Heartbleed OpenSSL Vulnerability and YourOfficeAnyWhere Servers


Heartbleed OpenSSL Vulnerability and YourOfficeAnyWhere Servers

The following article details the status of YourOfficeAnyWhere infrastructure and customer servers in relation to the Heartbleed OpenSSL Vulnerability.

The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs).

The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.


Does it affect me ?

The short answer to this is No. Servers running Windows Server and IIS (web server) are not susceptible to this bug as Microsoft DO NOT use OpenSSL code within their own web server software. Servers that are at risk are those running various distributions of Linux.  
However if your Windows servers is running another web server such as Apache then we strongly recommend you take measures to ensure your site is unaffected. You can test your site by clicking on the following URL http://filippo.io/Heartbleed/
Simply enter the address of your webserver and if everything is OK you will see a green banner. If you get any kind of error then you need to re certify your website and force your users to reset their passwords.
The following YourOfficeAnyWhere sites are unaffected by the Heartbleed bug:
Web Applications : https://webapps.yourofficeanywhere.co.uk/
Web Mail: https://webmail.yourofficeanywhere.co.uk/
Control Panel: https://myoffice.yourofficeanywhere.co.uk/
Gateway Services: https://apps.yourofficeanywhere.co.uk/ and https://tsg.yourofficeanyhwhere.co.uk/ 



Cardium offer services including Cloud Computing using Microsoft Remote Desktop Services paid for monthly and per user, installation, consultancy and virtualisation best practises.

Company Registration 5135448 VAT registration 834 5840 16





Tel: 01282 500318  |  Web: www.yourofficeanywhere.co.uk



Your Office Anywhere, Cardium Outsourcing, Unit 4, Dominion Court, Billington Road, Burnley, Lancashire, BB11 5UB, UK.


 © Your Office Anywhere 2013