Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: Testing for Heartbleed - SANS Internet Storm Center SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Testing for Heartbleed

There are a fair few sites popping up testing for this issue.  I know this is possibly overly motherly, sorry, but be careful.  You may not know who is running the site, what they are actually testing for and what is done with the information collected.  Consider sticking to the main sites and known security organisations.  

Metasploit now has a module out ( NMAP likewise has a check.  QUALYS has their SSLLABS page.  Other security vendors are also providing checks in their scanning products.  

Not saying the free scanners are "evil", just saying be careful what you use.  


Mark H


392 Posts
ISC Handler
Apr 9th 2014
When I use the SSL Labs site for, I can't get a good read on that site. I don't have problems with some other financial sites I have run through the SSL Labs tester.
C# stand-alone tool for testing via PacketStormSecurity (Have not tested):

"Authored by John Leitch
Bleed Out is a command line tool written in C# for targeting instances of OpenSSL made vulnerable by the prolific "Heartbleed" bug. The tool aggressively exploits the OpenSSL vulnerability, dumping both ASCII and binary data to files. It also checks the uniqueness of each chunk before persisting it, to ensure that duplicate chunks are not saved"

1 Posts
NMAP hasn't released the version with the script to check for this yet.

There are instructions here for getting it up and running with version 6.40
2 Posts
Please note that all online tests must be taken "cum grano salis".
At least one of them, in our checking, shows false positives.

9 Posts
We have discovered that the NMAP script "ssl-heartbleed" may not be reliable. A scan of a Polycom HDX 7000 device did not reveal vulnerability. However, testing with another tool did. Upon checking firmware versions against Polycom's documented vulnerability list, we confirmed vulnerability.

10 Posts
NMAP can be used for this too:
2 Posts

Sign Up for Free or Log In to start participating in the conversation!