
Detects the Heartbleed vulnerability (CVE-2014-0160) in OpenSSL on HTTP and HTTPS services via version checking, with guidance for using nmap, masscan, and bleed.py for broader scanning.
Targets the OpenSSL product directly on discovered HTTP and HTTPS services. This does not check for OpenSSL 1.0.2-beta which is vulnerable. Also, OpenSSL is commonly packaged into other software and better targeted on any service responding using SSL.
nmap -A -T4 --xml targets
Loop through target hosts with NMAP 6.3+ nmap -sV -p targethostPorts --xml --script=ssl-heartbleed.nse targethostmasscan targethosts -p0-65535 --rate 100000 --heartbleedpython3.exe bleed.py targethost -p targetport