Heartbleed vulnerability used against Hackers

In a rather interesting twist the BBC reveals that Internet security companies and anti-malware researchers have been targeting cyber criminals using the recently publicised Heartbleed exploit.

myce-opensll-heartbleed

Heartbleed is a bug in the OpenSSL protocol which allows attackers to force servers to reveal chunks of recent data which may contain passwords, account details, or other normally secure information.

Security researchers interviewed by the BBC revealed how they were able to gain access to several, now infamous, and extremely secure private forums frequented by hackers and cyber criminals including 'Darkode' and 'Damagelab'.

According to the researchers these normally extremely difficult to penetrate sites were left wide open by custom software using Heartbleed based attacks which revealed all the information required to infiltrate the forums.

The BBC reports further on this story here.

No posts to display