[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FD] heartbleed OpenSSL bug CVE-2014-0160



Paul,

On 11-04-14 08:32, Paul Vixie wrote:
> no remote file modification, no root shell, no
> non-root shell, no data-modification, no arbitrary file system reads...
> just a read only heap exploit, and it's worse than anything you could
> have previously fucking imagined?
>

9,10,11... whatever it is, it is bad.

Heartbleed leaks e-mails, user-credentials and lot's of other
interesting information.

Really, it wasn't pretty, what I have seen passing by the last few days.

--
Marco


Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/