[afnog] Time to update openssl
Randy Bush
randy at psg.com
Thu Apr 10 10:36:40 UTC 2014
> The command below will give false positives if the site supports
> hearbeats.
>>> openssl s_client -connect google\.com:443 -tlsextdebug 2>&1| grep 'server extension "heartbeat" (id=15)' || echo safe
no. you are misunderstanding what the command is intended to do. it
tells you if the heartbleed code is there. it does not tell you whether
or not the hole in it is present.
randy
More information about the afnog
mailing list