CrazyEngineers
  • Heartbleed And C Programming Language

    Kaustubh Katdare

    Kaustubh Katdare

    @thebigk
    Updated: Oct 22, 2024
    Views: 1.2K
    I've been hearing that at the core of the Heartbleed security flaw, lies the limitation of the C programming language. Though I couldn't make much sense out of it; I learn that it's because of the C programming language's ability to directly manipulate the heap; that lets it dump the memory to the hacker.

    I'd like those familiar with C programming language in depth to discuss the issue (if it's indeed the case). At the heart of it; the bug is about defining the key you want from the memory and defining the length greater than the actual length of the key; which leads the system to send you whatever it has in its memory. This often leads to exposing sensitive information to the hacker.

    I don't know who discovered this bug; but it's an interesting one to fix. I look forward to a discussion on the topic.
    0
    Replies
Howdy guest!
Dear guest, you must be logged-in to participate on CrazyEngineers. We would love to have you as a member of our community. Consider creating an account or login.
Replies
  • Abhishek Rawal

    MemberApr 12, 2014

    Heartbleed bug in OpenSSL was not limitation of 'C Programming language' but probably intended one to execute the program faster as malloc() & free() of libc6 is slow & thus only solution remaining was allocating pointer to combined cluster of memory. Well, that's what I understood from #-Link-Snipped-#. Or, maybe it could be sloppy coding. People do make mistake.

    Interesting bug to get fixed ? maybe! But before this bug reaches to entire world its fixes were already deployed in Servers of big companies like Google, Amazon, Facebook, Paypal, etc. Once patched, it was publicly announced.

    ---------------------------------------------------------------------------------------------
    I remember how everyone in Google+ were discussing on Heartbleed bug of openSSL. Bit off-topic, but this makes Google+ best social networking website where you do learn some new shit everyday, unlike FB where these kids troll eachother.
    Are you sure? This action cannot be undone.
    Cancel
Home Channels Search Login Register