Close Menu
Technotification
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Technotification
    • Home
    • News
    • How To
    • Explained
    • Facts
    • Lists
    • Programming
    • Security
    • Gaming
    Technotification
    Home › Open Source › Hackers claim to have found a new Flaw in OpenSSL similar to Heartbleed!

    Hackers claim to have found a new Flaw in OpenSSL similar to Heartbleed!

    By Vikram Singh RaoJuly 25, 2018
    Facebook Twitter Reddit LinkedIn
    openSSL

    An Anonymous group claims to have explored a new vulnerability in the latest version of OpenSSL, which was updated after the Heartbleed flaw. The Flaw affected almost all of the popular websites we use daily.
    According to group members-the bug is similar to Heartbleed, but some of the experts are questioning their claims.

    In a post at pastebin, Hackers wrote:

    We have just found an vulnerability in the patched version OpenSSL. A missing bounds check in the handling of the variable DOPENSSL_NO_HEARTBEATS. We could successfully Overflow the DOPENSSL_NO_HEARTBEATS and retrieve 64kb chunks of data again on the updated version,

    the hackers wrote on Pastebin.
    Hackers also claim that they can personally use this vulnerability for a long time before it gets patched, and on the other hand they are selling out that exploit for 2.5 Bitcoins ($1,069 / €780) or 100 Litecoins ($973 / €725).

    Group is unknown, as we said above, but they have an email address which is [email protected].

    We are team of five people, and we have coded non-stop for 14 days to see if we could find a workaround, and we did it! We have no reason to make it public when the vendors will go for a update again, they wrote.

    What is the proof, that their vulnerability is working:

    So, here comes twist-is there any video which proves that really their exploit is working, NO-They don’t have anything like that, but they have a screenshot which is of a response from a server. However, this is not enough to prove that the flaw is really working and experts questioning on their claims.

    “They say: ‘A missing bounds check in the handling of the variable DOPENSSL_NO_HEARTBEATS’. That’s not a variable, the ‘D’ is not actually part of the name, and it’s a compile-time macro that configures whether heartbeats will be compiled in or not,” one of the security expert and programmer Jann Horn noted on the Full Disclosure mailing list.
    “And because it’s a compile-time thing, it’s nothing that an attacker could ever influence,” Horn added.

    Some really believe what are you thinking now-IT IS A MONEY-MAKING SCAM. Yes, it could be, as their contact email [email protected] was used in the past by a group that offered to sell user information and source code from Mt. Gox and CryptoAve.
    We will update this news, if this exploit really works or any update comes from Hackers’ end or experts’ end.

    Share. Facebook Twitter LinkedIn Tumblr Reddit Telegram WhatsApp
    Vikram Singh Rao
    • Website
    • Facebook
    • X (Twitter)
    • LinkedIn

    I am an entrepreneur at heart who has made his hobby turned a passion, his profession now.

    Related Posts

    The Psychology of a Phishing Email: How Scammers Play with Your Mind

    July 16, 2024

    9 Essential Elements of a Strong Cyber Security Management System

    July 3, 2024

    Common Cyber Attacks and How to Prevent Them

    July 3, 2024

    How Cyber Security Paid Training Prepares You for Real-World Threats

    June 13, 2024

    The Role of Security in Server Colocation Environments

    March 12, 2024

    Navigating the Waters: Best Practices for Phishing Testing in 2024

    February 19, 2024
    Lists You May Like

    10 Best RARBG Alternative Sites in April 2025 [Working Links]

    April 1, 2025

    The Pirate Bay Proxy List in 2025 [Updated List]

    January 2, 2025

    10 Sites to Watch Free Korean Drama [2025 Edition]

    January 2, 2025

    10 Best Torrent Search Engine Sites (2025 Edition)

    February 12, 2025

    10 Best GTA V Roleplay Servers in 2025 (Updated List)

    January 6, 2025

    5 Best Torrent Sites for Software in 2025

    January 2, 2025

    1337x Alternatives, Proxies, and Mirror Sites in 2025

    January 2, 2025

    10 Best Torrent Sites for eBooks in 2025 [Working]

    January 2, 2025

    10 Best Anime Torrent Sites in 2025 [Working Sites]

    January 6, 2025

    Top Free Photo Editing Software For PC in 2025

    January 2, 2025
    Pages
    • About
    • Contact
    • Privacy
    • Careers
    Privacy

    Information such as the type of browser being used, its operating system, and your IP address is gathered in order to enhance your online experience.

    © 2013 - 2025 Technotification | All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.