.com/files/126068/hb_honeypot.pl.txt

$ sudo perl heartbleed_honeypot.pl

182.118.60.51

182.118.60.51

182.118.60.51

182.118.60.51

Page 10: CloudStack and the HeartBleed vulnerability

Honeypot sniff

Page 11: CloudStack and the HeartBleed vulnerability

Honeypot sniff

Page 12: CloudStack and the HeartBleed vulnerability

Honeypot sniff

Page 13: CloudStack and the HeartBleed vulnerability

ASF Infrastructure team:

“Thank you for your patience while we have worked to sort this out.We expect to reset all LDAP passwords within the next 48 hours or so,so do not be alarmed when your password stops working.”