Heartbleed patching effort stalls at around 300,000 vulnerable servers

The number of servers vulnerable to the Heartbleed exploit decreased by only around 9,000 in the past month, a recent scan shows

Despite a great start, the rate of patching OpenSSL servers against the critical Heartbleed vulnerability has slowed down to almost a halt. Around 300,000 servers remain vulnerable and many of them are unlikely to get patched anytime soon.

Over the past month only around 9,000 servers were secured, a far cry from the almost 300,000 servers patched during the first month after the vulnerability was revealed.

The Heartbleed flaw was publicly disclosed in early April and allows attackers to extract information from the memory of servers that run OpenSSL 1.0.1 through 1.0.1f, if they support an SSL feature called "heartbeat." The extracted information can include user passwords and long-term server private keys that can be used to decrypt SSL traffic captured from servers.

Shortly after the vulnerability was announced, Robert Graham, the CEO of Errata Security, ran an Internet scan and found 615,268 publicly accessible SSL servers that were vulnerable to Heartbleed. He repeated the scan one month later and found that the number of vulnerable systems had decreased by almost half, to 318,239.

The impressive patching rate was also reflected in the results of other tests. Immediately after the flaw was made public, Ivan Ristic, who runs a monthly scan of the Internet's top 155,000 SSL-enabled sites as part of the SSL Pulse project, estimated that up to 30 percent of those sites might be vulnerable. A month later the SSL Pulse data was showing that only 1,291 sites, or 0.8 percent of the total, were still vulnerable to Heartbleed, leading Ristic to describe the Heartbleed patching effort as "incredibly fast" in a recent email.

However, it doesn't seem there has been a lot of progress since early May.

"Last night, now slightly over two months after Heartbleed, we scanned again, and found 300k (309,197) still vulnerable," Graham said Saturday in a blog post. "This indicates people have stopped even trying to patch. "

Since the SSL Pulse scan results for June show only 1,044 sites vulnerable to Heartbleed, the almost 310,000 vulnerable servers found by Graham are likely hosting less popular sites not covered by the project. And if those servers haven't been patched until now, despite significant efforts to raise awareness about this vulnerability on the Internet, it's likely many of them will remain vulnerable for some time to come.

"Even a decade from now, though, I still expect to find thousands of systems, including critical ones, still vulnerable," Graham said.

The researcher plans to decrease the frequency of his scans in the future. The next scan will be performed in a month, then in six months and then yearly after that, he said.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags Errata Securitypatchesonline safetysecuritypatch managementencryptionExploits / vulnerabilities

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?