I also tried the code you linked here: https://news.ycombinator.com/item?id=7577659
This also failed, and it actually said my server was likely not vulnerable?
I compiled my own Nginx, (but not my own SSL, that came from Debian 7.0 Wheezy)
Linux ... 3.9.3-x86_64-linode33 #1 SMP Mon May 20 10:22:57 EDT 2013 x86_64 GNU/Linux
OpenSSL 1.0.1e 11 Feb 2013
I just upgraded the Debian libssl1.0.0 package, and now your code says I am safe. I see there is the len(all_data) > 24 check.
Should compiling my own Nginx have any effect on whether the exploit works? I would think not, but 2 different exploits failed (although maybe I didn't run it long enough).
FWIW it was Nginx 1.0.12.
EDIT: FWIW, now that I read Cloudflare's results, they think the Nginx server is only vulnerable shortly after being restarted. My server was running for months, which may have explained why it wasn't vulnerable. Oh well.
http://blog.cloudflare.com/the-results-of-the-cloudflare-cha...