killchain-compendium/exploit/ssl_tls/heartbleed.md

200 B

Heartbleed

  • SSL V1.0.1 and V1.0.1f

  • Client sends msg, msglength

  • If msg is 0 and the msglength is longer, return from server is arbitrary memory content

  • Heartbleed