1. Halo Guest, pastikan Anda selalu menaati peraturan forum sebelum mengirimkan post atau thread baru.

Info Penting Buat Anda Pengguna SSL

Discussion in 'Hosting & Domain' started by IDWebGlobal (IWG), Oct 19, 2014.

  1. IDWebGlobal (IWG)

    IDWebGlobal (IWG) Tim Support RumahSSL.com

    Joined:
    Apr 3, 2014
    Messages:
    535
    Likes Received:
    42
    Location:
    Di bawah langit & Di atas bumi
    Buat Anda yang sedang menggunakan SSL tolong segera untuk menonaktifkan SSLv3. Dikarenakan SSLv3 mempunyai celah atau bug.
    Berikut berita yang menyatakan SSLv3 mempunyai bug.

    __https://access.redhat.com/articles/1232123
    __http://puppetlabs.com/blog/impact-assessment-sslv3-vulnerability-poodle-attack
    __http://www.forbes.com/sites/jameslyne/2014/10/15/poodle-security-vulnerability-breaks-sslv3-secure-browsing/

    Dimohon untuk semua pengguna SSL dan mempunyai VPS segera patch server Anda dan untuk Anda yang jual / provider hosting segeralah patch SSLv3 dengan cara menonaktifkannya.

    Caranya begini:

    NGINX

    Code:
    [FONT=monospace]sudo nano /etc/nginx/nginx.conf[/FONT]
    cari tulisan ssl_protocols lalu ubah menjadi
    Code:
    [FONT=monospace]ssl_protocols TLSv1 TLSv1.1 TLSv1.2;[/FONT]
    Lalu restart Nginx Anda
    Code:
    [FONT=monospace]sudo service nginx restart[/FONT]

    APACHE

    Ubuntu:
    Code:
    [FONT=monospace]sudo nano /etc/apache2/mods-available/ssl.conf[/FONT]
    Centos:
    Code:
    [FONT=monospace]sudo nano /etc/httpd/conf.d/ssl.conf[/FONT]
    Cari tulisan SSLProtocol lalu uba menjadi
    Code:
    [FONT=monospace]SSLProtocol all -SSLv2 -SSLv3[/FONT]


    Tambahkan code berikut dibawah
    # See the mod_ssl documentation for a complete list.
    Code:
    SSLHonorCipherOrder on


    Restart Services
    Ubuntu:
    Code:
    [FONT=monospace]sudo service apache2 restart[/FONT]


    Centos:
    Code:
    [FONT=monospace]sudo service httpd restart[/FONT]


    Nah setelah dirasa sudah selesai silahkan cek url web Anda di __
    https://ssltools.websecurity.symantec.com/checker/views/certCheck.jsp hingga tidak ada icon tanda pentung atau tanda seru. Dan apabila masih ada tanda seru berarti patching Anda gagal. Bisa Anda lihat gambar dibawah ini apabila sukses.

    [​IMG]


    Posisi saya disini menggunakan VPS dan memakai Webuzo sebagai kontrol panel.


    Referensi: __http://httpd.apache.org/docs/2.2/ssl/ssl_faq.html#msie?utm_source=Email&utm_medium=email&utm_campaign=Namecheap+SSL+V+3.0+POODLE+Vulnerability
     
  2. masbayu22

    masbayu22 Super Hero

    Joined:
    May 18, 2011
    Messages:
    1,288
    Likes Received:
    95
    Location:
    Kulivps.com
    Seeppp... Thabks gan
     
  3. Mushlihin

    Mushlihin Super Hero

    Joined:
    Oct 31, 2011
    Messages:
    839
    Likes Received:
    61
    Location:
    Belawa-Wajo
    Info ngejleb nih mantap... Thanks
     
  4. niamz

    niamz Newbie

    Joined:
    Jan 4, 2012
    Messages:
    44
    Likes Received:
    0
    sip gan, semoga makin aman ajah dengan ssl
     
  5. amchostunlimited

    amchostunlimited Hero

    Joined:
    Jul 14, 2011
    Messages:
    630
    Likes Received:
    44
    Location:
    Jakarta
    check hxxp://poodlebleed.com/ untuk check server anda...

    The bug was discovered by Google Security Team researcher Bodo Möller in collaboration with Thai Duong and Krzysztof Kotowicz.
     
  6. exabytes (ID)

    exabytes (ID) Hero

    Joined:
    Nov 9, 2013
    Messages:
    701
    Likes Received:
    96
    Location:
    Jakarta
    SSLv3 memang perlu segera di patch agar aman. Thanks infonya,
     
  7. IDWebGlobal (IWG)

    IDWebGlobal (IWG) Tim Support RumahSSL.com

    Joined:
    Apr 3, 2014
    Messages:
    535
    Likes Received:
    42
    Location:
    Di bawah langit & Di atas bumi
    Sip segera patch yah gan

    yup untuk checker bisa lewat situ gan

    Wajib untuk di patch gan.
     
  8. JaringanHosting

    JaringanHosting Newbie

    Joined:
    Oct 23, 2014
    Messages:
    14
    Likes Received:
    0
    Wah.... Makasih lho uda sharing infonya. Mntapppp
     
  9. aanshared

    aanshared Ads.id Pro

    Joined:
    Feb 13, 2013
    Messages:
    422
    Likes Received:
    10
    Location:
    Palembang deket SumSang
    makasih info-nya bro,, sangat membantu sekali
     

Share This Page