How Heartbleed could've been found
blog.hboeck.de
How Heartbleed could've been found
1–10 of 43 posts
Re: How Heartbleed could've been found
#2And the best of it: only Heartbleed. nothing else. Nothing more.
Looks like it really went that way, but what are the odds?
Re: How Heartbleed could've been found
#3But beyond dynamic analysis, someone wrote a static analysis feature to find heartbleed as well: https://github.com/awruef/find-heartbleed
Re: How Heartbleed could've been found
#4This seems to me a bit like when you do a maze starting from the finish and it is, for whatever reason, trivial to go from one end to the other.
It is neat that it is 2015 and fuzzers are cool again, though.
Re: How Heartbleed could've been found
#5Re: How Heartbleed could've been found
#6Re: How Heartbleed could've been found
#7I rhink there's something fishy with it: you overcome several hurdles to fuzz OpenSSL and then - miraculously - you come up with Heartbleed. And the best of it: only Heartbleed. nothing else. Nothing more. Looks like it really went that way, but what are the odds?
Re: How Heartbleed could've been found
#8Google has a big fuzz-farm and Project Zero looking for this type of thing and even they did not find Heartbleed years ago. They are nabbing tons of bugs but there are many that are simply buried. This seems to me a bit like when you do a maze starting from the finish and it is, for whatever reason, trivial to go from one end to the other. It is neat that it is 2015 and fuzzers are cool again, though.
Re: How Heartbleed could've been found
#9He is doing great work to make the Internet safer.