Deadly 'Heartbleed' virus arrives in Indian cyberspace

Image
Press Trust of India New Delhi
Last Updated : Apr 11 2014 | 2:15 PM IST
Indian cyber security sleuths have alerted Internet users against a "highly severe" virus named 'heartbleed', which has sent alarm bells ringing across the globe for fear of exposing millions of passwords, credit card numbers and other sensitive information to hackers.
The virus prowling in the domestic arena, authorities said, attacks the openSSL of an online system which is the most essential protocol which encrypts information and data transfer over the Internet.
The Computer Emergency Response Team of India (CERT-In), the nodal agency to combat hacking, phishing and to fortify security-related defences of the country's Internet domain, fears it could compromise personal data and passwords of a user.
"A vulnerability (heartbleed) has been reported in OpenSSL, which could be exploited by a remote attacker to disclose potentially sensitive information. The vulnerability is due to improper bounds checking while handling TLS/DTLS heartbeat extension packets.
"A remote attacker could exploit this vulnerability by submitting crafted TLS or DTLS heartbeat packets to an affected device to retrieve sensitive information, such as private keys, user name and passwords or contents of encrypted traffic from process memory. By leveraging this information, an attacker may be able to decrypt, spoof, or perform man-in-the-middle attacks," the CERT-In said in its latest advisory to Internet users in the country.
Categorising the severity of the virus as "high", the agency said all unguarded or vulnerable online systems are prone to the virus' attack.
The virus, with derives its name from a 'bleeding red heart' motif, has made a number of countries sit up and take notice of its destructive and threatening activities over the last few days.
Two days back, Canada's tax agency had said that it has temporarily cut off public access to its electronic filling services just three weeks before the tax deadline because of security concerns over the "Heartbleed bug."
"It has been confirmed that the virus is active in the Indian cyberspace too. Some of its suspect messages also resemble a 'red-coloured X' motif similar to the red bleeding heart," a cyber security expert told PTI.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Apr 11 2014 | 2:15 PM IST

Next Story