Thousands of Australian servers are still vulnerable to Heartbleed

By

Three years after patches issued.

Around three years after the serious Heartbleed bug was discovered in the OpenSSL crypto library, thousands of servers in Australia remain vulnerable.

Thousands of Australian servers are still vulnerable to Heartbleed

Heartbleed can be exploited to silently to leech data remotely and has since been patched.

But a recent report by vulnerability scanning engine Shodan.io found 2596 systems in Australia and 535 hosts in New Zealand are still susceptible to the flaw.

In total, Shodan.io counted almost 200,000 vulnerable systems around the world. Most of these - over 42,000 - are in the United States, followed by more than 15,000 in South Korea. 

The vast majority of Heartbleed hosts are web servers using the HTTPS protocol for encrypted data transmissions. Shodan.io's report counted almost 52,000 instances of the open source Apache and some 13,000 installations of the Nginx web server that were vulnerable to Heartbleed.

Both are shipped with OpenSSL as the default crypto library. Other vulnerable products include firewalls, broadband routers and webmail servers.

Heartbleed stems from a programming error in the OpenSSL library that lets attackers read server memory in 64 kilobyte chunks. The attack leaves no traces and can be used to glean user credentials and the contents of communications, over supposedly secured internet data transmissions.

The OpenSSL developers issued patches to fix Heartbleed in 2014.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Woolworths' CSO is Optus-bound

Woolworths' CSO is Optus-bound

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

The Northern Beaches Women's Shelter hones focus on tech-enabled abuse

The Northern Beaches Women's Shelter hones focus on tech-enabled abuse

Log In

  |  Forgot your password?