Full Disclosure mailing list archives
Heartbleed client side analysis tool published
From: Curesec Research Team <crt () curesec com>
Date: Mon, 05 May 2014 10:06:21 +0200
Hi List! We are happy to announce hbad (heartbleed analysis daemon). If a request is sent to the hbad server by any client (e.g. IRC, Fetchmail, browser), the server initiates the SSL handshake and checks the SSL header for the Heartbeat addon. If it is available, it indicates the client uses OpenSSL. Thereupon the hbad server sends a Heartbeat request back to the client. If the client runs a vulnerable OpenSSL version, it sends back the Heartbeat response, which contains the sensitive data. Find the blogentry here: https://blog.curesec.com/article/blog/32.html Download documentation and client tests: https://www.curesec.com/data/hbad_en.pdf (English Documentation) https://www.curesec.com/data/hbad_dt.pdf (German Documentation) You can download hbad here: https://www.curesec.com/data/hbad-release.tar.gz Cheers, Curesec Research Team _______________________________________________ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- Heartbleed client side analysis tool published Curesec Research Team (May 05)