马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。
您需要 登录 才可以下载或查看,没有帐号?立即注册
x
欢迎大家来到仓酷云论坛!这两天OpenSSLHeartBleed毛病弄得胆战心惊,请看这篇文章:剖析、诊断OpenSSLHeartbleedBug,今朝可知的可以使用此毛病的版本是:
OpenSSL1.0.1through1.0.1f(inclusive)arevulnerable
OpenSSL1.0.1gisNOTvulnerable
OpenSSL1.0.0branchisNOTvulnerable
OpenSSL0.9.8branchisNOTvulnerable
到本人办理的办事器上实行一下下令:
[root@server~]#opensslversion
OpenSSL1.0.1e-fips11Feb2013
很分明,我的办事器上存在毛病,因而,到网高低载了一个剧本:Python剧本检测OpenSSLHeartBleed(心脏流血)毛病,测试一下:
liang@liang:~/golang$pythonssltest.py
Enterahost:www.***x.com
Testingwww.***x.com...vulnerable.
代表此网站存在毛病可被使用。
幸亏,Centos已供应晋级包,办理此成绩:
<divstyle="padding-bottom:0px;border-right-width:0px;text-transform:none;background-color:rgb(255,255,255);list-style-type:none;text-indent:0px;margin:0px;padding-left:0px;padding-right:0px;font:14px/28px宋体;white-space:normal;border-top-width:0px;border-bottom-width:0px;letter-spacing:normal;color:rgb(51,51,51);border-left-width:0px;list-style-image:none;word-spacing:0px;padding-top:0px;-webkit-text-stroke-width:0px"><divclass="container"style="box-sizing:content-box!important;border-bottom:0px;position:relative!important;text-align:left!important;border-left:0px;padding-bottom:0px!important;line-height:1.1em!important;list-style-type:none;font-style:normal!important;margin:0px;outline-style:none!important;outline-color:invert!important;min-height:inherit!important;padding-left:0px!important;outline-width:0px!important;width:auto!important;bottom:auto!important;padding-right:0px!important;font-family:Consolas,BitstreamVeraSansMono,CourierNew,Courier,monospace!important;background:nonetransparentscrollrepeat0%0%;float:none!important;height:auto!important;font-size:1em!important;vertical-align:baseline!important;overflow:visible!important;border-top:0px;top:auto!important;right:auto!important;font-weight:normal!important;list-style-image:none;border-right:0px;padding-top:0px!important;left:auto!important;border-top-left-radius:0px;border-bottom-left-radius:0px;border-bottom-right-radius:0px;border-top-right-radius:0px">[root@server~]#yum-yinstallopenssl
[root@server~]#opensslversion-a
OpenSSL1.0.1e-fips11Feb2013
builton:TueApr802:39:29UTC2014
platform:linux-x86_64
<divclass="linenumber6index5alt1"style="box-sizing:content-box!important;border-bottom:0px;position:static!important;text-align:left!important;border-left:0px;padding-bottom:0px!important;line-height:1.1em!important;list-style-type:none;font-style:normal!important;margin:0px;outline-style:none!important;outline-color:invert!important;min-height:inherit!important;padding-left:1em!important;outline-width:0px!important;width:auto!important;bottom:auto!important;padding-right:1em!important;font-family:Consolas,BitstreamVeraSansMono,CourierNew,Courier,monospace!important;white-space:pre!important;background:white;float:none!important;height:auto!important;font-size:1em!important;vertical-align:baseline!important;overflow:visible!important;border-top:0px;top:auto!important;right:auto!important;font-weight:normal!important;list-style-image:none;border-right:0px;padding-top:0px!important;left:auto!important;border-top-left-radius:0px;border-bottom-left-radius:0px;border-bottom-right-radius:0px;border-top-right-radius:0px">options:bn(64,64)md2(int)rc4(16x,int)des(idx,cisc,16,int |