Register FAQ Search Today's Posts Mark Forums Read
Go Back   JazzJackrabbit Community Forums » Maintenance & Feedback » Site and Forum Rules, Questions & Feedback

J2O Heartbleed Bug Verification

PT32 PT32's Avatar

JCF Member

Joined: Jul 2008

Posts: 274

PT32 is an asset to this forum

Apr 11, 2014, 04:25 PM
PT32 is offline
Reply With Quote
J2O Heartbleed Bug Verification

Okay, so I don't know if this affects us or not, but I thought I'd check.

The last couple days, word's been going around about a nasty Internet data leak called "Heartbleed," where sites using a certain type of SSL were vulnerable to having any input information (passwords, credit card numbers, etc) exposed, and stolen.

I read somewhere that over 500,000 sites were vulnerable, so I thought I'd check in and make sure our beloved J2O/JCF wasn't/weren't among them.

Any light to shed on this rather disturbing goings-on?

Thanks!
__________________
Don't say "cannot," say "why not?"

IN DEVELOPMENT:
Renascence: The Last Jackrabbit
djazz djazz's Avatar

JCF Member

Joined: Feb 2009

Posts: 257

djazz is OFF DA CHARTdjazz is OFF DA CHARTdjazz is OFF DA CHART

Apr 12, 2014, 12:34 AM
djazz is offline
Reply With Quote
I don't think so since it's a HTTPS+OpenSSL issue. J2O doesnt use encryption so stuff are sent in clear over the internet anyways. J2O seem to store my hashed password in a cookie, and that's not encrypted.
Heartbleed allows the "hacker" to access out of bounds data through OpenSSL. This data is a part of the memory of the server, and could potentially contain passwords or even the server's private key certificate.
I may be wrong though, this is just how I've heard how heartbleed works.

Here's an XKCD illustration of how it works:
__________________
WebJCS 2 (new and in progress)
WebJCS 1 (old but complete)
SGIP Simple Games in Progress list
Level Packer v2 - With a GUI!
PHP Tileset Compiler
Stijn Stijn's Avatar

Administrator

Joined: Mar 2001

Posts: 6,964

Stijn is a splendid one to beholdStijn is a splendid one to beholdStijn is a splendid one to beholdStijn is a splendid one to beholdStijn is a splendid one to beholdStijn is a splendid one to beholdStijn is a splendid one to behold

Apr 12, 2014, 02:14 AM
Stijn is offline
Reply With Quote
Yeah, J2O doesn't use SSL.

Though it's not inconceivable that other sites on the server do, and as such there *is* a non-zero chance that some data got leaked. If you want to be sure, change your password.
init init's Avatar

JCF Member

Joined: Apr 2010

Posts: 11

init is doing well so far

Apr 12, 2014, 02:42 AM
init is offline
Reply With Quote
Well, at least it's enabled, but not configured properly: https://jazz2online.com So I think the possibility for a memory leak is still there.
Quote:
If you want to be sure, change your password.
I think the fact that passwords are sent in plain text when logging in is a much greater potential security issue than the possibility that passwords have been leaked through a buggy OpenSSL version used by another site on the same web server which just happens to have J2O passwords stored in the affected 64K memory segment.

Then again, we're talking about a fan site for a video game which was released 16 years ago, so I think this discussion is more of an academic value than any practical one.
PT32 PT32's Avatar

JCF Member

Joined: Jul 2008

Posts: 274

PT32 is an asset to this forum

Apr 12, 2014, 03:17 PM
PT32 is offline
Reply With Quote
Okay, thanks for the info!
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

All times are GMT -8. The time now is 10:57 AM.