Open cardosec

Case 0759F3 · Famous breaches · L2 Practitioner

Heartbleed

Practise as: Explain it · Interview

Interview questionExplain Heartbleed at the protocol level.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. CVE-2014-0160 in OpenSSL 1.0.1 to 1.0.1f, in the TLS heartbeat extension (RFC 6520); fixed in 1.0.1g, April 2014
  2. Heartbeat request declares a payload length; OpenSSL trusted it without checking the real payload size
  3. Server echoed back up to 64 KB of adjacent memory per request, with no logs left behind
  4. Leaked memory could include private keys, session cookies and passwords
  5. Remediation meant patch, then revoke and reissue certificates and reset credentials; spurred OpenSSL funding

If the interviewer pushes back

  • Why did patching alone not end the exposure, and how does forward secrecy change the impact?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.