Hacker News new | ask | show | jobs
by lox 4454 days ago
Great idea, I just setup an RSS-to-slack trigger for future notifications: http://zpr.io/HSkn
2 comments

Should anyone else find it useful, here's what I'm now using: http://zpr.io/HS5f

It detects new AWS security bulletin items and notifies you via Google Hangout.

Great!

./heartbleeder zapier.com

VULNERABLE - zapier.com:443 has the heartbeat extension enabled and is vulnerable to CVE-2014-0160

AWS's ELB (which we use) were vulnerable, we'll be replacing certificates ASAP. We (and most the rest of the internet using ELB) seem to be in the clear now:

    ./heartbleeder zapier.com
    SECURE - zapier.com:443 has the heartbeat extension enabled, but timed out after a malformed heartbeat (this likely means that it is not vulnerable)
When did you run your check? Do you have a recent binary of heartbleeder?