Yeah there’s lot of buzz on heartbleed as the worst bug ever. My opinion? It is a serious bug due to the fallacy of the way C works . Despite the hype memory leakage is not exactly something new and skillful botnet/attackers/pentesters have exploited it for years.
What can we learn from this bug?.. At the Beginning and at the End of an Encrypted Connection lies the encrypted data. Don`t the trust user input in one thing, but trusting your server memory and hands behind it is also well sucks.
If you are one of the CISO fans well PCI often said “End-to-End Encryption” .. which means data + communication channel are supposed to be well encrypted.. Which is good
But there’s one catch…
Suppose an attacker/sysadmin managed to get hold on a server with a privileged access (or decided to abused it anyway). Hypothetically something like this.
References
- ^ XKCD (xkcd.com)
- ^ Folks from Rohitab (www.rohitab.com)
Sumber: http://y0nd13.blogspot.com
0 Response to "Epilogue Pentest: Forget about Heartbleed and Enter the Reality of Volatile Memory"
Post a Comment