I have read about recent vulnerability in openssl. I tried to exploit one of my cloud servers where I run my web sites. I managed to get 64 KB of data. But what I managed to get was only HTML, CSS, PHP codes. But here states:
We have tested some of our own services from attacker's perspective. We attacked ourselves from outside, without leaving a trace. Without using any privileged information or credentials we were able steal from ourselves the secret keys used for our X.509 certificates, user names and passwords, instant messages, emails and business critical documents and communication.
I have some questions:
1.What was the server configuration of testers?
2.What other sensitive data can be retrieved with this vulnerability?
3.What sensitive data is stored in RAM of Apache Web Server?