diff --git a/CHANGELOG.md b/CHANGELOG.md index 0f5447b..02f5301 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,7 @@ * QUIC protocol check * bump SSLlabs rating guide to 2009r +* Check for Opossum vulnerability ### Features implemented / improvements in 3.2 diff --git a/doc/testssl.1 b/doc/testssl.1 index d0fbdd9..3d23674 100644 --- a/doc/testssl.1 +++ b/doc/testssl.1 @@ -659,6 +659,9 @@ variable \f[CR]CCS_MAX_WAITSOCK\f[R]. \f[CR]\-T, \-\-ticketbleed\f[R] Checks for Ticketbleed memory leakage in BigIP loadbalancers. .PP +\f[CR]\-\-OP, \-\-opossum\f[R] Checks for HTTP to HTTPS upgrade +vulnerability named Opossum. +.PP \f[CR]\-\-BB, \-\-robot\f[R] Checks for vulnerability to ROBOT / (\f[I]Return Of Bleichenbacher\[cq]s Oracle Threat\f[R]) attack. .PP @@ -1312,6 +1315,8 @@ RFC 2246: The TLS Protocol Version 1.0 .IP \[bu] 2 RFC 2595: Using TLS with IMAP, POP3 and ACAP .IP \[bu] 2 +RFC 2817: Upgrading to TLS Within HTTP/1.1 +.IP \[bu] 2 RFC 2818: HTTP Over TLS .IP \[bu] 2 RFC 2830: Lightweight Directory Access Protocol (v3): Extension for diff --git a/doc/testssl.1.html b/doc/testssl.1.html index 42e17c2..589a305 100644 --- a/doc/testssl.1.html +++ b/doc/testssl.1.html @@ -590,6 +590,8 @@ CCS_MAX_WAITSOCK.

-T, --ticketbleed Checks for Ticketbleed memory leakage in BigIP loadbalancers.

+

--OP, --opossum Checks for HTTP to HTTPS upgrade + vulnerability named Opossum.

--BB, --robot Checks for vulnerability to ROBOT / (Return Of Bleichenbacher’s Oracle Threat) attack.

@@ -1131,6 +1133,7 @@