Results 1 to 2 of 2
  1. #1
    Player
    Hyperia's Avatar
    Join Date
    Mar 2014
    Location
    Gridania
    Posts
    1,406
    Character
    Aileen Pureheart
    World
    Sargatanas
    Main Class
    White Mage Lv 100

    Do we have to worry about the Heartbleed issue on the Internet?

    With all of the news going on about the Heartbleed encryption vulnerability, do we need to do anything about our accounts or is SE safe from this problem?
    (0)

  2. #2
    Player
    Raist's Avatar
    Join Date
    Aug 2013
    Posts
    2,457
    Character
    Raist Soulforge
    World
    Midgardsormr
    Main Class
    Thaumaturge Lv 60
    Just tested the forum's main URL with a test tool, and it came back as safe.

    na.finalfantasyxiv.com passed as well (lodestone and such).

    Will have to dig up my notes to test more servers... forget the exact URL's.

    Edit: additional tests run on URL's found in executables:

    frontier.ffxiv.com passed (used in launcher, embedded in the game's executables)
    An embedded URL for the patch server passed.
    secure.square-enix.com passed (used for user/pass verifications in launcher, Mog Station, and SE AM site and such)

    Can't verify the neolobby URL's--won't take HTTPS or standard port 443 to access the servers to test them (getting an I/O timeout... so their security may be blocking all but specific ports)

    Edit 2:
    notes from the author of the test tool about the error I was getting... neolobby servers may in fact be patched as well since they do respond to a ping/trace so I may not be getting blocked by a firewall:
    timeout is apparently also caused by patched servers that don't respond to our "quit" message. This happens with a patched server, but is not a green since the same behavior might be caused by my servers being overloaded, so I can't be sure....

    ...broken pipe, connection reset by peer and timeout errors are rising now, they are probably counter-measures, firewalls and IPS closing the connection or sink-holing it when they detect a heartbeat
    (0)
    Last edited by Raist; 04-11-2014 at 10:52 AM. Reason: brainfarts... some tests included the HTTP on it, muddling the test results.

Tags for this Thread