weakish

CVE-2014-0160 (heartbleed) 漏洞该如何修复?(只升级软件足够么?

  •  
  •   weakish · Apr 9, 2014 · 4019 views
    This topic created in 4454 days ago, the information mentioned may be changed or developed.
    看到这里的修复指南还建议重新生成密钥、清cookies、让用户重新生成密码

    http://segmentfault.com/a/1190000000461002

    理论上确实有一定风险,既然可以读到内存,机器上可能在内存中出现过的数据就都有潜在的风险。

    问题是这个机率大么?有必要这么大费周章么?

    像某宝说修复了,它就既没清cookie,也没提示换密码的说。
    No Comments Yet
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   2598 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 53ms · UTC 05:02 · PVG 13:02 · LAX 22:02 · JFK 01:02
    ♥ Do have faith in what you're doing.