Re: The Poodlebleed Bug

2014-10-15 Thread Andrew Lutomirski
On Wed, Oct 15, 2014 at 9:00 AM, Sérgio Basto  wrote:
> this site
> http://poodlebleed.com/
>
> says that my server with F19 is vulnerable
>
> any news about this ?

Poodlebleed?

For Pete's sake.  The attack is called POODLE, and it's much more
likely to be an attack against a client instead of an attack against a
server.

That being said, if you aren't serving a web page that you need IE6 on
XP to connect to, you can turn off SSLv3 to protect your clients.  The
setting varies depending on what server application you're using.

>
> Thanks,
> --
> Sérgio M. B.
>
> --
> devel mailing list
> devel@lists.fedoraproject.org
> https://admin.fedoraproject.org/mailman/listinfo/devel
> Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct
-- 
devel mailing list
devel@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel
Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct

Re: The Poodlebleed Bug

2014-10-15 Thread Nathanael D. Noblet
On Wed, 2014-10-15 at 17:00 +0100, Sérgio Basto wrote:
> this site 
> http://poodlebleed.com/ 
> 
> says that my server with F19 is vulnerable 
> 
> any news about this ? 

Disable SSL3? Who needs IE6 on XP?



-- 
devel mailing list
devel@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel
Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct

The Poodlebleed Bug

2014-10-15 Thread Sérgio Basto
this site 
http://poodlebleed.com/ 

says that my server with F19 is vulnerable 

any news about this ? 

Thanks, 
-- 
Sérgio M. B.

-- 
devel mailing list
devel@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel
Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct