Steal a connectionAs described above, the redirect the client to a malicious server requires that clients must be instructed to access the server specified. However, many client programs will only connect to a domain name be pre-installed or be set available. In these cases, the client will still be exploited.In the shared network open as public Wi-Fi networks, network traffic can be viewed and adjusted by the stranger, this allows the attacker to redirect the client programs contain vulnerabilities.Usually, the security technology SSL/TLS (HTTPS, encrypted web browser instance) is one of the solutions to this problem, because the encrypted block device sneaks and redirect. However, an attacker can send multiple malicious Heartbleed message before the SSL/TLS session is established.An attacker can participate in a public network and view sneak information of potential victims. When a potential victim using a client programs that contain the flaw to establish an SSL/TLS connection to a server, the attacker will redirect the connection to a malicious server.Before SSL/TLS connection is established and capable of preventing all the redirects, the attacker would have to send many messages to toxic Heartbleed to extract the content located in the computer memory of the victims.
đang được dịch, vui lòng đợi..