Re: [FD] Yahoo! hacked on October 5, 2014...

2014-10-07 Thread Pål Nilsen
I guess this is related?: https://news.ycombinator.com/item?id=8416393 On 7 Oct 2014 20:51, "Jonathan Hall" wrote: > I submitted to Yahoo! earlier some documentation detailing both the > "shellshock"/bash vulnerability and how my research on it lead me to > discovering that Yahoo!'s internal serv

Re: [FD] heartbleed OpenSSL bug CVE-2014-0160

2014-04-10 Thread Pål Nilsen
This is pretty nice: https://lastpass.com/heartbleed/ They seem to even have historic data for some sites' certificates. On 10 April 2014 11:02, Reindl Harald wrote: > > > Am 10.04.2014 00:32, schrieb Craig Holmes: > > On April 8, 2014 10:21:34 AM Matthew Musingo wrote: > >> Even if your system

Re: [FD] heartbleed OpenSSL bug CVE-2014-0160

2014-04-10 Thread Pål Nilsen
There's probably an "official" place to get ssltest.py, but I put it here after some guys on IRC asked for it yesterday: https://ccdn.tracetracker.com/ssltest.py On 10 April 2014 08:39, Txalin wrote: > > How realistic is it that an attacker would be able to glean passwords > through > > this vu