3 ms·
It is worse than plain HTTP, actually. Heartblead allows an attacker anywhere on the internet to read out memory from your server. This is worse than plain HTTP
by subleq 13y ago
It is worse than plain HTTP, actually. Heartblead allows an attacker anywhere on the internet to read out memory from your server. This is worse than plain HTTP in two ways:
- With plain HTTP, the attacker would have to be in a MITM position to intercept traffic. With Heartblead, he can read traffic he wouldn't normally have access to from the server's memory.
- There may be secrets in memory that would never even be sent over the network that are now accessible. For example, if running a web app in the same process doing SSL termination, private keys such as Django's SECRET_KEY may be available. Under certain situations, knowledge of the SECRET_KEY can effect remote code execution.
In short, Heartbleed gives the entire world the ability to read memory from your server. This is much worse than an HTTP MITM.