3 ms·
It seems some servers had some combination of nginx+openssl that caused the memory location being dumped to always be a recent HTTP request/response. Keep hitti
by jbinto 13y ago
It seems some servers had some combination of nginx+openssl that caused the memory location being dumped to always be a recent HTTP request/response. Keep hitting that enough times and you'll get all sorts of goodies (session cookies, cleartext passwords).
This tweet shows someone getting credentials from Yahoo Mail:
https://twitter.com/markloman/status/453502888447586304 https://twitter.com/markloman/status/453502888447586304
I think any service who suspects they've been vulnerable should issue a forced password reset email to their users. Even if there's only an infinitesimal chance of credential disclosure, how can you be sure, and why not take precautions?