3 ms·
Excuse the formatting above, it seems to have eaten my whitespace. Just for further reference i recommend reading about OpenSSLs freelists implementation. Esse
by AReallyGoodName 13y ago
Excuse the formatting above, it seems to have eaten my whitespace.
Just for further reference i recommend reading about OpenSSLs freelists implementation. Essentially if you have an object that uses a specific amount of space it will be stored in a specific location. Which is why private key extraction is possible. You just need to craft a request that puts your_actual_payload in a location so that the 65536 bytes that are read from it into a buffer also end up reading the key.
http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse http://www.tedunangst.com/flak/post/analysis-of-openssl-free...