* From https://www.cloudflarechallenge.com/heartbleed * So far, two people have independently solved the Heartbleed Challenge. The first was submitted at 4:22:01PST by Fedor Indutny (@indutny). He sent at least 2.5 million requests over the span of the challenge, this was approximately 30% of all the requests we saw. The second was submitted at 5:12:19PST by Illkka Mattila using around 100 thousand requests. We confi…
CloudFlare's Heartbleed challenge cracked
41–50 of 155 posts
Re: CloudFlare's Heartbleed challenge cracked
#42* From https://www.cloudflarechallenge.com/heartbleed * So far, two people have independently solved the Heartbleed Challenge. The first was submitted at 4:22:01PST by Fedor Indutny (@indutny). He sent at least 2.5 million requests over the span of the challenge, this was approximately 30% of all the requests we saw. The second was submitted at 5:12:19PST by Illkka Mattila using around 100 thousand requests. We confi…
Re: CloudFlare's Heartbleed challenge cracked
#43Re: CloudFlare's Heartbleed challenge cracked
#44As I said, I am not sure that is right or if that was the method used to exploit cloudflare, as I didn't had the time nor the knowledge of openssl implementation to test it out, I am just throwing my guess out there before the official exploit comes about.
edit: formatting
Re: CloudFlare's Heartbleed challenge cracked
#45Earlier quoted context omitted.
Putting that mapping in /etc/hosts lets your machine skip DNS lookup for that hostname, and just use his IP for that domain name. Then, your browser checks the received certificate against the authenticated TLS connection, and sees that all is well, allowing you to connect without a warning. Since the browser does not warn of a certificate mismatch, he must have a valid certificate for 'cloudflarechallenge.com'. QED.
But seems like only the http connection is working, i get a warning in Chrome when visiting https://cloudflarechallenge.com . Isn't that the only situation where the key would be checked. That's the part that doesn't make sense.
openssl s_client -connect 165.225.128.15:443 -showcerts \
-servername www.cloudflarechallenge.com
(Though to fully check, you need to compare certificates with the one off the real site, and ensure that his blog appears upon an HTTP request - to exclude proxying.)Re: CloudFlare's Heartbleed challenge cracked
#46Earlier quoted context omitted.
No. This means you need to change keys for every ssl service you run. Passwords were known to be leaked earlier.
Really it means (as everyone assumed in the first place) that anything a web server might have in its heap needs to be totally thrown away. Private keys. Passwords. Credit card numbers. Security questions/answers. Sessions. Anything you'd send to a web server or receive from a web server is presumed compromised.
Re: CloudFlare's Heartbleed challenge cracked
#47https://twitter.com/eastdakota/status/454792635279220737 Pic of the CloudFlare team reviewing the attack. Ten guys crowded around one monitor.
Hah! That's awesome. Gotta love the Sierra Nevada on the desk too :) edit: now why in the world is my comment being downvoted?
Backup Suspect: Teetotaler/Brogrammer-hater. Doesn't like beer on the desk at work.
Re: CloudFlare's Heartbleed challenge cracked
#48Re: CloudFlare's Heartbleed challenge cracked
#49https://twitter.com/eastdakota/status/454792635279220737 Pic of the CloudFlare team reviewing the attack. Ten guys crowded around one monitor.
Hah! That's awesome. Gotta love the Sierra Nevada on the desk too :) edit: now why in the world is my comment being downvoted?
Re: CloudFlare's Heartbleed challenge cracked
#50Considering he just pulled a shadow file as well, it's not pretty.
Remember, lots of people are pushing up bogus stuff into the heap, so just because you see something there doesn't mean Cloudflare leaked it.