Is a "Reverse Heartbleed" exploit possible to read the client's memory?

https://news.ycombinator.com/item?id=7555865
by gcr • 12 years ago
7 3 12 years ago

So here's a question about the recently-discovered heartbleed OpenSSL bug.

Let's say I connect to a server with Firefox/Chrome. Could the server read the client's memory and extract cookies/history/sessions for other sites the client visited?

I'm not sure if firefox or chrome link against OpenSSL, but that could also be pretty tricky.

Related Stories

Loading related stories...

Source preview

news.ycombinator.com