Is a "Reverse Heartbleed" exploit possible to read the client's memory?
https://news.ycombinator.com/item?id=7555865So here's a question about the recently-discovered heartbleed OpenSSL bug.
Let's say I connect to a server with Firefox/Chrome. Could the server read the client's memory and extract cookies/history/sessions for other sites the client visited?
I'm not sure if firefox or chrome link against OpenSSL, but that could also be pretty tricky.