On 4/16/2014 12:01 PM, Fredrik Strömberg wrote:
> We have successfully extracted private key material multiple times
> from an OpenVPN server by exploiting the Heartbleed Bug. The material
> we found was sufficient for us to recreate the private key and
> impersonate the server.


Hi,
        Can you post some stats about how many requests it took on average to 
get the key ? e.g. how many bytes sent at the server, how many bytes 
back and how many total packets would be helpful.

        ---Mike

-- 
-------------------
Mike Tancsa, tel +1 519 651 3400
Sentex Communications, m...@sentex.net
Providing Internet services since 1994 www.sentex.net
Cambridge, Ontario Canada   http://www.tancsa.com/

------------------------------------------------------------------------------
Learn Graph Databases - Download FREE O'Reilly Book
"Graph Databases" is the definitive new guide to graph databases and their
applications. Written by three acclaimed leaders in the field,
this first edition is now available. Download your free book today!
http://p.sf.net/sfu/NeoTech
_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to