Testing for "reverse" Heartbleed
blog.meldium.com
blog.meldium.com
----------------------------------------
[0] http://news.netcraft.com/archives/2014/04/08/half-a-million-...
http://blog.sucuri.net/2014/03/more-than-162000-wordpress-si...
They are pretty good at staying on top of WP related vulnerabilities.
e: "sloppily maintained", if you will
Software which is easy to set up initially, but hard to upgrade, tends to be much more likely to be out of date than software which is easier to upgrade.
Things that consist of "a big blob of PHP plus a lot of extensions" tend to fall into this camp. PHP apps are generally very easy to get set up the first time, and popular ones like Wordpress have lots of extensions you can add on; but then once you've been running that for a while, you discover that if you upgrade, these n extensions all break, and rather than bothering to find replacements, you just don't bother upgrading.
How do you fix this? Make upgrading easy, don't rely on extensions, or make sure you have bulletproof, stable APIs so that no one worries "if I upgrade, all these things are going to break."
If the client code (at whatever site you are targeting) is vulnerable then each heartbeat response you get from the client site may give you up to 64KB of its memory contents.
As if this couldn't get worse...