Werner posted this:
https://aws.amazon.com/security/security-bulletins/heartblee...
Wonder where this is even linked from?
https://aws.amazon.com/security/security-bulletins/heartblee...
Wonder where this is even linked from?
Just used Zapier to set up a RSS-to-email trigger to get notified about things like this in the future, although Amazon really should be sending them out automatically to customers.
It detects new AWS security bulletin items and notifies you via Google Hangout.
./heartbleeder zapier.com
VULNERABLE - zapier.com:443 has the heartbeat extension enabled and is vulnerable to CVE-2014-0160
./heartbleeder zapier.com
SECURE - zapier.com:443 has the heartbeat extension enabled, but timed out after a malformed heartbeat (this likely means that it is not vulnerable)
When did you run your check? Do you have a recent binary of heartbleeder?