FiloSottile / Heartbleed

A checker (site and tool) for CVE-2014-0160
http://filippo.io/Heartbleed
MIT License
2.31k stars 461 forks source link

Data protection #10

Open csikiati opened 10 years ago

csikiati commented 10 years ago

Hi, when checking mail.yahoo.com I have noticed that a password and sometimes even a username is returned, which is pretty serious. Under a minute of clicking 2 pairs of credentials were dispayed. Do you genereate these other bits, or dispay them as they are?

rendy67 commented 10 years ago

Why are you checking mail.yahoo.com? it's for internal purpose

csikiati commented 10 years ago

Because I have an account there and therefore it's internal to me personally. Very internal. After checking our company, this was a logical step. Basically you have a tool here that can be misused.