{"id":1064,"date":"2014-04-10T13:38:38","date_gmt":"2014-04-10T17:38:38","guid":{"rendered":"http:\/\/www.kaspersky.com.tr\/blog\/?p=1064"},"modified":"2020-02-26T18:35:55","modified_gmt":"2020-02-26T15:35:55","slug":"heartbleed-guvenlik-acigi-binlerce-sitede-guvenliginizi-tehlikeye-atabilir","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/heartbleed-guvenlik-acigi-binlerce-sitede-guvenliginizi-tehlikeye-atabilir\/1064\/","title":{"rendered":"&#8220;Heartbleed&#8221; G\u00fcvenlik A\u00e7\u0131\u011f\u0131 Binlerce Sitede G\u00fcvenli\u011finizi Tehlikeye Atabilir"},"content":{"rendered":"<p>E\u011fer bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 sabah 8 haberlerine \u00e7\u0131k\u0131yorsa ger\u00e7ekten ciddi bir durum var demektir. T\u0131pk\u0131 bu sabah, Internet \u00fczerinde en yayg\u0131n kullan\u0131lan kriptolama k\u00fct\u00fcphanesi olan OpenSSL ile ilgili ortaya \u00e7\u0131kan Heartbleed isimli g\u00fcvenlik a\u00e7\u0131\u011f\u0131nda oldu\u011fu gibi. E\u011fer bu konuda kafan\u0131z kar\u0131\u015ft\u0131ysa endi\u015fe etmeyin, bundan sonraki 500 kelime i\u00e7inde t\u00fcm hikayeyi anlataca\u011f\u0131z.<\/p>\n<p>Google, Facebook veya bankan\u0131z\u0131n online sitesi gibi bir web sitesine <a href=\"https:\/\/www.kaspersky.com\/blog\/digital-certificates-httpss\/\" target=\"_blank\" rel=\"noopener nofollow\">kriptolu ba\u011flant\u0131<\/a> kurdu\u011funuzda verileriniz SSL\/TLS protokol\u00fc ile \u015fifrelenerek g\u00f6nderilir. Pek \u00e7ok popular web sunucusu bu i\u015fi yapmas\u0131 i\u00e7in OpenSSL k\u00fct\u00fcphanesini kullan\u0131r. Bu hafta ba\u015f\u0131nda <a href=\"https:\/\/threatpost.com\/openssl-fixes-tls-vulnerability\/105300\" target=\"_blank\" rel=\"noopener nofollow\">OpenSSL ekibi \u201cHeartbeat\u201d isimli TLS \u00f6zelli\u011fi i\u00e7in ciddi bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 i\u00e7in yama yay\u0131nlad\u0131<\/a>. Bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131 nedeniyle sald\u0131ganlar sunucu haf\u0131zas\u0131n\u0131n 64kB\u2019l\u0131k k\u0131sm\u0131na kadar\u0131n\u0131 g\u00f6rebilirler.<\/p>\n<p>Di\u011fer bir deyi\u015fle, Internet \u00fczerindeki herhangi biri bu k\u00fct\u00fcphanenin g\u00fcvenlik a\u00e7\u0131\u011f\u0131 olan s\u00fcr\u00fcm\u00fcn\u00fcn \u00e7al\u0131\u015ft\u0131\u011f\u0131 bir makinan\u0131n haf\u0131zas\u0131n\u0131 okuyabilir. En k\u00f6t\u00fc senaryoda bu k\u00fc\u00e7\u00fck haf\u0131za bloku, kullan\u0131c\u0131 ad\u0131, \u015fifre hatta sunucunun kriptolu ba\u011flant\u0131 kurmak i\u00e7in kulland\u0131\u011f\u0131 \u00f6zel anahtar gibi hassas verileri i\u00e7eriyor olabilir. Bunlara ek olarak, Heartbleed g\u00fcvenlik a\u00e7\u0131\u011f\u0131 arkas\u0131nda hi\u00e7 bir iz b\u0131rakm\u0131yor. Yani sunucunun hack edilip edilmedi\u011fini, edildiyse ne t\u00fcr verilerin \u00e7al\u0131nd\u0131\u011f\u0131n\u0131 s\u00f6ylemek m\u00fcmk\u00fcn de\u011fil.<\/p>\n<p>\u0130yi haber OpenSSL bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131na yama yay\u0131nlad\u0131. K\u00f6t\u00fc haber, Heartbleed g\u00fcvenlik a\u00e7\u0131\u011f\u0131na sahip olan sitelerin bu yamay\u0131 y\u00fcklediklerinin bir garantisi yok. Daha k\u00f6t\u00fc haber, bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131 kullanmak \u00e7ok kolay g\u00f6z\u00fck\u00fcyor ve en az iki y\u0131ld\u0131r sunucular bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131 ile \u00e7al\u0131\u015f\u0131yordu. Yani pek \u00e7ok pop\u00fcler web sitesinin sertifikalar\u0131, hatta \u015fifreleri de dahil hassas bilgileri \u00e7al\u0131nm\u0131\u015f olabilir.<\/p>\n<h1>Kullan\u0131c\u0131lar i\u00e7in eylem plan\u0131<\/h1>\n<ul>\n<li><b>Favori web sitleriniz g\u00fcvenlik a\u00e7\u0131\u011f\u0131na sahip mi kontrol edin<\/b>. G\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131n varl\u0131\u011f\u0131n\u0131 <a href=\"http:\/\/filippo.io\/Heartbleed\" target=\"_blank\" rel=\"noopener nofollow\">kontrol edebilece\u011finiz online ara\u00e7lar<\/a> mevcut. Yama yap\u0131lm\u0131\u015f olabilece\u011fi i\u00e7in daha \u00f6nce g\u00fcvenlik a\u00e7\u0131\u011f\u0131 olup olmad\u0131\u011f\u0131n\u0131 kontrol etmeyi unutmay\u0131n. \u015eansl\u0131y\u0131z ki <a href=\"https:\/\/github.com\/musalbas\/heartbleed-masstest\/blob\/94cd9b6426311f0d20539e696496ed3d7bdd2a94\/top1000.txt\" target=\"_blank\" rel=\"noopener nofollow\">pop\u00fcler web sitlerinin b\u00fcy\u00fck bir k\u0131sm\u0131<\/a> bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131 konusunda kontrol edilmi\u015f. \u0130yi haber, Google ve Facebook bu durumdan etkilenmemi\u015f. K\u00f6t\u00fc haber Yahoo, Flickr, Duckduckgo, LastPass, Redtube, OkCupid, Hidemyass, 500px daha pek \u00e7ok site etkilenmi\u015f. E\u011fer bu sitelerden birinde hesab\u0131n\u0131z var ise harekete ge\u00e7meye haz\u0131r olun.;<\/li>\n<li><b>Sitede \u015fu anda g\u00fcvenlik a\u00e7\u0131\u011f\u0131 olup olmad\u0131\u011f\u0131n\u0131 kontrol edin<\/b>. Bunun i\u00e7in bu <a href=\"http:\/\/filippo.io\/Heartbleed\" target=\"_blank\" rel=\"noopener nofollow\">basit arac\u0131<\/a> kullanabilirsiniz.<a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2014\/04\/06015025\/heartbleed1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1066\" alt=\"heartbleed1\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2014\/04\/06015025\/heartbleed1.png\" width=\"400\" height=\"203\"><\/a><\/li>\n<li>Site sahibi hatay\u0131 yamad\u0131\u011f\u0131nda sertifikalar\u0131 da yeniden imzalamal\u0131d\u0131r. Bu nedenle <b>sunucu<\/b> <b>sertifikas\u0131n\u0131 izlemeye haz\u0131r olun<\/b> ve <b>yeni bir tane kullan\u0131ld\u0131\u011f\u0131ndan emin <\/b>(8 Nisan ve sonras\u0131 bir tarih) olun. Bunun i\u00e7in taray\u0131c\u0131n\u0131zda sertifika iptal kontrol\u00fcn\u00fc etkinle\u015ftirin.\u00a0Google Chorme i\u00e7in \u00f6rnek ayarlar \u015fu \u015fekilde:<a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2014\/04\/06015023\/heartbleed2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1067\" alt=\"heartbleed2\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2014\/04\/06015023\/heartbleed2.png\" width=\"427\" height=\"173\"><\/a><\/li>\n<li>\u2028Bu sayede taray\u0131c\u0131n\u0131z\u0131n eski sertifikalar\u0131 kullanmas\u0131n\u0131 \u00f6nlemi\u015f olursunuz. Sertifikan\u0131n olu\u015fturulma tarihini el ile kontrol etmek i\u00e7in adres \u00e7ubu\u011fundaki ye\u015fil \u00e7ubu\u011fa t\u0131klay\u0131p \u201cBa\u011flant\u0131\u201d sekmesindeki \u201cbilgi\u201d linkine bas\u0131n:\u2028<a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2014\/04\/06015022\/heartbleed3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1068\" alt=\"heartbleed3\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2014\/04\/06015022\/heartbleed3.png\" width=\"346\" height=\"353\"><\/a><\/li>\n<li>En \u00f6nemli ad\u0131m ise sunucu yamas\u0131 yap\u0131l\u0131p ve sertifika yenilendikten sonra <b>hemen \u015fifrenizi de\u011fi\u015ftirmektir.<\/b> Bu durumu bir f\u0131rsat olarak de\u011ferlendirerek \u015fifre politikan\u0131z\u0131 de\u011fi\u015ftirip <a href=\"https:\/\/www.kaspersky.com\/blog\/21st-century-passwords\/\" target=\"_blank\" rel=\"noopener nofollow\">kolay hat\u0131rlanabilen ama g\u00fc\u00e7l\u00fc \u015fifreler<\/a> kullanmaya ba\u015flayabilirsiniz. Ayr\u0131ca yeni \u015fifrelerinizin g\u00fc\u00e7l\u00fc olup olmad\u0131\u011f\u0131n <a href=\"https:\/\/www.kaspersky.com\/blog\/password-check\/\" target=\"_blank\" rel=\"noopener nofollow\">\u015eifre Kontrol<\/a> edici ile kontrol edebilirsiniz.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>E\u011fer bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 sabah 8 haberlerine \u00e7\u0131k\u0131yorsa ger\u00e7ekten ciddi bir durum var demektir. T\u0131pk\u0131 bu sabah, Internet \u00fczerinde en yayg\u0131n kullan\u0131lan kriptolama k\u00fct\u00fcphanesi olan OpenSSL ile ilgili ortaya \u00e7\u0131kan<\/p>\n","protected":false},"author":350,"featured_media":1065,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1287,1284,1351],"tags":[744,559,558,556,557,560,561,562],"class_list":{"0":"post-1064","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-tips","9":"category-threats","10":"tag-guvenlik","11":"tag-haberler-2","12":"tag-heartbleed","13":"tag-hesap-guvenligi","14":"tag-kriptolama","15":"tag-openssl","16":"tag-sifreler","17":"tag-ssl"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/heartbleed-guvenlik-acigi-binlerce-sitede-guvenliginizi-tehlikeye-atabilir\/1064\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/guvenlik\/","name":"G\u00fcvenlik"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/1064","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/350"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=1064"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/1064\/revisions"}],"predecessor-version":[{"id":7750,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/1064\/revisions\/7750"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/1065"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=1064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=1064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=1064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}