Cupid - new type of attack with Heartbleed vector

June 3, 2014

A new type of attack called Cupid works on Heartbleed method of attack. The Cupid is exploitable on TLS connections over EAP (Extensible Authentication Protocol) which is popular framework used in wireless and peer-to-peer connections. If the attack is succesful hackers can gain the access to the contents of the memory exactly like in the Heartbleed scenario, and steal the private key of the certificate used on the TLS connection, and authentication credentials.