@markloman @asemota cc @ach0w see mentioned tweet. How does a hacker set that up in the middle? How do they intercept traffic to Yahoo?
-
-
-
-
@markloman@asemota@ach0w what do you mean server query? I mean can can any program just query traffic to a server they don't have access? -
- 1 more reply
New conversation -
-
-
@markloman where has this come from please? -
@PCClinicMids from the Yahoo login server, just by accessing port 443 using a special script that abuses the#heartbleed vulnerability.
End of conversation
New conversation -
-
-
@markloman it looks like Yahoo has been patched in the last 10-15 minutes, based on the tool at filippo.io. Can you confirm? -
@air_hadoken yes, Yahoo seems to have installed the OpenSSL update on its servers.
End of conversation
New conversation -
-
-
@markloman@yo_bj Do not login ever? Or right now? -
@SarahJPurcell@yo_bj only right now. Yahoo is still figuring out how to install the OpenSSL update, revoke and reissue certificates.
End of conversation
New conversation -
-
-
@markloman@k3170Makan I can't understand why the password is plaintext. Shouldn't we use password hash? -
@conmancm@k3170Makan this is from memory. Yahoo’s server isn’t working with hashed passwords, allowing mem-scraping (like breach at Target) - 1 more reply
New conversation -
-
-
@markloman@Galrahn Yahoo’s still a thing? -
@E__Strobel@Galrahn Yes, Yahoo is still vulnerable. Stay away. - 1 more reply
New conversation -
-
-
@markloman Is it OK for http://ABCNews.com to use this pic? Will credit. Want to give context of what Heartbleed looks like in action. -
@AlyssaNewcomb Sure no problem. Send me a link to the article when you published it :) -
@markloman Will do. Thanks!
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.