• Home
  • About

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
By using Twitter’s services you agree to our Cookie Use and Data Transfer outside the EU. We and our partners operate globally and use cookies, including for analytics, personalisation, and ads.
1njected's profile
Tomas Rzepka
Tomas Rzepka
Tomas Rzepka
@1njected

Tomas Rzepka

@1njected

The Grid. A digital frontier. I tried to picture clusters of information as they moved through the computer. And then, one day...I got in.

Joined September 2011
  • © 2016 Twitter
  • About
  • Help
  • Terms
  • Privacy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @

Retweet this to your followers?

Optional comment for Retweet
 
 

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @
140

Are you sure you want to delete this Tweet?

Promote this Tweet

Block

  • Add a location to your Tweets

    When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more

    Profile summary

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Your reply includes the people in this conversation up to this point. Learn more

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    Preview

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Buy Now

    Hmm... Something went wrong. Please try again.

    Previous Tweet Next Tweet
    1. Neel Mehta ‏@neelmehta 8 Apr 2014

      Heap allocation patterns make private key exposure unlikely for #heartbleed #dontpanic.

      268 retweets 80 likes
      Tomas Rzepka ‏@1njected 8 Apr 2014

      @neelmehta @tqbf We can extract the private key successfully on FreeBSD after restarting apache and making the first request with ssltest.py

      • Retweets 83
      • Likes 35
      • pixelmy Liam Laverty Stefan Andrew Wooster ☠ ʇɟosuɐɯoɹ Barry K. Nathan Masafumi Negishi Jean-Marc Desperrier ᏇNOBLETROUT⛵
      11:27 PM - 8 Apr 2014
      83 retweets 35 likes
        1. Tomas Rzepka ‏@1njected 9 Apr 2014

          @neelmehta @tqbf @_miw FreeBSD 9.1 #heartbleedpic.twitter.com/AktnQD3E7w

          72 retweets 30 likes
        2. View other replies
        3. stokedsecurity ‏@stokedsecurity 9 Apr 2014

          @1njected @spierenburg @neelmehta @tqbf @_miw probably only worked with first request to server, right?

          0 retweets 0 likes
        4. Tomas Rzepka ‏@1njected 9 Apr 2014

          @stokedsecurity @spierenburg @neelmehta @tqbf @_miw Seem to depend on server load/mem usage

          0 retweets 0 likes
        1. Philip ‏@_miw 8 Apr 2014

          @1njected Ieeeeek. Ok, do you have proof because this is significant discovery with major financial ramifications. similar results on Linux?

          0 retweets 0 likes
        2. Tomas Rzepka ‏@1njected 8 Apr 2014

          @_miw Does not work on Debian. We patched the FreeBSD machine but I will see if we can gather some evidence. :)

          0 retweets 0 likes
        3. Philip ‏@_miw 9 Apr 2014

          @1njected Ive been smashing TLS daemons on my Debian lab machine but haven't seen anything interesting. What is it about the FreeBSD alloc??

          0 retweets 0 likes
        4. Tomas Rzepka ‏@1njected 9 Apr 2014

          @_miw Maybe that freebsd uses mmap to implement malloc? http://www.tuicool.com/articles/vqmAZf 

          0 retweets 4 likes
        5. Philip ‏@_miw 9 Apr 2014

          @1njected that's easily the best writeup on it I've seen. Thanks.

          0 retweets 1 like
        6. Root Labs ‏@rootlabs 9 Apr 2014

          @_miw @1njected FYI, that's a rip-off of the original author's analysis. "http://tuicool.com " plagiarized http://blog.existentialize.com/diagnosis-of-the-openssl-heartbleed-bug.html …

          0 retweets 2 likes
        7. View other replies
        8. Tomas Rzepka ‏@1njected 9 Apr 2014

          @rootlabs @_miw sry, yes that is correct. Didn’t have the link so I googled and that site was the first to appear. They link to it the orig.

          0 retweets 0 likes
        1. Mako ‏@makomk 9 Apr 2014

          @thegrugq @1njected Cool! I've recovered it from Apache on Gentoo as a bare prime factor in binary, but your demo's a lot clearer.

          5 retweets 3 likes
        2. Tomas Rzepka ‏@1njected 9 Apr 2014

          @makomk @thegrugq Cool, do need to restart apache or just send enough requests?

          0 retweets 0 likes
        3. View other replies
        4. Mako ‏@makomk 11 Apr 2014

          @1njected @thegrugq With hints from https://news.ycombinator.com/item?id=7573377  got reliable extraction from Apache defaults on Debian:pic.twitter.com/uWKQnMkaNB

          19 retweets 16 likes
        1. Ryan Barnett ‏@ryancbarnett 9 Apr 2014

          @1njected @neelmehta @tqbf attackers just need to send payloads at midnight when most sites run daily log rollover/restart scripts.

          0 retweets 0 likes
        2. Tomas Rzepka ‏@1njected 9 Apr 2014

          @ryancbarnett @neelmehta @tqbf Yes, or if your lucky, find a DOS-vuln and wait for admin to restart.

          0 retweets 0 likes
        3. Henrik Kramshoej ‏@kramse 9 Apr 2014

          @1njected @ryancbarnett @neelmehta @tqbf what about Apache maxrequestsperchild - be enough to have something load/free the key somewhere?

          0 retweets 0 likes

      Loading seems to be taking a while.

      Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

        Promoted Tweet

        false

        • © 2016 Twitter
        • About
        • Help
        • Terms
        • Privacy
        • Cookies
        • Ads info