Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Enhanced heartbleed: consistently get 64k of heap (pastebay.net)
8 points by sp332 on April 11, 2014 | hide | past | favorite | 1 comment


According to @puellavulnerata: examining my own tests closer, if you use a payload length above 16k, it sends back an ill-formed response exceeding the maximum TLS record length. A lot of the proofs-of-concept can't parse it properly - the payload length in the heartbeat response doesn't match the TLS record length. That's what this code fixes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: