Is this really an accurate challenge? I have wondered if the true exposure risk from Heartbleed may be over-stated* due to memory separation between processes, etc. This however is probably a clean server with a fairly static install. There isn't a risk of things like session leakage which I think is the true risk of Heartbleed. Nor would there be the memory fragmentation that would occur in a production system. Whil…
The Heartbleed Challenge
121–125 of 125 posts
Re: The Heartbleed Challenge
#122 -----BEGIN RSA PRIVATE KEY-----
MIIEowIBAAKCAQEAwYUYN1fR2/z+Net8DdDhNR7poeX608gwFNDVTQZNjldwi503
cLCaFbPpGkkh84sxpsL0PqrMx9OprdNaMPe0ewuTjjZyb1MaqzfXz/XCiOaT7kWZ
P9bRae2cI5CETZHD/CvWjsxZ+0exFRSGtph+3esDuvwGQprfYY8d2PIpPOFDgIW7
gCX6/xTpB+3PCt8lQYbrYiOIogrI+1xpqp5WBCHRzL6La/Zhav1Q6rrSHk1woGdk
gJBNr3k8NsOjFfNbJgLTgsOz7Yu7Wh6UiV7Y5BMxzuK0eMlJey9ODkyFwhG/pnMg
qeMf4j1bfaA9AdI8sffSd+1hY9tbt4vfZhBphQIDAQABAoIBACGh/glwS9rN52h7
mr3T9bADxVsL20H/YsvbV5bhZ407iSXalw4Qw1bOQ877stje8iwnaceSa7C3CqBZ
QS2Nf2J7KpPmxpCugs4LEIjmD383g7I/iljb/t1IHIDZ1wScNtGW1N1QirrvRMmD
Hb6SVko/VBClSHk+7V/JPci8nYok1vWytXyi/QJ8EaQ5FPglm3n+QHBnFdl3A8qn
cWpK3t6BYijkJAK5PNIc1g0YxkSerG5hwCqWleRt29V5QPZqgEc0raSFolN0XOo6
8us1z37IDRGvm0sHbGgKfi3/Mj+b3Npa+0cQgsGVmymLjyMSf/cLiF0c3rDpHamY
NqsFj8ECgYEA4JHeIM0M/MVCbUaqCFOtGYmRK9CL8eoAGVJgXa96Z+gP7W/bAjw9
IEe9NeGIwr2KidZljyv23CwK1Fn7nDuloG5ZXvzpP3jNRJ62Z0Y6RkICpWgpN1HL
uUG6R4LlB3mXyYE4UGoNAxfgWRcPAn0vsKIuY5/N69FBXiE9h6cjHVkCgYEA3Jq8
v/qx7T73p9iUFAFDUNF/poQShqimGdfubMSbhUBXGkx5hPyKYUrzUwwZTlLwo4SB
+nP1cuJUdnEY+ZlzSxvh/EADvxiq20aUm7R+o+GXc68JZBmUKg+tQVSTw+Us8uds
w1jhFa+b4UpSR+ZHOhR5Hhiw1mdRPu5TAwdtzA0CgYBJpQxnTVdY/YePNoFEQcye
d1K4P6flKYvmwfEASC+oK54ti2UTEpYpI92U8eVbl7T7Bug/T3ehNIBIq0msLpNe
TVHZqK8FNaR7QGEo9QrfR35+p+38SkK4+ikQkohxLxrr5giFtoGV5hqYnMs7Ubp1
/nmgCiQJlZIOQHBhMBp/4QKBgEog3OgNz5gPHp0SE8AdJIeVvjUwECGbriTlAEMg
VboTArHdnL/pNH649sajPCWrjR0FO7/zEzlFgGhEXMYSoEFO30MqJ5ghK9h/ARTJ
M/zRo1jGKnuudLElj2xyhSzAZ7g/t7Z0uT3WQqUTmk56vNhxZLmORm3lTdG9t7s+
1dBJAoGBAJWKz/T/0PQLOOggof0KzEciehWuLcV0eLid16DaNWwiVkm88zt54MdB
FkbsXWJpQxYpKCxt4XaZGBVP5yLIkrWjElWMtrZPh3pYR8WJQTwosv74n7roBt80
9ejTR8GQ7401BS7foMjCnVevrl2UwN5SPvtYsLLEMxYGGgSwfz9D
-----END RSA PRIVATE KEY-----Re: The Heartbleed Challenge
#123Earlier quoted context omitted.
Or you can put in a memory area with unmapped sections on both sides if you are paranoid.
True.. I wonder if any specs/certifications actually require something like that. Typically I mostly use tricks like that to track down bugs, but there's nothing wrong with using it in production for something like a single key/cert alloc. It becomes a bit unwieldy if you have lots of things to protect. (Especially on machines with 64k pages :))
Someone else who uses Powerpc?
Re: The Heartbleed Challenge
#124Note that by visiting, your IP and referer become accessible by anyone running an heartbleed exploit: 93.142.x.x - - [11/Apr/2014:10:44:36 -0400] "GET /heartbleed HTTP/1.1" 200 1148 "https://news.ycombinator.com/" "Mozilla/5.0 (Windows NT 6.1; WOW64)AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.116 Safari/537.36"
Whoops, too late. Were you able to get that info from actually running the exploit?
Re: The Heartbleed Challenge
#125Earlier quoted context omitted.
The article is about Cloudfare saying their keys are safe. We were discussing implications of someone winning the Cloudfare challenge. You suggested the fall of the challenge would confirm Neel being wrong? I was alluding to Neel's position that that any key leaking is "unlikely" - a much more tenuous position than Cloudfare's. But maybe you meant that he's alrady been proven wrong, and the nsa would be another? Then…
Too often you seem lame jokes like the original comment that require the belief that NSA is leaps and bounds ahead of the world in infosec AND yet NSA is composed of bumbling morons. NSA would be grossly incompetent if they knew how to retrieve the private key AND then informed the world of their offensive capability. This is a basic tenet of intelligence operations, you do not publicize your capabilities to your adv…
That's the joke. It's a nutty professor situation.