Penetration Testing mailing list archives

Re: verify HTTPS 'vulnerabilities'


From: Thomas Springer <tuevsec () gmx net>
Date: Tue, 26 Jul 2005 17:27:31 +0200

Dan Rogers wrote:
List,

Simple question:

I have a report from Nessus telling me that a web server is offering
'export class' cyphers for it's SSL/TLS service. Nessus also managed
to obtain an internal IP address from the host (which is correct).
Only HTTPS is open.

i put an https-check based on openssl online at http://serversniff.net that tells you about certs and allowed ciphers on your https-server.

tom


Current thread: