Earlier quoted context omitted.
But seems like only the http connection is working, i get a warning in Chrome when visiting https://cloudflarechallenge.com . Isn't that the only situation where the key would be checked. That's the part that doesn't make sense.
Try setting 'www.cloudflarechallenge.com' in /etc/hosts instead, and when visiting the URL hit - to ensure your browser isn't caching anything. I see Indutny's blog for ' https://www.cloudflarechallenge.com'[/etc/hosts mapped to 165.225.128.15] in both FF and Chrome.
CloudFlare's Heartbleed challenge cracked
31–40 of 155 posts
Re: CloudFlare's Heartbleed challenge cracked
#32The important thing to know here is that you not only have to change your current certs you ALSO HAVE TO REVOKE THE OLD ONE. If you only change your current cert to get a new key but you don't go through the revocation process of the old certificate if someone managed to get the old one they can still use it for a MiTM attack - as both certs would be valid to any client.
http://news.netcraft.com/archives/2013/05/13/how-certificate...
Re: CloudFlare's Heartbleed challenge cracked
#33Earlier quoted context omitted.
I was lucky, my boss understood pretty quickly how big a deal it was. My project manager didn't, though, but he did pretty quick when I cracked our dev server and told him his password for a couple of services. It was fun playing pen tester and getting paid for it this week :)
Do you guys store passwords in plain text? Shouldn't you only be able to get password hashes from a vulnerable server? I might be reading too much into your statement, but I'd like to know if I'm misunderstanding the situation.
Re: CloudFlare's Heartbleed challenge cracked
#34Pic of the CloudFlare team reviewing the attack. Ten guys crowded around one monitor.
Re: CloudFlare's Heartbleed challenge cracked
#35Earlier quoted context omitted.
Do you guys store passwords in plain text? Shouldn't you only be able to get password hashes from a vulnerable server? I might be reading too much into your statement, but I'd like to know if I'm misunderstanding the situation.
If the passwords were POSTed over and left on the heap, then they were vulnerable to being scooped up via Heartbleed, even if they are stored hashed in the database.
Re: CloudFlare's Heartbleed challenge cracked
#36https://twitter.com/indutny/status/454767565991325697 How do you not love this guy.
> How do you not love this guy. Me? Insane jealousy. (Although I do like that he made me google up the X-Men And Teen Titans cover art to confirm the source of his Twitter pic.)
Re: CloudFlare's Heartbleed challenge cracked
#37So far, two people have independently solved the Heartbleed Challenge.
The first was submitted at 4:22:01PST by Fedor Indutny (@indutny). He sent at least 2.5 million requests over the span of the challenge, this was approximately 30% of all the requests we saw. The second was submitted at 5:12:19PST by Illkka Mattila using around 100 thousand requests.
We confirmed that both of these individuals have the private key and that it was obtained through Heartbleed exploits. We rebooted the server at 3:08PST, which may have contributed to the key being available in memory, but we can’t be certain.
Re: CloudFlare's Heartbleed challenge cracked
#38Earlier quoted context omitted.
I was lucky, my boss understood pretty quickly how big a deal it was. My project manager didn't, though, but he did pretty quick when I cracked our dev server and told him his password for a couple of services. It was fun playing pen tester and getting paid for it this week :)
Do you guys store passwords in plain text? Shouldn't you only be able to get password hashes from a vulnerable server? I might be reading too much into your statement, but I'd like to know if I'm misunderstanding the situation.
Re: CloudFlare's Heartbleed challenge cracked
#39https://twitter.com/eastdakota/status/454792635279220737 Pic of the CloudFlare team reviewing the attack. Ten guys crowded around one monitor.
edit: now why in the world is my comment being downvoted?
Re: CloudFlare's Heartbleed challenge cracked
#40* From https://www.cloudflarechallenge.com/heartbleed * So far, two people have independently solved the Heartbleed Challenge. The first was submitted at 4:22:01PST by Fedor Indutny (@indutny). He sent at least 2.5 million requests over the span of the challenge, this was approximately 30% of all the requests we saw. The second was submitted at 5:12:19PST by Illkka Mattila using around 100 thousand requests. We confi…