And that was at the same time that everyone was worried about POODLE and the media was going crazy over it.
Somehow this vulnerability went over the radar.
What is interesting is that based on our own data, we started noticing attacks around 8 hours after it was disclosed and we shared some of the payloads being used here:
That's exactly the issue. Most enterprises didn't even have time to be notified and properly test/push a patch live before the attacks were already in the wild.
You have a good point, but I was looking at these two points:
1- Extent of the damage
2- Number of points vulnerable
Heartbleed had (has) a lot more servers vulnerable, but the impact is a lot lower and it is a lot harder to exploit to extract valuable data. In fact, I doubt you will see a compromise or a major issue because of heartbleed (despite the mass drama).
Compared to this problem with Drupal, that is used by the many of the top sites online, the overall damage can be a lot bigger.
It depends on the complexity of the attack. This Drupal one took our team less than an hour to have a working proof of concept (just based on the diffs).
The exploit is very simple, and doesn't require any interaction with the remote site. Explaining why they started on it very fast.
On other more complex exploits, we generally see days (if not weeks), before the attacks start.
We’re small company (35+), with a very culturally diverse configuration across all our teams. We have team members distributed around the world – from the US, Canada to Malaysia, Russia, Brazil and Colombia.
Sucuri is looking for a Senior Frontend Developer to join our R&D (Research and Development) team.
As a senior frontend develper you would be responsible to build dynamic, responsive and beautiful HTML/Javascript/CSS code to be integrated into our web application products.
More details here: http://sucuri.net/company/senior-frontend-developer-022516
Sucuri is looking for a System Administrator with strong Linux and shell scripting experience to join our IT team.
As a system administrator with Sucuri, you would be responsible for building and maintaining our entire stack. This includes all servers and applications used by the team. You would also be responsible for the security of the servers, including log monitoring to ensure their integrity and performance. We place a strong emphasis on security, so you should too. In case of emergencies, you should be available as well.
http://blog.sucuri.net/2014/10/drupal-sql-injection-attempts...
In there you can see the type of backdoors being added (generally fake users with admin-level privileges).