Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-14-2014, 11:41 AM   #1
suesheboy
Confirmed User
 
suesheboy's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
Heartbleed: Motorola and Google...damn

Been a huge Motorola fan boy since the early 80's...yeah I paid $495 for a beeper and more than $4,000 for my first suite case cell phone. Like Google too.

MY tablet has an OS vulnerable to the heartbleed exploit and it took until the 5th tech support person to even find someone to know what it was.

They said to install virus software (won't help with how the exploit works)

They have no idea of when or if they will fix the problem and no mechanism in place to alert people if there is a fix or what to do.

For now I am bringing the table back to factory state and waiting. What a fuck up.

I smell a BIG class action suit brewing.
suesheboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2014, 12:02 PM   #2
bigluv
Confirmed User
 
Join Date: Jul 2008
Posts: 850
I've found the amount of info is sort of lacking as regards mobile.

I think the mobile threat may be overstated. Really, how many incoming services using SSL are used on mobile where there is an incoming connection from an unknown host? In my experience most mobile networks are NATed anyways, and so is your home WiFi. I haven't seen an indepth explanation of so far, just lists of mobile apps that have been compiled using vulnerable versions.
bigluv is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2014, 12:10 PM   #3
bigluv
Confirmed User
 
Join Date: Jul 2008
Posts: 850
My experience with guys on the security side of the IT house is usually they have very little ability to measure actual likelihooods or effects. It's all 'the sky is falling' FUD. I've never met a security guy I had any respect for.

Just for fun just quickly checked any UPNP assigned ports on my home router and I've got nothing for my phone or tablet. So as far as I'm aware all persistent connections are established with the mobile device as the source. Which would mean that Heartbleed is irrelevant in that situation.
bigluv is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2014, 02:53 PM   #4
suesheboy
Confirmed User
 
suesheboy's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
From what I understand a malicious (or hacked) web site can get what's in the ram of effected phones and tablets.

Right now my tablet is going to be used for netflix and that's it.It will not be replaced by a Motorola one thats for sure.
suesheboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2014, 03:06 PM   #5
slavdogg
Confirmed User
 
Join Date: Jan 2001
Posts: 3,570
get an iphone and an ipad
__________________
Adult Traffic for Sale
slavdogg is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2014, 03:45 PM   #6
bigluv
Confirmed User
 
Join Date: Jul 2008
Posts: 850
You're right suesheboy, I educated myself a little bit further and some sources claim that the heartbeat requests are two-way, so a client once it has connected to a host of its choosing would be vulnerable. The important part there is a host of its choosing - there's no ability to exploit this without the connection being initiated by the client.
This limitation is pretty seriously limiting though in my opinion.

Therefore, you would have to be visiting a website whose server has and continues to be seriously compromised (not just heartbleed vulnerable or previously heartbleed vulnerable) but actually taken over by bad actors. So all the usual caveats about not clicking random crap links sortof applies, and I'm sure chrome and antivirus and google search would have a chance to warn you of malware just like usual as soon as they are up to speed. You can pretty easily self police this as far as browsing goes by thinking twice before you use https.

Beyond that, you already did have to evaluate whats sites your apps were connecting to, and if some of them might be small enough to be compromised and stay compromised for heartbleed, so this little wrinkle just ups the ante in that vein a little more.

I think most people when they hear android 4.1.x is affected think that they are suddenly going to be hit by scanning malware completely foreign to them, but that's not how it works.
bigluv is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2014, 05:03 PM   #7
suesheboy
Confirmed User
 
suesheboy's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
Quote:
Originally Posted by slavdogg View Post
get an iphone and an ipad
Funny thing is I have to buy both in order to build out apps, but I don't see myself using them as much. I almost never use my lap top, I use a tablet constantly.
suesheboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2014, 05:04 PM   #8
_Richard_
Too lazy to set a custom title
 
_Richard_'s Avatar
 
Industry Role:
Join Date: Oct 2006
Location: Vancouver
Posts: 30,986
Quote:
Originally Posted by bigluv View Post
It's all 'the sky is falling' FUD. I've never met a security guy I had any respect for.
: thumbsup
_Richard_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-14-2014, 05:07 PM   #9
suesheboy
Confirmed User
 
suesheboy's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
bigluv who ever comes up with the silver bullet can sell it and make a fortune!
suesheboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2014, 04:32 AM   #10
PornDiscounts-V
Confirmed User
 
PornDiscounts-V's Avatar
 
Industry Role:
Join Date: Oct 2003
Location: L.A.
Posts: 5,740
You have to have something the hacker wants. Nobody in this thread has something they want. So don't worry about getting hacked.
__________________
Blog Posts - Contextual Links - Hardlinks on 600+ Blog Network
* Handwritten * 180 C Class IPs * Permanent! * Many Niches! * Bulk Discounts! GFYPosts /at/ J2Media.net
PornDiscounts-V is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2014, 05:00 AM   #11
suesheboy
Confirmed User
 
suesheboy's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
Quote:
Originally Posted by vvvvv View Post
You have to have something the hacker wants. Nobody in this thread has something they want. So don't worry about getting hacked.
Lets see...webmasters with access to countless web sites backends...yeah we are low value targets....NOT!
suesheboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2014, 08:06 AM   #12
bronco67
Too lazy to set a custom title
 
bronco67's Avatar
 
Join Date: Dec 2006
Posts: 29,035
I still don't make credit card transactions on my phone yet...I just don't trust it and don't know if I ever will.
__________________
bronco67 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.