Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
heartbleed-vulnerability-exploitation — hands on investigation of the heartbleed vulnerability (CVE-2014-0160). | Kitploit
उपकरण/GitHubGitHub/l1lf1ng3r/heartbleed-vulnerability-exploitation
ReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationNetwork SecurityCryptographyPenetration TestingLearning & EducationIncident Response

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
Labs & Practice
GitHubl1lf1ng3r/heartbleed-vulnerability-exploitation

heartbleed-vulnerability-exploitation

hands on investigation of the heartbleed vulnerability (CVE-2014-0160).

रिपॉजिटरी देखें
1520 दिन पहलेअभी तक समीक्षित नहीं
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

heartbleed-vulnerability-exploitation

Description

hands on investigation of the Heartbleed vulnerability (CVE-2014-0160).

Summary

this lab documents a hands-on investigation of the Heartbleed vulnerability, a critical flaw in OpenSSL's implementation of the TLS heartbeat extension. the goal was to understand how the vulnerability works at the protocol level and exploit it in a controlled environment to observe its impact, practicing skills directly relevant to SOC analysis (vulnerability assessment and impact analysis).

Objective

  • understand the root cause of Heartbleed (improper bounds checking in OpenSSL's heartbeat extension).
  • identify a vulnerable OpenSSL service using reconnaissance and scanning tools.
  • exploit the vulnerability in a controlled lab environment to observe data exposure.
  • document remediation strategies from a SOC/analyst perspective.

Environment & Tools

  • Target: vulnerable web server (nginx 1.15.7 on port 443) running an outdated OpenSSL version, isolated lab VM.
  • Attacker/Analyst Machine: linux-based analysis environment.
  • Tools Used:

 nmap - service enumeration and vulnerability discovery.

 Metasploit - auxiliary/scanner/ssl/openssl_heartbleed module for exploitation.

Methodology

1. Reconnaissance
  • ran a full TCP port scan with service/version detection (nmap -sS -vv -p- -A )
  • identified open ports: 22 (SSH), 111 (rpcbind), 443 (SSL/HTTP).
  • fingerprinted port 443 as running ngix 1.15.7 over SSL/TLS (candidate for outdated OpenSSL)

Hash Identification
Hash Identification

2. Vulnerability Identification

  • ran (nmap -sV --script vuln ) to check all discovered services against known vulnerability scripts.
  • confirmed the target as VULNERABLE to Heartbleed via the ssl-heartbleed NSE script, flagged as high risk.

Hash Identification
Hash Identification

3. Exploitation

  • launched metasploit framework (msfconsole) and located the relevant module with (search heartbleed).
  • selected auxiliary/scanner/ssl/openssl_heartbleed and reviewed module options.
  • configured RHOSTS, RPORT 443, and verbose true, then ran the module.
  • the module sent a malformed TLS heartbeat request and captured the server's oversized response, leaking adjacent process memory.

Hash Identification
Hash Identification
Hash Identification
Hash Identification
Hash Identification

Findings

  • the target (nginx 1.15.7, port 443) was confirmed vulnerable to CVE-2014-0160 via both nmap's ssl-heartbleed script and Metasploit's openssl_heartbleed scanner.
  • exploitation successfully leaked heap memory from the server, returning printable strings alongside binary data.
  • the leaked memory contained fragments of a prior HTTP request body, including "user_name, user_email, and user_message" parameters demonstrating that Heartbleed can expose application layer data that happened to reside in adjacent memory.
  • no authentication was required to exploit the vulnerability, making it exploitable by any network-adjacent attacker.

Hash Identification

Remediation

  • upgrade OpenSSL to a patched version.
  • revoke and reissue any SSL certificates/private keys potentially exposed prior to patching.
  • force password resets for accounts with sessions active during the vulnerable window.
  • disable the heartbeat extension entirely if patching is not immediately possible.

Skills Demonstrated

  • full-scope port scanning and service enumeration (nmap).
  • vulnerability scanning with NSE scripts (vuln, ssl-heartbleed)
  • exploit module configuration and execution in Metasploit framework.
  • root cause analysis of a memory-safety vulnerability.
  • security reporting and remediation planning.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2014-0160
  • https://heartbleed.com/
  • https://www.openssl.org/news/secadv/20140407.txt
टूल डाउनलोड करें