jspenguin
Highest Rated Comments
jspenguin3 karma
When the bug was first announced, I tried to use your tester, but it was not working; apparently, there was too much traffic. That prompted me to write my own tester in Python, which I posted on Reddit, and it got spread out over the globe, and apparently someone even incorporated it into Metasploit.
I haven't looked at your code, but I have a basic question about it: Does your tester perform a full key exchange before sending the heartbeat request? My script just sends a pre-fabricated ClientHello, then an unencrypted heartbeat request, and I wasn't able to get it to return more than 16k at a time.
jspenguin821 karma
"He says that it is good luck to rub the head of a dwarf."
"Tell him that it is even better luck to suck on a dwarf’s cock."
View HistoryShare Link