@daveaitel Do you know the best reference offhand where you compare heartbleed (useless) vs shellshock (useful)?
-
-
Replying to @dguido
@dguido@daveaitel Whoa… who claimed heartbleed was useless?1 reply 0 retweets 2 likes -
Replying to @flyryan1 reply 0 retweets 0 likes
-
Replying to @daveaitel
@daveaitel@flyryan Thanks, I couldn't remember which of your many keynotes that was! I agree, it's hard to find many breaches traced to HB.4 replies 0 retweets 0 likes -
This Tweet is unavailable.
-
This Tweet is unavailable.
-
Replying to @hybr1z
@suqdiq@daveaitel@dguido@flyryan pulling valid creds or sessions is not useless, not sure why Dave said the vuln was1 reply 0 retweets 0 likes -
Replying to @jstnkndy
@jstnkndy@suqdiq@daveaitel@flyryan It requires attention to detail and does not easily scale as an attack vector. Shellshock does.3 replies 0 retweets 1 like -
Replying to @dguido
@jstnkndy@suqdiq@daveaitel@flyryan Shellshock is much easier to dev into a repeatable process that works across targets w/ known results2 replies 0 retweets 1 like
@jstnkndy @suqdiq @daveaitel @flyryan Heartbleed tends to be different for every target, may lead to creds, but then what do you do? thinky
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.