Remote-exploiting curl

1 · Daniel Stenberg · Feb. 3, 2020, 9:15 a.m.
In a Blackhat 2019 presentation, three gentlemen from the Tencent Blade Team explained how they found and managed to exploit two curl flaws. Both related to NTLM over HTTP. The “client version Heartbleed” as they call it. Reported responsibly The Tencent team already reported the bugs responsibly to us and we already fixed them back … Continue reading Remote-exploiting curl →...