Live data from Hacker News

CloudFlare's Heartbleed challenge cracked

twitter.com

151–155 of 155 posts

Re: CloudFlare's Heartbleed challenge cracked

#151
post #145

Earlier quoted context omitted.

This is a great example of why a little knowledge is a bad thing. It almost sounds like you know what you are talking about, which probably confuses people. Heartbleed is dangerous because it exposes private keys, and that let's you decrypt SSL traffic. That in turn may let you read passwords. Don't conflate the two separate things. Compartmentizing is good, but doesn't protect against Heartbleed. Disposable proxies…

The Private key thing is "bad" but far less bad than the user data that is being exposed. The Private Key Exposure lets you do impersonation, but you would have to do something with DNS, or such to get it to work. Where as me getting your user/pass, or account information has immediate impact, and can't be "undone". PS Conflate doesn't mean what you think it does. Conflate has to be wrapper for several topics or idea…

"Conflate" is very often, and properly, used to mean "treating two unrelated things as though they were related," which I believe is exactly what the poster meant to say you are doing. You can make an argument that "trying to conflate" would be more accurate, but only if you're more of a linguistic prescriptivist than most editors.

Re: CloudFlare's Heartbleed challenge cracked

#152
http://iwin270.com/

Nhửng thay đổi trong lần cập nhât phiên bản này - Cập nhật game Liêng . - Fix lỗi lag ở game Xì Tố - Cập nhật các tính năng rung , tính năng mời bạn qua facebook . - Hỗ trợ tối đa các dòng điện thoại Java ( J2ME ) - Các tình trạng lag , disconnect được khắc phục phần lớn . - Chặn các nick auto treo tài khoản . - Và còn rất nhiều tính năng mới đang đợi bạn khám phá

Re: CloudFlare's Heartbleed challenge cracked

#153

Earlier quoted context omitted.

That's close but you actually want to change the size of your packet, not the size of the requested return data. // Essentially OpenSSLs bug is the following buffer = malloc(payload_claimed) // we aren't going over these bounds // Later memcpy(buffer, your_actual_payload, payload_claimed) // we are going over your_actual_payloads bounds By changing your actual payloads size you can influence what data we get. The pay…

Doesn't seem to match https://gist.github.com/indutny/a11c2568533abcf8b9a1

http://iwin270.com/

Nhửng thay đổi trong lần cập nhât phiên bản này - Cập nhật game Liêng . - Fix lỗi lag ở game Xì Tố - Cập nhật các tính năng rung , tính năng mời bạn qua facebook . - Hỗ trợ tối đa các dòng điện thoại Java ( J2ME ) - Các tình trạng lag , disconnect được khắc phục phần lớn . - Chặn các nick auto treo tài khoản . - Và còn rất nhiều tính năng mới đang đợi bạn khám phá

Re: CloudFlare's Heartbleed challenge cracked

#154
iWin sau gần 4 năm phát triển đã cho rất nhiều phiên bản để đem lại lợi ích tốt nhất cho người dùng . trong tháng 10 – 2013 này iWin đã ra cho ra đời phiên bản iwin 280. dành cho hệ điều hành J2ME, hay còn gọi là Java. cập nhật thêm Game Tiến Lên Miền Nam Solo game dành cho 2 người. Nâng tổng số trò chơi trong iwin lên 17 trò, với chức năng solo giúp cho cuộc chơi thêm gây cấn và mang đậm dấu ấn cá nhân. Bạn có thể mời bạn mình cùng chơi với tính năng mời bạn cùng chơi của iWin nhé. http://iwin280.com/

Re: CloudFlare's Heartbleed challenge cracked

#155
post #112

Earlier quoted context omitted.

Interesting. But from got the prime1 and prime2, from there how do you obtain the private certificate?

i think this took me as long as coding the recovery tool :( https://github.com/jjarmoc/csaw2012_cert_app/blob/master/lib... https://github.com/ius/rsatool

Yah, that's the trickiest part. I was pretty ecstatic when I found a real world use case for toy code that I spent way too much time on :)
Post reply on HN