Hijacking user sessions with the Heartbleed vulnerability
mattslifebytes.com
Hijacking user sessions with the Heartbleed vulnerability
1–10 of 70 posts
Re: Hijacking user sessions with the Heartbleed vulnerability
#2Two years is a long time, people. If ordinary people can write proof of concepts in less than 24 hours after it is publicly disclosed, what to think of those getting paid to find and abuse such bugs? I mean, what are the odds this bug was not abused in production environments the past two years?
Re: Hijacking user sessions with the Heartbleed vulnerability
#3Re: Hijacking user sessions with the Heartbleed vulnerability
#4Scary...
Re: Hijacking user sessions with the Heartbleed vulnerability
#5This is one of these things of which you think "Ah, what are the odds of me being affected?" but quickly changing to "This is pretty bad..." and finally to "FUCK FUCK FUCK, WHY?". Two years is a long time, people. If ordinary people can write proof of concepts in less than 24 hours after it is publicly disclosed, what to think of those getting paid to find and abuse such bugs? I mean, what are the odds this bug was n…
Re: Hijacking user sessions with the Heartbleed vulnerability
#6What are the possibilities of using public key cryptography in the browser? For example, I upload my public key to some website, create an account which is locked to my private key. I get the convenience of not having to log in manually and some extra safety.
Re: Hijacking user sessions with the Heartbleed vulnerability
#7For SSH it's common to use private keys to communicate securely with servers using public key cryptography. This is convenient and protects against key loggers. What are the possibilities of using public key cryptography in the browser? For example, I upload my public key to some website, create an account which is locked to my private key. I get the convenience of not having to log in manually and some extra safety.
Re: Hijacking user sessions with the Heartbleed vulnerability
#8For SSH it's common to use private keys to communicate securely with servers using public key cryptography. This is convenient and protects against key loggers. What are the possibilities of using public key cryptography in the browser? For example, I upload my public key to some website, create an account which is locked to my private key. I get the convenience of not having to log in manually and some extra safety.
Re: Hijacking user sessions with the Heartbleed vulnerability
#9 # ./hb-test.py mail.yahoo.com |grep -A3 -B3 passRe: Hijacking user sessions with the Heartbleed vulnerability
#10This is scary: # ./hb-test.py mail.yahoo.com |grep -A3 -B3 pass