Hacker News new | ask | show | jobs
by mdhardeman 3086 days ago
Even if you could find them all and make automatic determinations as to whether or not they facilitate the vulnerability. (You really can't automate that as you need to be a customer of the host to really attempt to pull off the exploit.)

Even if... You would only know for the set of web hosts for the time period you checked each one.

New ones come and old ones die every day.

1 comments

You don't need to keep a master list of IP addresses up to date, you only have to test an IP when a request for a cert comes in from that IP.