Tech●●●●●Difficulty 4 of 5

How did one bug put much of the internet at risk, from Heartbleed to Log4Shell?

Heartbleed let strangers read a server's memory by asking for a 500-letter word when only four letters were sent.

▶ Start the story

Both Heartbleed and Log4Shell show how a single small bug in a widely shared piece of code can reach much of the internet at once.

Heartbleed, disclosed in April 2014, was a flaw in OpenSSL, a widely used library that secures web connections. A feature called heartbeat lets one computer send a short message and a number for its length, and the other must echo back exactly that message. The code trusted the number without checking it against the real message. So an attacker could send a four-letter word while claiming it was five hundred letters long, and the server would reply with the word plus whatever else sat in its memory, up to 64 kibibytes at a time. The leak could include passwords, session cookies and even a server's private keys. At disclosure some 17 percent of the internet's secure web servers, around half a million, were believed vulnerable. The flawed code came from a PhD student's contribution that a core developer reviewed without noticing the bug.

A heartbeat: honest versus malicious

Honest request

  • Send back the four-letter word "bird"
  • Reply: "bird"

Heartbleed request

  • Send back the 500-letter word "bird"
  • Reply: "bird" plus 496 characters of memory

In late 2021, Log4Shell hit Log4j, an open-source Java logging tool used ubiquitously in applications. Log4j records data inside applications, which can include what users type, and an attacker who got the right string logged could make the program load and run malicious code from a public address. And because web requests are often logged, almost any web server using it could be reached. It scored 10 out of 10 for severity and could affect hundreds of millions of devices.

Both bugs sat in widely shared code that many other programs relied on.

Quiz me

0/3

  1. 1.What was the core mistake in Heartbleed?
  2. 2.Why did patching OpenSSL not fully fix the problem for a site?
  3. 3.Why could Log4Shell be reached on so many web servers?

Recap

Heartbleed trusted a length it was told without checking it; Log4Shell acted on text it was only meant to record.

💡 A trick to remember it · Heartbleed: the server believed "this word is 500 letters long" and echoed its own secrets.

Surprising fact · Heartbleed was a bug in a feature that echoes a message: the server believed the length the sender claimed.

Sources (2)

No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.

  1. [1]Heartbleed · Wikipedia
  2. [2]Log4Shell · Wikipedia
More lessons in 💻 Tech (3) See all tech lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗