5 ms·
ErrataSec, at least (their IPs are implicated in the logs) says this is a false-positive generated by the minimalist SSL implementation in masscan: http://blog
by semenko 13y ago
ErrataSec, at least (their IPs are implicated in the logs) says this is a false-positive generated by the minimalist SSL implementation in masscan:
http://blog.erratasec.com/2014/04/no-we-werent-scanning-for-hearbleed.html http://blog.erratasec.com/2014/04/no-we-werent-scanning-for-...
- 0x0 13y agoCounterpoint: if the tool is 6 months old, why did these logs only show scans happening in the few weeks leading up to this bug's disclosure? At this point I'd just assume the worst, and change all the passwords, keys and sessions.
- mikeash 13y agoI thought that was just when their logs began. Presumably older ones were deleted.
- tptacek 13y agoIf masscan does generate these false positives, and masscan has been available for 6 months, and masscan is widely used across the global internet, then a log going back to January SHOULD have masscan false positives in them before March. It seems like: * Either Robert Graham is wrong that masscan can create these log entries (unlikely) * masscan isn't used widely enough to ambiently generate errors since its release (maybe) * This operator managed somehow to truncate or alter their log configuration (maybe) * Some other heretofore unknown TLS scanning tool generates a different false positive (maybe) * Some heretofore unknown entity knew about Heartbleed and scanned the Internet for it (maybe) The evil unknown heartbleeder isn't the most likely scenario in this list.
- deleted 13y ago[deleted]
- shimon_e 13y ago"Although this is painful for the security community, we can rest assured that infrastructure of the cyber criminals and their secrets have been exposed as well." http://heartbleed.com/ http://heartbleed.com/ Sounds like they may have scanned the whole internet themselves. Google reissued their cert on 12 Mar. I assume that is when they discovered it?
- btgeekboy 13y agoI don't know how often they've reissued their certificate in the past, but the certificate's good for almost exactly 90 days. (89.6, to be exact.) Perhaps it was simply time to make another?
- snori74 13y agoYes, that's probably the case. Note that apparently MediaMonks also have logs which might show earlier exploitation too: https://www.eff.org/deeplinks/2014/04/wild-heart-were-intelligence-agencies-using-heartbleed-november-2013 https://www.eff.org/deeplinks/2014/04/wild-heart-were-intell...