Heartbleed in murga-linux.com?

For discussions about security.
Post Reply
Message
Author
User avatar
mavrothal
Posts: 3096
Joined: Mon 24 Aug 2009, 18:23

Heartbleed in murga-linux.com?

#1 Post by mavrothal »

Though everybody is wondering if puppy is affected by the HeartBleed openSSL bug (even if puppy is not the most likely OS for a server :roll: ) I was rather wondering if murga-linux.com was vulnerable to the bug.
Test sites showing it as fine now and I guess is not a major site :shock: to make the lists, but should we be changing passwords fast or not?
== [url=http://www.catb.org/esr/faqs/smart-questions.html]Here is how to solve your[/url] [url=https://www.chiark.greenend.org.uk/~sgtatham/bugs.html]Linux problems fast[/url] ==

User avatar
dejan555
Posts: 2798
Joined: Sun 30 Nov 2008, 11:57
Location: Montenegro
Contact:

#2 Post by dejan555 »

considering that forum is running ancient phpbb version I doubt openssl is being bumped to newer versions with bug included either.
But maybe server management is not managed by John but some hosting company. In that case he should mail them.
puppy.b0x.me stuff mirrored [url=https://drive.google.com/open?id=0B_Mb589v0iCXNnhSZWRwd3R2UWs]HERE[/url] or [url=http://archive.org/details/Puppy_Linux_puppy.b0x.me_mirror]HERE[/url]

User avatar
ThoriumBlvd
Posts: 159
Joined: Fri 04 Oct 2013, 09:04
Location: N.E. USA

#3 Post by ThoriumBlvd »

IIRC GoDaddy is either the server-host or the domain-holder. Good luck with that.
[img]http://www.am3radio.us/image3.jpg[/img] . [img]http://www.am3radio.us/image4.jpg[/img]

User avatar
Flash
Official Dog Handler
Posts: 13071
Joined: Wed 04 May 2005, 16:04
Location: Arizona USA

#4 Post by Flash »

Website security is the responsibility of our website administrator, John Murga, not our host, whoever that is. As dejan555 pointed out, our website software is so old that it could not contain the ssl "enhancement" that introduced the Heartbleed flaw. :lol:

User avatar
Semme
Posts: 8399
Joined: Sun 07 Aug 2011, 20:07
Location: World_Hub

#5 Post by Semme »

As I've never seen an encrypted page here, I doubt murga-linux even supports ssl over http.

Code: Select all

echo ^D | telnet www.murga-linux.com https
And if it does.. WHOOP-DEE-DOO!

http://www.networking4all.com/en/suppor ... ocol=https

https://www.sslshopper.com/ssl-checker. ... -linux.com

User avatar
mavrothal
Posts: 3096
Joined: Mon 24 Aug 2009, 18:23

#6 Post by mavrothal »

Flash wrote:As dejan555 pointed out, our website software is so old that it could not contain the ssl "enhancement" that introduced the Heartbleed flaw. :lol:
The fact that php is old does not necessarily means that the OS is old too, but as correctly pointed out there are no https here. So all the passwords can be sniffed out but at least we are safe from heardbleed :lol:
== [url=http://www.catb.org/esr/faqs/smart-questions.html]Here is how to solve your[/url] [url=https://www.chiark.greenend.org.uk/~sgtatham/bugs.html]Linux problems fast[/url] ==

slavvo67
Posts: 1610
Joined: Sat 13 Oct 2012, 02:07
Location: The other Mr. 305

#7 Post by slavvo67 »

So what you're saying is it's good to be old! Hoorah! :lol:

User avatar
dejan555
Posts: 2798
Joined: Sun 30 Nov 2008, 11:57
Location: Montenegro
Contact:

#8 Post by dejan555 »

mavrothal wrote:So all the passwords can be sniffed out but at least we are safe from heardbleed :lol:
:lol: Yeah, logging to forum works even from dillo xD
puppy.b0x.me stuff mirrored [url=https://drive.google.com/open?id=0B_Mb589v0iCXNnhSZWRwd3R2UWs]HERE[/url] or [url=http://archive.org/details/Puppy_Linux_puppy.b0x.me_mirror]HERE[/url]

User avatar
mikeb
Posts: 11297
Joined: Thu 23 Nov 2006, 13:56

#9 Post by mikeb »

Dropbox has messed up my use of curl to access it as it's changed its ssl system because of this.
The point is are there any other puppy related sites using https that might affect such as package managers, quickpet, flash updaters etc etc?

mike

jamesbond
Posts: 3433
Joined: Mon 26 Feb 2007, 05:02
Location: The Blue Marble

#10 Post by jamesbond »

mavrothal wrote:The fact that php is old does not necessarily means that the OS is old too, but as correctly pointed out there are no https here. So all the passwords can be sniffed out but at least we are safe from heardbleed :lol:
Now that's different. This forum doesn't use http so we can expect anybody to sniff our passwords just like that. But those https sites come with *expectation* that they are secure. The fact that they are *not* :roll:
Fatdog64 forum links: [url=http://murga-linux.com/puppy/viewtopic.php?t=117546]Latest version[/url] | [url=https://cutt.ly/ke8sn5H]Contributed packages[/url] | [url=https://cutt.ly/se8scrb]ISO builder[/url]

nooby
Posts: 10369
Joined: Sun 29 Jun 2008, 19:05
Location: SwedenEurope

#11 Post by nooby »

John told us some years ??? ago that he choose
the old version to avoid some vulnerability.

But I am too much noob to not get such things.

But I do remember him made it a choice and
he did see some merit doing it that way.
I use Google Search on Puppy Forum
not an ideal solution though

Post Reply