Re: [Haifux] The Heartbeat vulnerability in OpenSSL (and hence ssh/https)

2014-04-11 Thread Tzafrir Cohen
On Fri, Apr 11, 2014 at 08:35:00AM +0300, Eli Billauer wrote: Hi all, I suppose that the security freaks already know about this, and still, this seems important enough for an alert. In a nutshell, a bug in the mechanism that allows keepalive messages to be sent to maintain an SSL link,

Re: [Haifux] The Heartbeat vulnerability in OpenSSL

2014-04-11 Thread Eli Billauer
Thanks for that one, Tzafrir. In fact, I did try a Python script on my SSH server, and it just failed to run through the test (connection reset by peer). It makes sense now. :) And now when you said it, it's quite easy to confirm that all over the web.