Demonstrates the "heartbleed" problem using full OpenSSL stack, and how simple pattern-matching isn't sufficient to detect this attack. It evades the pattern matching in IDS (Snort and EmergingThreat rules), it doesn't send the pattern in packets that everyone is looking for, and it doesn't generate logfile error messages.
more here.......https://github.com/robertdavidgraham/heartleech
more here.......https://github.com/robertdavidgraham/heartleech