killchain-compendium/Exploits/SSL+TLS/Heartbleed.md

200 B

Heartbleed

  • SSL V1.0.1 and V1.0.1f

  • Client sends msg, msglength

  • If msg is 0 and the msglength is longer, return from server is arbitrary memory content

  • Heartbleed