a thoughtful web.
Good ideas and conversation. No ads, no tracking.   Login or Take a Tour!
comment by Hell
Hell  ·  3884 days ago  ·  link  ·    ·  parent  ·  post: How does the heartbleed attack work?

Wow. I can't believe something held to such a standard of being secure had such a simple leak. Does anyone know how someone could ask for more characters than they typed in though?





user-inactivated  ·  3884 days ago  ·  link  ·  

    Does anyone know how someone could ask for more characters than they typed in though?

You write a program to make heartbeat requests whose length field is greater than the length of the data.

ecib  ·  3884 days ago  ·  link  ·  

And for so long...

alpha0  ·  3884 days ago  ·  link  ·  
alpha0  ·  3884 days ago  ·  link  ·  

64k payload for "heartbeat" on TCP. IETF board approved. Enough said?