a thoughtful web.
Good ideas and conversation. No ads, no tracking.   Login or Take a Tour!
comment
aesthetikx  ·  3987 days ago  ·  link  ·    ·  parent  ·  post: How does the heartbleed attack work?

It is my understanding that this type of exploit would typically cause a server to crash (modern operating systems won't allow random memory access in this way), however in this case OpenSSL uses a custom memory allocation method for performance reasons. Still, surprising that the overflow isn't checked for, it's one of the most common sources of vulnerability.