LFI to RCE via access_log injection

#OpenSSL CVE-2014-0224 Detection Script


OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of Change Cipher Spec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability. This script tests for that vulnerability.

DOWNLOAD LINK

MD5 | 84c2620d5ab5b01965eb58186c07113e




source

Comments