Couverture de Heartbleed: The Check That Never Ran

Heartbleed: The Check That Never Ran

Heartbleed: The Check That Never Ran

Écouter gratuitement

Voir les détails

Late on New Year's Eve 2011, a maintainer merged a code change into OpenSSL, the cryptographic library behind Apache and nginx. One validation check was missing from it. For two years, that gap let anyone pull raw memory from a live server: passwords, session data, and possibly the private key that proves a server's identity, all without leaving a trace. Disclosed in April 2014 as Heartbleed, the bug forced a global scramble to patch, revoke certificates, and reset passwords — and turned on a question a public challenge later settled: could the private key actually be extracted? From Zero Day Logs.

adbl_web_anon_alc_button_suppression_t1
Aucun commentaire pour le moment