Case 0759F3 · Famous breaches · L2 Practitioner
Heartbleed
Practise as: Explain it · Interview
Interview questionExplain Heartbleed at the protocol level.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- CVE-2014-0160 in OpenSSL 1.0.1 to 1.0.1f, in the TLS heartbeat extension (RFC 6520); fixed in 1.0.1g, April 2014
- Heartbeat request declares a payload length; OpenSSL trusted it without checking the real payload size
- Server echoed back up to 64 KB of adjacent memory per request, with no logs left behind
- Leaked memory could include private keys, session cookies and passwords
- Remediation meant patch, then revoke and reissue certificates and reset credentials; spurred OpenSSL funding
If the interviewer pushes back
- Why did patching alone not end the exposure, and how does forward secrecy change the impact?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.