If your webserver has the vulnerable version of the OpenSSL library, then your server will return some extra bytes, from someplace in memory.
It may turn out that the space in memory it's returning from is useless. Or, like yahoo, you may be giving out plain-text ASCII passwords to complete strangers who can type a command line. Which of these two extremes you get is largely based on luck.