4 ms·
Found a Python PoC: http://s3.jspenguin.org/ssltest.py http://s3.jspenguin.org/ssltest.py Edit: and just used it to dump 64K from a known-vulnerable device we
by Gygash 12y ago
Found a Python PoC: http://s3.jspenguin.org/ssltest.py http://s3.jspenguin.org/ssltest.py
Edit: and just used it to dump 64K from a known-vulnerable device we control. Got a session cookie. Jeez.
- cdelsolar 12y agoJESUS CHRIST, all sorts of private information. Patch your servers now!
- vinhboy 12y agoAfter reading your comment, I started looking back at the packets I got using the script on a site I knew was not patched. Damn.. there are plaintext passwords in there for paypal. This shit is scary.
- cdelsolar 12y agoThere is going to be massive amounts of fraud all over the world for a while because of this bug.
- MasterScrat 12y agoWorks pretty well on openssl.org...
- thenickdude 12y agoLooks like that file was pulled. Here's a mirror on Pastebin: http://pastebin.com/YsdUXL1F http://pastebin.com/YsdUXL1F