3 ms·
OK fair, 64K. But is it actually possible to control were you get the 64K from or is it just off the top of the stack? And is it actually possible that the top
by danielpal 13y ago
OK fair, 64K. But is it actually possible to control were you get the 64K from or is it just off the top of the stack?
And is it actually possible that the top of the stack has your private key?
- M4v3R 13y agoIt has been repedately demonstrated that it is possible to get private key from the server using this vulnerability, as well as user login details. You don't have only one shot - you can query the server multiple times (and every time you will receive slightly different data) until you have everything you want. So yeah, the issue was/is very serious.
- erichurkman 13y agoSee this post for a trivial example of session theft from JIRA [1]. You may not get the memory chunk you want the first time, but you can repeat it until you do. [1] https://www.mattslifebytes.com/?p=533 https://www.mattslifebytes.com/?p=533
- makomk 13y agoIt's from somewhere on the heap not the stack. You can influence where on the heap the data comes from by adjusting the size of your request, amongst other tricks.