Commit Graph
100 Commits
Author SHA1 Message Date
Dirk 1ea7a0947f - RC4 has now 2 CVEs and cipher per default are displayed short
- introducng a variable name LONG which for certain funcs shows broad output with hexc, cipher, KX, etc.
- FIX: regression not showing security headers
- introducing VULN_THRESHLD
2015-04-22 18:24:39 +02:00
Dirk 3891f5b13b - FIX #83
- emphasize also OS names in HTTP headers
2015-04-22 15:22:53 +02:00
Dirk 06bd8b2517 - FIX for complete bailing out 2015-04-22 11:56:13 +02:00
Dirk bafce6edce - reordering code so that all attacks are together
- RC4 is now really omitted in PFS test
- cleanup of some comments
2015-04-22 10:33:44 +02:00
Dirk c751e9f459 typo 2015-04-21 08:14:36 +02:00
Dirk 5bec0a16c9 - better compatibility with windows 2003 server
- all long options are advertised now as with dashes and not underscore
- cosmetic stuff
2015-04-20 10:05:01 +02:00
Dirk 7b6dba6369 FIX for #82 2015-04-18 23:03:16 +02:00
Dirk Wetter 3f0f489f50 Indicated freeze 2015-04-16 21:05:23 +02:00
Dirk 5625ee536e - BUGFIX: IIS server lead to false pisitive if SSLv3 was enabled
(timeout was faster then socket resply)
- FIX: CORS header not labeled as green
- NEW: Now also STARTTLS works with all cmd line options and is absolutely doing the same stuff!
  (integrated starttls() into parse_hn_port() )
- option --mx needed to be changed because of starttls
- regression fix: exec for socket doesn't play nice with stderr redirect
  (probably bash bug)
- added some env options to cmd line as long args (--assuming-http,--ssl_native,
  --color, debug, --sneaky, --warnings)
- threw away getent as it doesn't work under Linux && not network && localhost
  (replaced by grep)
- SSL-POODLE is not labeled anymore experimental
- HB+CCS are called while checking STARTTLS but given a hint that its not yet supported
- added more env vars to debug output
- cleanups
2015-04-16 20:36:17 +02:00
Dirk f682c5ceea - FIX regression: more_flags execution was missing
- FIX regression: capitalized/all lowercase headers weren't detected
- if socksend is blocked (IDS) output looks better and is reported as test didn't succeed
- no secure cookie or Httponly will be marked as brown
- tput color yellow is now brown
2015-04-14 13:16:43 +02:00
Dirk 9d5168dbb5 - more robust grep >=2.20, e.g Debian 8.0 (thx @stevenb18)
- FIX: false positive for breach while testing google.com (referer header was hardcoded to google.com)
2015-04-14 10:15:07 +02:00
Dirk 683e9dccab - FIX (regression): -V
- logic of some ENV variables changed (attention!)
- included some ENV as long options (not in the help yet)
- decentralized http check for breach
- if openssl is not executable it bails out better now
- help function now exits
2015-04-13 22:55:40 +02:00
Dirk 1043c40a60 Merge branch 'master' of github.com:drwetter/testssl.sh 2015-04-10 15:16:20 +02:00
Dirk a12d39769f - underline CN, SAN and issuer deutschepost case (see sourceforge.net/p/ssllabs/mailman/message/33764851/) 2015-04-10 15:15:47 +02:00
Dirk Wetter bfcd684e19 Update Readme.md 2015-04-10 10:13:30 +02:00
Dirk Wetter 9ebf112858 Update Readme.md 2015-04-09 22:24:57 +02:00
Dirk 53e0955dfb FIX: missing server preferences, NEW: each cipher server preferences per protocol! 2015-04-09 22:08:48 +02:00
Dirk 7f984ea83f - 2015-04-09 21:45:22 +02:00
Dirk a98161acc9 - fixes to changes from Peter's better cmd line parsing
- cosmetc improvements (vulneraibilities)
2015-04-09 21:42:52 +02:00
Dirk Wetter eb73ffc053 Merge pull request #79 from PeterMosmans/refactoring
Refactored major parts of code
2015-04-09 21:38:29 +02:00
Dirk 84aca9d9a3 FIX #80: show HTTP 401 2015-04-02 13:35:22 +02:00
Dirk 2cc56c4d1f NEW: added security headers 2015-04-02 13:04:57 +02:00
Dirk 8da96f78f2 - got rid of "strings" 2015-04-02 12:19:24 +02:00
Dirk 4bbd19ba03 - updated binaries from Peter. Necessary because handshake under rare circumstances
failed (routines:tls1_setup_key_block:cipher or hash unavailable:t1_enc.c:802.
  SLES 12 server, some ciphers under TLS 1.2
2015-04-02 11:46:12 +02:00
Dirk 940f51e74b protocol check via sockets now also for SSLv3 2015-03-31 10:34:30 +02:00
Dirk 9ed58b6202 cleanups / bsd date in tls time 2015-03-30 23:09:19 +02:00
Dirk 6c30386278 rechi 2015-03-30 15:03:29 +02:00
Dirk d9ae35fc7e open fixes from Rechi (pull request $67) 2015-03-30 14:59:44 +02:00
Dirk Wetter 7f4fc5902e Merge pull request #75 from feld/tr
Using square brackets in tr results in trying to match/replace them
2015-03-19 09:14:54 +01:00
Dirk Wetter f4c9f692d2 Merge pull request #76 from feld/printf
Fix variable directly referenced in printf
2015-03-19 09:14:32 +01:00
Dirk 0d3b7f343f Дилян 2015-03-17 22:14:05 +01:00
Dirk 2d0bfca343 - FIX for 3des cipher report (thx Дилян) 2015-03-17 22:12:25 +01:00
Dirk ca6ca5d47e - added two pairs of ciphers to server preference (thx Dilian) 2015-03-17 22:02:23 +01:00
Dirk 2faad9de9a - working tls handshake with bash sockets (not yet in production, hint: see option "-q" in the bottom) 2015-03-17 18:11:18 +01:00
Dirk c159af7f42 - check whether openssl is executable
- spaces to tabs
- adding hint to "aha" in help
2015-03-17 15:14:58 +01:00
Dirk 263535520f - FIX for date --> applied to other BSD systems too
- FIX for SNI output as it doensn';t make sense for non HTTP servives
- lines for RC4 and PFS shortenedA
- display all MX records to test before testing
- removed LOCERR, added CCS_MAX_WAITSOCK, HEARTBLEED_MAX_WAITSOCK
2015-03-17 12:22:21 +01:00
Dirk f8ba69f9fb - some internal code internal cleanups
- minor cosmetic output corrections
- preparation for bash sockets for SSLv3 to TLS 1.2
2015-03-16 00:22:51 +01:00
Dirk 4556108a72 further improvements through shellcheck 2015-03-15 16:59:29 +01:00
Dirk 68695bbad3 FIX #74 for sed BSD: doesn't like inline \n
headline for BEAST was missing
2015-03-15 16:10:14 +01:00
Dirk 655944bd4d - FIX: regression for wc -l w/o cat (3x)
- removal of unneccessary waitpid, inline
2015-03-15 14:41:34 +01:00
Dirk fbd383f345 - prework for checking hpkp fingerprints 2015-03-15 10:18:37 +01:00
Dirk 5cd4b8f73e - Shellcheck static analysis by Mark 2015-03-15 09:04:49 +01:00
Dirk Wetter bf411d8c11 Merge pull request #73 from feld/master
Shellcheck static analysis
2015-03-15 08:56:01 +01:00
Dirk b5a568da62 - @feld 2015-03-13 12:21:06 +01:00
Dirk c1ca5a641b - FIX garbled output for servers with a TLS reply on SSLv2 socket call 2015-03-13 12:20:19 +01:00
Dirk Wetter 74d984cebc Merge pull request #72 from feld/feld
Minor optimizations to reduce unnecessary forking
2015-03-13 11:00:52 +01:00
Dirk d8d8318f6d FIX for #71 (proper workaround for lastpipe in rc4, pfs, and cbc) 2015-03-09 08:07:45 +01:00
Dirk 77e28922c1 - NEW: proper check for freak CVE-2015-0204
- NEW: check for number of keys for hpkp
- cleanup hsts+hpkp
2015-03-07 09:51:55 +01:00
Dirk f23904b35f - MX record: the lower the # the higher the priority (thx, rechi) 2015-03-03 07:21:30 +01:00
Dirk 77ed44207c - see #41 2015-03-02 14:44:02 +01:00
Dirk 55e8908234 - finalize mx records, FIX: #41 2015-03-02 14:42:28 +01:00
Dirk Wetter 2614c093d7 Merge pull request #66 from Rechi/master
Check MX Records (#41)
2015-03-02 14:13:33 +01:00
Dirk 37fa44cecf - remark about rc4 rfc 2015-03-02 14:09:34 +01:00
Dirk Wetter 3f55de1483 Update Readme.md 2015-03-02 13:59:45 +01:00
Dirk 29214c7a1f - better detection for ssl poodle
- change of shorticut from zero to letter o
2015-02-27 21:21:39 +01:00
Dirk Wetter 87f821e390 Merge pull request #65 from schuetzm/fix-nrsaved
Don't let error message slip through when no certs have been downloaded
2015-02-24 18:28:09 +01:00
Dirk Wetter 868c813055 Merge pull request #64 from PeterMosmans/spellingfix
FIX: minor spelling issue
2015-02-24 10:03:32 +01:00
Dirk 8aa8254c2d - FIX #62 (CentOS 7/RHEL: engine failure), was not usable b4 2015-02-23 10:40:10 +01:00
Dirk d0d7bb47e2 - FIXED: #47 ("double" linefeed if RFC mapping file is not present) 2015-02-22 23:05:40 +01:00
Dirk e2448ea95d - NEW: tells how many certificates provides (and grabs them with DEBUG=1)
- COLOR for no cipher order is red now
- "VULNERABLE" comes now always with "NOT ok"
2015-02-21 11:47:12 +01:00
Dirk 1be281c404 - FIXED: #38, new openssl from Peter Mosmans makes the workaround unneccessary 2015-02-21 10:46:30 +01:00
Dirk a255462812 - to tell the difference between the sets of binaries 2015-02-21 10:39:27 +01:00
Dirk bacb3b69ba - FIXED: #38, new openssl from peter mosmans makes the workaround unneccessary 2015-02-21 10:38:04 +01:00
Dirk Wetter cacb200049 Update Readme.md 2015-02-15 14:10:11 +01:00
Dirk b261c1079a - Fix #55 (302 detection for URL) 2015-02-15 14:00:13 +01:00
Dirk f203b8b299 - Fix #46 (preload lists HPKP and HSTS)
- word match for includeSubDomains (useful if one specified the keyword wrong)
2015-02-15 13:37:44 +01:00
Dirk b0a40ae1e8 - FIX #60: mod_security CRS doesn't complain anymore 2015-02-15 13:14:11 +01:00
Dirk ab48c66f74 - certificate sha2 fingerprint added (#59, @@kyhwana)
- sha1 fp: removed colons as long serials after it look ugly (lf)
2015-02-15 12:58:51 +01:00
Dirk e5a015b842 - workaround for issue #58, same in http_header
- FIX: if a web site returned IMAP e.g. in HTML code it may have led to the assumption IMAP is the service ;-/
2015-02-13 16:01:46 +01:00
Dirk d15d5b0c6f - FIX regression: CRIME check
- FIX: port ended up sometimes as URL part
- also if it runs http a line is displayed as confirmation that HTTP was detected
2015-02-12 13:40:53 +01:00
Dirk db99cc8c0c - new build with proper banner string 2015-02-12 11:12:49 +01:00
Dirk Wetter 7d6adee53f Update Readme.md 2015-02-12 10:50:52 +01:00
Dirk Wetter bc1cf841e3 Update Readme.md 2015-02-12 09:45:26 +01:00
Dirk d9e4873fda - WORKAROUND for bug in PeterMosmans OPENSSL chacha/poly version: not testing EXPORT40/EXPORT then 2015-02-12 09:32:47 +01:00
Dirk d98aa626e7 - NEW: check for Secure Client-Initiated Renegotiation
- debugging #1: PS4 and debugme
- debugging statement tmpfile_handle where missing #2
2015-02-11 09:43:04 +01:00
Dirk Wetter c80fc50728 Update Readme.md 2015-02-10 13:18:02 +01:00
Dirk d4c3266486 - sha2 like mozilla 2015-02-10 12:43:08 +01:00
Dirk 32ca73f982 Merge branch 'master' of github.com:drwetter/testssl.sh 2015-02-10 12:40:14 +01:00
Dirk Wetter d5c4aca6f0 Update Readme.md 2015-02-10 12:39:54 +01:00
Dirk Wetter 30b7390654 Update Readme.md 2015-02-10 12:39:20 +01:00
Dirk Wetter bbb832ae59 Update Readme.md 2015-02-10 12:39:02 +01:00
Dirk 1e75ac8be3 - vanilla as a workaround for bug #38 2015-02-10 12:37:03 +01:00
Dirk Wetter 80c21abcac Update Readme.md 2015-02-10 12:34:35 +01:00
Dirk Wetter f47b589fe9 Update Readme.md 2015-02-10 12:20:59 +01:00
Dirk Wetter 76ad830d1a Update Readme.md 2015-02-10 12:00:02 +01:00
Dirk Wetter 2272a34557 Update Readme.md 2015-02-10 11:59:47 +01:00
Dirk ed04b636da - starttls for ldap now also supported 2015-02-09 14:02:02 +01:00
Dirk Wetter 0b23307683 Merge pull request #57 from schuetzm/patch-1
Trivial typo fix
2015-02-09 13:52:11 +01:00
Dirk Wetter 857880218d Update Readme.md
Bug #38
2015-02-05 10:06:27 +01:00
Dirk Wetter 2b35b66551 Delete openssl32-1.0.2pm.chacha+poly 2015-02-05 10:02:54 +01:00
Dirk 82410b7214 - updated to 1.0.2 stable from pm
- still bug #38: https://github.com/drwetter/testssl.sh/issues/38
2015-02-05 09:58:33 +01:00
Dirk bbec58bb02 Merge branch 'master' of github.com:drwetter/testssl.sh
Conflicts:
	openssl-bins/openssl-1.0.2-chacha.pm/openssl32-1.0.2pm-krb5.chacha+poly.asc
	openssl-bins/openssl-1.0.2-chacha.pm/openssl64-1.0.2pm-krb5.chacha+poly.asc
2015-02-05 09:54:24 +01:00
Dirk 6b1d5a732b - updated to 1.0.2 stable from pm
- still bug #38: https://github.com/drwetter/testssl.sh/issues/38
2015-02-05 09:48:42 +01:00
Dirk Wetter c4a5caadbc Delete openssl64-1.0.2pm.chacha+poly.asc 2015-02-05 09:48:28 +01:00
Dirk Wetter 7340103bd8 Delete openssl64-1.0.2pm.chacha+poly 2015-02-05 09:48:17 +01:00
Dirk Wetter aeeb63c694 Delete openssl64-1.0.2pm-krb5.chacha+poly.asc 2015-02-05 09:48:05 +01:00
Dirk Wetter ef466364c3 Delete openssl32-1.0.2pm.chacha+poly.asc 2015-02-05 09:47:55 +01:00
Dirk Wetter b7864fc05e Delete openssl32-1.0.2pm.chacha+poly 2015-02-05 09:47:43 +01:00
Dirk Wetter 3d9bbfee02 Delete openssl32-1.0.2pm-krb5.chacha+poly.asc 2015-02-05 09:47:28 +01:00
Dirk 731e5fefb4 - updated to 1.0.2 stable from pm
- still bug #38: https://github.com/drwetter/testssl.sh/issues/38
2015-02-05 09:41:56 +01:00