2 ms·
Is there a way to tell if a third-party site has patched the bug? (Upgraded to 1.0.1g) Not much point in changing your password on that site before the vulnerab
by jeffDef 13y ago
Is there a way to tell if a third-party site has patched the bug? (Upgraded to 1.0.1g) Not much point in changing your password on that site before the vulnerability is fixed.
- _fn 13y agoSomeone wrote this: http://filippo.io/Heartbleed/ http://filippo.io/Heartbleed/
- elliottcarlson 13y agoecho -e "quit\n" | openssl s_client -connect <HOSTNAME>:443 -tlsextdebug 2>&1| [ "` grep -c 'TLS server extension \"heartbeat\" (id=15), len=1'`" -gt 0 ] && echo 'Vulnerable'
- jsmthrowaway 13y agoThat can false-positive, for what it's worth, in servers with fixed TLS heartbeats (instead of removing them).