Skip to content

Instantly share code, notes, and snippets.

@taylor
Last active August 29, 2015 13:58
Show Gist options
  • Select an option

  • Save taylor/10418893 to your computer and use it in GitHub Desktop.

Select an option

Save taylor/10418893 to your computer and use it in GitHub Desktop.
Heartbleed bug quick info

Heartbleed bug tools and references

Quick reference and testing tools for the Heartbleed bug

Top 100 Alexa vulnerability tests results

Test services with:

Test your browser:

More SSL tests with https://www.ssllabs.com/ssltest/


What to do

Linux

  • See the advisories for your distro

OS X

  • Should not be affected for Apple's since they switched in 2012
  • Brew openssl should be upgraded. 1 liner from @gregkare's tweet
    • brew update && brew upgrade openssl && brew uses openssl --installed | xargs brew reinstall

Windows

  • See advisories. Check 3rd party software

Critical Apps:

  • Web, email (IMAP, POP, SMTP) services
  • Databases
  • VPN software such as openvpn

I recommend enabling perfect forward secrecy on all services SSL/TLS services.


Reading material

Advisories:

Articles:

Discussions:

Info on possible exploits:

Misc:


Other semi-related info

On March 3, 2014 a GnuTLS x.509 bug was found:

25 years of vulnerabilities form 1988 to 2012

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment