I've built a web tester for this bug, find it at
It actually exploit the bug, since it was quite trivial, and echo some memory.
It's written in Go, no more than 100 lines. I'll release code in some time.
It actually exploit the bug, since it was quite trivial, and echo some memory.
It's written in Go, no more than 100 lines. I'll release code in some time.
Another, known unpatched, app is reported to be affected by both tools.
Is it possible that FiloSottile/Hearbleed may report false positives?
How vulnerable a specific site is depends on luck. Yahoo must have broken a whole bunch of mirrors because total amateurs can send mail.yahoo.com a certain blob of code and it has a good chance of returning a stranger's password.
lsof | grep ssl | grep DEL