Apr 11, 2014, 04:25 PM | |
J2O Heartbleed Bug Verification
Okay, so I don't know if this affects us or not, but I thought I'd check.
The last couple days, word's been going around about a nasty Internet data leak called "Heartbleed," where sites using a certain type of SSL were vulnerable to having any input information (passwords, credit card numbers, etc) exposed, and stolen. I read somewhere that over 500,000 sites were vulnerable, so I thought I'd check in and make sure our beloved J2O/JCF wasn't/weren't among them. Any light to shed on this rather disturbing goings-on? Thanks!
__________________
Don't say "cannot," say "why not?" IN DEVELOPMENT: Renascence: The Last Jackrabbit |
Apr 12, 2014, 12:34 AM | |
I don't think so since it's a HTTPS+OpenSSL issue. J2O doesnt use encryption so stuff are sent in clear over the internet anyways. J2O seem to store my hashed password in a cookie, and that's not encrypted.
Heartbleed allows the "hacker" to access out of bounds data through OpenSSL. This data is a part of the memory of the server, and could potentially contain passwords or even the server's private key certificate. I may be wrong though, this is just how I've heard how heartbleed works. Here's an XKCD illustration of how it works: ![]()
__________________
WebJCS 2 (new and in progress) WebJCS 1 (old but complete) SGIP Simple Games in Progress list Level Packer v2 - With a GUI! PHP Tileset Compiler |
Apr 12, 2014, 02:42 AM | ||
Well, at least it's enabled, but not configured properly: https://jazz2online.com So I think the possibility for a memory leak is still there.
Quote:
Then again, we're talking about a fan site for a video game which was released 16 years ago, so I think this discussion is more of an academic value than any practical one. |
![]() |
«
Previous Thread
|
Next Thread
»
Thread Tools | |
|
|
All times are GMT -8. The time now is 05:06 AM.
Jazz2Online © 1999-INFINITY (Site Credits). Jazz Jackrabbit, Jazz Jackrabbit 2, Jazz Jackrabbit Advance and all related trademarks and media are ™ and © Epic Games. Lori Jackrabbit is © Dean Dodrill. J2O development powered by Loops of Fury and Chemical Beats. Powered by vBulletin® Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Original site design by Ovi Demetrian. DrJones is the puppet master. Eat your lima beans, Johnny.