Commit Graph

2844 Commits

Author SHA1 Message Date
867d698a16 - days left until expiration 2015-12-08 17:51:46 +01:00
1f39ab8241 - fix timestamp in log file 2015-12-08 16:37:35 +01:00
041b77c5ed - sanity check whether URL/URI is last arg
- typo fix while logging (fall back CVS tags weren't written
2015-12-08 13:31:52 +01:00
2e0e7b83d5 reverse non-typo
drill comes later
2015-11-28 17:33:10 +01:00
ad8f82f190 Merge pull request #240 from k0ste/master
Add drill support (ldns lib), fix mistype
2015-11-28 17:14:18 +01:00
7fee2fe29b Show SHA384 certificates as secure 2015-11-26 13:53:35 -06:00
30d046a6a5 fix PWD mistype 2015-11-23 20:02:06 +06:00
43cb1d8763 add drill support 2015-11-23 19:54:41 +06:00
f76d07d43e - logging now the cmd line, FIX #238
- internal improvements of stdout banner
2015-11-21 13:39:37 +01:00
c5a4eafed7 Fix filename typo
CREDITS.md was called CREDIT.md
2015-11-14 17:19:13 -06:00
7e08d3d4da fixed typo in parameter descriptions 2015-11-12 23:47:43 +01:00
5749051839 - fix vertical distances after PFS && wide
- fix misleading "--ip=v4only" in help
2015-11-11 17:49:36 +01:00
756a6ab41d - NEW: logging of stdout!
- rearragments in global var declaration for better readability
2015-11-11 11:56:32 +01:00
87592aafd9 - line space for some single vuln. adjusted 2015-11-08 22:14:28 +01:00
e122d65f52 Only use local rDNS with .local domain 2015-11-06 19:16:21 -06:00
457fcacf3f Fix error 2015-11-05 19:39:26 -06:00
d9dfe438e5 Prefer 'avahi-resolve' over 'dig' for mDNS 2015-11-05 19:04:04 -06:00
a9a4326038 Support rDNS with mDNS and Bonjour mDNS (mac) 2015-11-05 15:54:29 -06:00
50c5f0b93d add '-bugs' so that buggy F5s can be better tested 2015-11-03 23:29:53 +01:00
e390345629 typo 2015-11-03 19:51:45 +01:00
c272878c73 - warning session tickets -> PFS 2015-11-03 19:51:05 +01:00
8ff39c5028 - client based authentication, FIX #215
- SSL Session ID support test
2015-11-03 13:13:10 +01:00
0463471c40 - fixing side effect from #225
- other minor output corrections
2015-11-03 10:30:59 +01:00
84e6be3547 - revert part of #225
- clarify name of bool var for type of tput
2015-11-02 10:49:40 +01:00
8b54609c3d Merge pull request #225 from Harinus/master
Fix: tput: No value for $TERM and no -T specified
2015-11-02 10:40:59 +01:00
8c173764bd Use 'awk' instead of 'sed -E' 2015-11-01 10:40:44 -06:00
686dd511a6 Add support for .local domains with avahi 2015-10-31 20:01:52 -05:00
6a8d4870ab Missing space ;)
Whoops... edited this from the github webpage..
2015-10-30 09:56:48 +01:00
9bfeac19bc Fix: tput: No value for $TERM and no -T specified
Avoid "tput: No value for $TERM and no -T specified" when running from CGI or similar by checking for interactive shell
2015-10-30 09:46:35 +01:00
62af7be5a1 Added check for availability oftput (Fixes #222)
Slight change due to drwetter's comment
2015-10-25 22:31:44 +10:00
4095dc53be Changed wording for easier readability. 2015-10-16 14:40:06 +01:00
7bf1319c93 - FIX #218 for exim and friends 2015-10-15 15:14:37 +02:00
eb49132682 - changed headline for each sub test from blue to underline+bold
- save determine_service log
2015-10-15 14:15:07 +02:00
78fab8addb - FIX #213, wording 2015-10-13 22:25:01 +02:00
d4dbf1138c - FIX #214 2015-10-13 08:31:54 +02:00
1a1f007ef9 - banner f'up reversed 2015-10-11 23:34:53 +02:00
8c0786d147 - switched on clientauth functionality (missed b4) 2015-10-11 23:23:35 +02:00
b9bfd48871 - client based auth (see sclient_connect_successful() works now, see #206)
- careful regression tests for this, point open: speed
- test for more TLS extensions
- heartbleed() does now before a check whether heartbeat is available to save time
- breach simplyfied (and doesn't have to be killed in seldom cases)
- tmpfiles are only being erased after exit not after each function
- user agent is testssl -- unless --sneaky is chosen
- global host vars are now being resetted to prevent side effects
- tls version in record layer is now always 1
- used ERRFILE wherever possible
- smaller code cleanups
2015-10-11 23:07:16 +02:00
0600e39b45 - fix screw up of rDNS display for those few folks having only IPv4 ;-) 2015-10-06 12:30:29 +02:00
f8d6a2fb6d - IPv6 formatting fixed, see #11 (points 3,4,5)
5 cannot be done automagically, see issue
2015-10-05 09:56:21 +02:00
a0d634f94a - ouput corrections for BEAST 2015-10-04 12:32:29 +02:00
41bc2fb70c - regression wrt what_dh 2015-10-03 00:14:52 +02:00
f3cef41053 - some speed improvements (sed, tr --> bash internal s'n'r)
- revamped BEAST a bit: availablity of higher protocols lead now to yellow color, see #208
- Fixed error in BEAST (no higher protos led to no message)
- made BEAST it faster: one check for protocol ssl3+tls1 upfront, see #208
2015-10-01 13:27:14 +02:00
2ca6c2b0dc improved variable naming, scope and worked around length limitation of cipher list, as suggested by @drwetter 2015-09-30 14:54:39 +02:00
449aada392 fix CBC cipher selection
CBC cipher selection is not so easy using the openssl tool alone. Selecting the cipher based on the string CBC occuring in it would be right if it’s
about the RFC name of the cipher but not so with the openssl naming. Since CBC ciphers are not going to be continued anyway, I think it’s safe to take
a static list. However, it’s easy to extract it from the cipher list in openssl-rfc.mapping.html, but we certainly don’t want to require that file to
be shipped all the time.
2015-09-30 12:44:27 +02:00
1c1eaa53d8 - fix for renamed http_header function 2015-09-29 18:47:49 +02:00
cac49cb1f1 - "--file" implicitly does "--warnings=batch"
- "--file" works now fine with equal sign
- fixed load balancer issue where header request stalled and testssl.sh consequently too
- http_date needed to be changed too because of that
- needed to estimate then the http_date when request was killed (HAD_SLEPT)
  will Mr. Spock like this??
- fixed load balancer issue where header request for breach test stalled and thus an error was displayed
- code improvements
2015-09-28 22:54:00 +02:00
feaef680aa - IPv6 #11 is 80% working (whohoo!). Needed is an openssl capable IPv6 and HAS_IPv6=true in the environment
- FIX #191
2015-09-26 22:44:33 +02:00
cc81642ee3 - #FIX 202 (EV detection from TERENA/Digicert) 2015-09-25 14:35:42 +02:00
a2efc201b7 - added a failure condition for trust check 2015-09-24 09:10:43 +02:00