+38 38 0
Published 10 years ago by idlethreat with 3 Comments
Additional Contributions:

Join the Discussion

  • Auto Tier
  • All
  • 1
  • 2
  • 3
Post Comment
  • idlethreat
    +4

    This is a viciously serious SSL bug that will ruin your day. Here's what it looks like:

    (normal login experience)

    * Normal User: "I want to login. Here's my encrypted login information"

    * Server: (unwraps the encrypted login information)

    * Server: "OK. Normal User. you can log in"

    * Normal User: "yay. I logged in"

    (heartbleed bug experience)

    * Normal User: "I want to login. Here's my encrypted login information"

    * Server: (unwraps the encrypted login information)

    * Attacker: "Hi"

    * Server: (quietly sends Normal User's login information to Attacker)

    * Server: "OK. Normal User. you can log in"

    * Normal User: "yay. I logged in"

    This is a super critical bug. I was able to snag a user's login information on a public website and could easily log in as him. It's that dangerous. More information here:

    http://heartbleed.com

    http://www.reddit.co.../the_heartbleed_bug/

    • drunkenninja (edited 10 years ago)
      +3

      Ohh shit, that's serious! Checking this out right now...

      • Gozzin
        +4

        Same here and passing it on.

Here are some other snaps you may like...