Test your server for the Heartbleed bug
filippo.io
filippo.io
EDIT: Got it working by changing "github.com/titanous/heartbleeder/tls" to "./tls" and running "go run heartbleeder.go example.com"
Am I missing something?
On the bright side, since such servers are Heroku's inbound load-balancers, individual app dyno secrets in RAM probably aren't at risk. But, impersonating herokuapp.com, decoding its sessions, or viewing fragments of arbitrary other traffic through the same server may all be possible.
Heroku reports they're aware and working on it: http://status.heroku.com
I'm also getting this error:
Error: not well-formed
Source File: http://heartbleed.filippo.io/bleed/foo.com
Line: 1, Column: 1
Source Code:
{"code": 1, "data": ""}Other than that, great work @ars!
Loading bar implemented!
Also caching the results should also lighten the load on your server significantly since many people are probably checking common websites.
(as suggested someone in another thread here). That will answer Yes to a patched OpenSSL.
The OP's site actually attempts a (mild?) exploit of this.
Any chance you would open source this?
I mentioned in another thread today that perhaps having the source code for script-kiddies to start attacking everything might not be the best thing to do at this time. I think it's great to just have a website like this to test the vulnerability. It would also be nice if someone like Google could host the page so it won't get knocked down by too many requests as I'm sure will be happening for the next few days.
(Sidenote: Bitcoin exchanges, please for the love of all that is good... don't start getting owned by this. UPDATE NOW)
https://gist.github.com/hlein/10121981
What, praytell, is a script kiddie going to do with that, other than oogle at the word "vulnerable"?
What else should I do?
grep -l 'libssl.*deleted' /proc/*/maps
And restart all processes listed.And then restart everything that comes back from a
sudo lsof -n | grep ssl | grep DEL