How to analyze the recurrence of heart bleeding vulnerability CVE-2014-0160 in Heartbleed
This article is about how to analyze the Heartbleed heart bleeding loophole CVE-2014-0160 recurrence, the editor feels very practical, so share with you to learn, I hope you can get something after reading this article, say no more, follow the editor to have a look.
Heartbleed heart bleed vulnerability (CVE-2014-0160)
Objective: to detect whether the target system has a CVE-2014-0160 vulnerability and use this vulnerability to obtain the cookie value of a web page.
Target system (vulhub target machine):
1. Start the environment and enter the path to cd / home/vulhub/vulhub-master/openssl/heartbleed
two。 Build and run vulnerability environment docker-compose build
Docker-compose up-d
3. After the environment starts, visit https://192.168.1.131 to view the test page
Kali penetration:
Kali opens the msfconsole loading module to get sensitive data (Cookie)
The red pen mark is the obtained cookie:
The comparison is correct:
The above is how to analyze the recurrence of Heartbleed's heart bleeding loophole CVE-2014-0160. The editor believes that there are some knowledge points that we may see or use in our daily work. I hope you can learn more from this article. For more details, please follow the industry information channel.