砍敺 IT_man 2015-1-12 10:51 蝺刻摩 : k% L. I, a: Z$ ^+ k$ D: a
- G3 j5 v7 S* Q, R5 ~$ I
OpenSSL憭扳瘣Heartbleed函蝬脰楝撖唾撓摰冽霅血
% q. z7 X5 s) Q: w! v4 q2 \! H- T7 S- ?' M# l6 c p
( r- H; g! }' w. J, |OpenSSL慵eartBleed憭扳瘣嚗箏函蝬脰楝撣嗡憭批嚗鋡怨箸舐雯頝舀脖誑靘湧瞍瘣摰敶梢踹惜W啣憭憭抒桀隞乩摯閮嚗雿桀舐亦荔敶梢輻蝯銝芣蝬脰楝銝隡箸剁瞍瘣航賢冽澆蝔桃蝬脰楝閮剖蝯蝡航蝵殷星C嚗喲xndroid璈賡隞亙兢 箇Ⅱ靽雿輻刻鞈摰剁閮鞈銝剖冽迨蝬脰楝蝞∠靘銝W嗾暺蝣箏祕憟賡脩芣!! ; [1 A" i% M R3 J7 E1 t, m
1.暻潭烙penSSL Bleeding 5 d* c, _: q2 \5 I* V1 I b% D
8 s s0 j2 M4 q3 ?! Y, u) y9 I
- OpenSSL Bleeding特SL摰鈭(敶梢輻砍1.0.1 1.0.1f / 1.0.2-beta ~ 1.0.2-beta1)瞍瘣6 \4 b- l ~& u, @
- 餅臭誑望迨瞍瘣敺隡箸刻園銝剛 64 KB鞈嚗望瑕閮園銝剖航賢函璈鞈1 M( _6 \( _$ k, y' E0 v7 z
+ ?. D& i7 m0 ^% B$ x0 Y5 Y
2.OpenSSL Bleeding航賡勗拿
9 ~' ~$ h; Z) V- U! \1 P3 h- 餅航梁靘鞈嚗脣雿輻刻撣唾撖蝣潦祉勗撖唾撓靽霅瑞鞈
- 雿輻刻頨思遢嚗脰蝔格靘憒摮email批捆鈭斗鞈靽∠典∟蝑 I5 I$ M" G! k+ t+ ~4 ]: K6 d
7 T7 f$ o* P3 { 3.撠蝬脩蝞∠撱箄降 - 蝣箄OpenSSL 祆臬血敶梢選瑼X交寞(鈭銝) A. Apache 摰鋆桅銝嚗撠暹 OPENSSL-README.txt嚗嗅扳 OpenSSL 祈閮
: N( r5 R0 X1 p% L5 KB.雿輻汪inux_Like雿璆剔頂蝯梯臭蝙冽批嗅賭誘 (Shell Prompt)嚗 Apache OpenSSL 摰鋆桅銝銋bin桅嚗瑁隞歹 openssl version 喳舀亥岷暹 OpenSSL 銋祈閮 - 令penSSL砍敶梢踵殷脰砍蝝嚗 A.拍函頂蝯勗蝝隞(ex. apt-get yum)脰OpenSSL砍蝝6 N# I/ W& h0 e/ g! c2 q. r
嚗
% E+ A6 T# S9 e; r5 i B.OpenSSL摰寧雯蝡銝頛 OpenSSL 1.0.1g隞乩(tarball)蝝 - 芣瑼X葫蝬脩臬血歇摰靽桀儔
/ B5 Q: A+ h' j* j& { 典臭蝙其誑銝蝬脩嚗脰瞍瘣瑼X葫雿璆准 A.Heartbleed test http://filippo.io/Heartbleed/ 5 e' r+ K( U* A5 O/ q- I. K, M
B.LastPass Heartbleed Checker http://lastpass.com/heartbleed/
% q7 A B+ E) z2 W' }
h. ~! d( N3 \ p 4.撠蝬脩閬質撱箄降
# l% d' S! o6 s' n# o, F銝砌蝙刻舐⊥閫瘙榴eartbeat瞍瘣憿嚗粹銝虫臭蝙刻餉行鋆蝵桀憿嚗舐雯蝡蝬脰楝憿嚗雿舐箔踹雿鞈憭瘣抬雿 臭誑∪隞乩芣靽霅瑟芣踝
+ b. ?3 a3 n) r* _! i2 S- 靽霅西死嚗鈭閫閬賣heartbeat瞍瘣憿蝬脩嚗芸楛鞈航賣憭瘣押
- 交靘閬瘙雿霈游蝣潘隢靘批遣霅啣瑁
- 閫撖芸楛撣唾臬行舐瘣餃嚗銝餃霈游舫餃萎辣蝑閬撖蝣潦
- 雿輻冽啁脫頠擃
- 銝閬摮銝蝬脩嚗撠文嗥雯https://剔蝬脩
" f0 V r( ^) H
8 ~) N1 r# ]) C# {; n' Q 5.蝬脩 : Q3 b# s* ]% Y' W6 V
( w$ j, U; o" [- m$ \ @' C. j1 \" R
|