3 ms·
Do you have the same feelings about the Rapid7 team? What about the guys at Tenable? Heck, the Offensive Security guys are making an entire Linux distro that
by davis_m 13y ago
Do you have the same feelings about the Rapid7 team? What about the guys at Tenable? Heck, the Offensive Security guys are making an entire Linux distro that is nothing more than "evil hacker tools". Surely there are countless crimes committed with their software. Do you believe that all of them are in the wrong.
I am not an exceptionally gifted programmer. This is a trivial change to the original PoC to point out an additional attack vector. Pointing out that there is more to this attack than leaked private keys is very important.
- dhimes 13y agoYou did the right thing. I know very little about exploitation- I have to pay someone else to learn about things like this and fix it for me. This makes the time taken to do that much shorter for me and others like me. So thank you thank you thank you! Do you have a "donate" button somewhere?
- cheald 13y agoThe line between whitehat pentester and blackhat cracker is very thin, of course. They use the same tools and the same techniques; the differentiating component is intent and target. The title of your post is "Using Heartbleed PoC for Hijacking User Sessions En Masse". Not "Your users' sessions are at risk", or "Heartbleed affects more than private keys". The express intent of the published code is the theft of user sessions. I know that you probably don't have any intent to do Bad Things with it, but if I was a prosecutor looking for someone to slap around with the CFAA, you just threw up a giant neon "SUP BITCHES" sign. The folks you mentioned all produce tools which are intended and marketed for use by white-hat security professionals in the pre-emptive exploitation of their own networks for the purposes of security. Yes, we all know that the Bad Guys use Metasploit extensively to find and exploit machines, but if Rapid7 were positioning their tool as the premiere solution for pwnz3ring b0x3n, you don't think they'd be in a legally different situation? I never said you were wrong. In fact, my exact words were "I wouldn't convict you" - I really do get why you published this, and I don't think you're some bad guy cackling to yourself from deep within your evil lair or anything. However, we know from recent history that things less gray have (unjustly, IMO) in fact landed people in prison. It's not illegal to own a crowbar or lockpicking set, but it's illegal to own one with the intent to commit burglary. Intent matters, and they way you positioned your PoC is problematic in that its stated intent is "mass hijacking", rather than "demonstration of an additional security problem". I am not trying to say that there's anything wrong with the code you've published - there isn't - but that the way you've presented it is potentially problematic if it were to attract the wrong kind of attention. That's all.