Dirk
53b6e2cfe8
changed PoC to a 3 rounder test (like testssl.sh) to increase reliability.
...
If different memory is returned each try it is for sure vulnerable. This
helps getting weird servers properly tested and weeds out false positives.
2017-06-07 18:16:18 +02:00
Dirk
5bb5c19e63
cleanup before addressing #592
2017-06-07 09:54:24 +02:00
Dirk
a8ffa66cad
output polishing for must staple
2017-06-01 18:15:44 +02:00
Dirk
63cb4ffc5e
improved high level sections of DNS in determine_ip_addresses()
...
FIX #668
Polishing ``get_*_record()``
Simplfied ``main`` a bit
2017-06-01 18:08:13 +02:00
Dirk
a90eb8c9be
FIX #744
2017-06-01 16:24:45 +02:00
Dirk Wetter and GitHub
f3f29cd85c
Merge pull request #760 from dcooper16/fix_757
...
Fix #757
2017-06-01 15:51:21 +02:00
Dirk
e4f64463a4
FIX #758
2017-06-01 15:47:38 +02:00
Dirk
5890677d85
chmodded
2017-06-01 11:14:52 +02:00
Dirk
de5b2aa042
readded basic check from seccubus whether check via starttls works
2017-06-01 11:14:04 +02:00
Dirk Wetter and GitHub
bd015b9129
Merge pull request #753 from dcooper16/mass_testing_command_line_error
...
Massing testing with command line error
2017-05-31 21:37:54 +02:00
Dirk
91b9236055
PoC for unit test in bash
2017-05-31 10:30:02 +02:00
Dirk Wetter and GitHub
55b89ee131
Rename 02_http.t to 32_http.t
2017-05-30 22:15:13 +02:00
Dirk Wetter and GitHub
4afedb45b1
Rename 01_badssl.com.t to 31_badssl.com.t
2017-05-30 22:14:19 +02:00
Dirk Wetter and GitHub
8e1ace839f
Merge pull request #755 from dcooper16/stop_parent
...
Stop parent if child encounters parsing error
2017-05-30 21:05:05 +02:00
Dirk
de177a774c
fix formatting problem in run_client_simulation() wide mode when CHACHA20/POLY1305-OLD ciphers
...
are encountered and remove 4 columns before protocols.
mimor readability improvements in prepare_array() and run_client_simulation()
2017-05-22 23:04:58 +02:00
Dirk Wetter and GitHub
26bf3300e8
Delete mapping.txt
...
has been replaced in 2.9dev by cipher-mapping.txt
2017-05-22 11:38:23 +02:00
Dirk
d64fabafd5
completed the commit 601c810240
...
started to use the ip parameter to decide where the dns resoultion
takes place (see #739 and #748 ). --ip=proxy or DNS_VIA_PROXY=true
will mean DNS resolutioni is done by proxy,
furthermore: swapped a few pr_magenta by pr_warning. Generally
testssl.sh should use for warnings a warning function and not
directly a color (we want to be flexible). There are still a few
remainders for fatal() which use bold magenta and thus I haven't
changed yet.
Also html_reserved() is being called also if no html output
is being requested. This could be fixed better probably.
2017-05-19 20:28:18 +02:00
Dirk
601c810240
add stderr to line showing "Waiting for test" FIX #750
2017-05-19 17:09:47 +02:00
Dirk
041abd57ce
FIX #749 and #751
...
Additionally fix a probable cmd line parsing problem where an argument '--file' was supplied with '='
2017-05-19 17:00:30 +02:00
Dirk
83b3be5636
update to also reflect dcooper16's work
2017-05-17 18:56:07 +02:00
Dirk Wetter and GitHub
a3c318655d
Merge pull request #745 from dcooper16/run_mass_testing_parallel2
...
More improvements to mass testing in parallel
2017-05-17 18:34:13 +02:00
Dirk Wetter and GitHub
a5e224b082
Update Readme.md
2017-05-17 09:03:15 +02:00
Dirk
dfda82aa7d
Merge branch '2.9dev' of github.com:drwetter/testssl.sh into 2.9dev
2017-05-16 09:46:55 +02:00
Dirk
3b1638f603
small performance improvement for prepare_arrays() by replacing grep + awk by awk only
2017-05-16 09:45:16 +02:00
Dirk
59a175cba3
changed to Linux
2017-05-15 20:53:09 +02:00
Dirk Wetter and GitHub
5bb1a67dde
Update Readme.md
2017-05-15 20:14:11 +02:00
Dirk
e8b5a82c7e
Considerable reliability improvements for ticketbleed: if a handshake server hello
...
was received, testssl.sh tries 3 times to get memory from the server, If
the server returns different memory it's highly likely vulnerable.
(some more vulnerable devices to test against would be appreciated).
This is the default now -- all other hosts are mostly labled as OK.
Parsing SERVICE should be a little faster and more reliable
Increased needed debug level for output @ parse_tls_serverhello
2017-05-15 19:47:13 +02:00
Dirk
b694930fc2
RFC 5077 states that the server MAY give a hint of the lifetime of the ticket.
...
Sometimes it just does not. In those case also sometimes session resumption
via tickets is supported.
This fixes the output for Session Ticket RFC 5077 and doesn't draw the wrong
conclusion from a missing lifetime hint.
It also tests for ticketbleed first whether there's a session ticket TLS
extension.
2017-05-15 13:18:20 +02:00
Dirk
49b1be9f34
fix json/csv output for ticketbleed
2017-05-15 10:08:34 +02:00
Dirk
b4889a731b
Upgraded proxy sockets to use CONNECT 1.0 to avoid proxy problems -- for the time being (see also #741/ #739 )
2017-05-12 18:31:59 +02:00
Dirk
2aa68827b9
don't do double work, reordering stuff
2017-05-12 17:58:20 +02:00
Dirk
f70bc4e08f
better platform support, revert to pure /bin/sh, better verbosity...
2017-05-12 17:21:45 +02:00
Dirk Wetter and GitHub
bed1f8cc0d
Merge pull request #743 from dcooper16/broken_pipe
...
Prevent broken pipe error
2017-05-12 16:18:18 +02:00
Dirk Wetter and GitHub
2750febb2f
Merge pull request #740 from dcooper16/run_mass_testing_parallel
...
Improvements to mass testing in parallel
2017-05-10 18:49:55 +02:00
Dirk
2936a42bc7
address #626
2017-05-09 21:58:03 +02:00
Dirk
9ed47eaa19
FIX #718 (added TLS padding to ticketbleed handshake). Also added TLS extension Signature Algorithms
2017-05-09 17:29:57 +02:00
Dirk
23e6209beb
Merge branch '2.9dev' of github.com:drwetter/testssl.sh into 2.9dev
2017-05-08 23:55:19 +02:00
Dirk
ebd9e6ae65
manually merged #728 (see #423 ), credits also to @seccubus. Unfortunately the unit tests don't make so much sense atm
2017-05-08 23:51:37 +02:00
Dirk Wetter and GitHub
53da6da77b
Merge pull request #730 from typingArtist/729_catch_read_timeout
...
correctly capture return code in starttls_full_read
2017-05-04 22:32:23 +02:00
Dirk
699b48c8b8
lowering severity and taking other clients as browsers into account #735
2017-05-04 12:34:20 +02:00
Dirk Wetter and GitHub
19052da1a5
Merge pull request #735 from tkaehn/alert_on_missing_sans
...
Alert on missing SANs
2017-05-04 11:52:47 +02:00
Dirk Wetter and GitHub
c9b6ee25b1
Delete 11_hpkp.t
2017-05-04 10:29:06 +02:00
Dirk
7d8479f55e
temporary disabled until either an replacement has been coded or host is up again
2017-05-04 10:14:42 +02:00
Dirk
ba9c056dfc
renamed browser --> client simulation
2017-04-28 20:35:07 +02:00
Dirk Wetter and GitHub
ef10fc3119
Merge pull request #726 from oerdnj/2.9dev-no-downgrade-breach
...
Revert "Downgrade BREACH attack to MEDIUM severity"
2017-04-25 23:10:11 +02:00
Dirk Wetter and GitHub
bd4575e14d
Merge pull request #724 from oerdnj/2.9dev
...
Fix prln usage to outln
2017-04-25 16:27:47 +02:00
Dirk
8ea8513529
fixed in Testing server preferences --> Negotiated cipher the empty TMPfile which led to an ugly error
...
fixed in Session Resumption for tickets if no extension=no resumption: there was 1x LF too much
2017-04-24 19:18:39 +02:00
Dirk Wetter and GitHub
7a99549e80
Merge pull request #721 from dcooper16/client_simulation_wide_option
...
Add wide option for client simulations
2017-04-24 16:26:08 +02:00
Dirk
01489b9ca1
special treatment for empty serverhello for ticketbleed
2017-04-24 09:25:23 +02:00
Dirk
2db8e8e8b1
use HAS_NO_SSL2
2017-04-22 22:14:06 +02:00
Dirk
c8cd1318e9
FIX #719 , still work to do for ticketbleed ( #655 )
2017-04-22 15:39:18 +02:00
Dirk
f8e1ad0b7f
add missing #
2017-04-22 15:19:39 +02:00
Dirk
584c933493
updated user agent for sneaky
2017-04-21 11:31:42 +02:00
Dirk
7de5e0113b
check in
2017-04-21 11:29:20 +02:00
Dirk
28660f7a77
corrected pr_warningln
2017-04-20 17:29:07 +02:00
Dirk
1d992f3620
preview from clientsim branch, important to add now
2017-04-20 17:24:07 +02:00
Dirk
7c676dfc63
FIX #717 -- doubel meaning fo '-h'
2017-04-19 19:46:54 +02:00
Dirk Wetter and GitHub
869ec9b9c3
Merge pull request #685 from dcooper16/openssl_location
...
Populate OPENSSL_LOCATION in find_openssl_binary
2017-04-19 18:23:14 +02:00
Dirk Wetter and GitHub
219a07a620
Merge pull request #716 from gniltaws/2.9dev
...
Use $TESTSSL_INSTALL_DIR instead of $RUN_DIR in find_openssl_binary() - Second Try
2017-04-19 18:05:03 +02:00
Dirk Wetter and GitHub
828dda79f3
Merge pull request #715 from dcooper16/travis_check_for_html
...
Add Travis test for HTML output
2017-04-19 16:01:07 +02:00
Dirk
c4a2ba8b49
vuln count adjusted
2017-04-19 01:21:13 +02:00
Dirk Wetter and GitHub
51497c9dfb
Merge pull request #714 from drwetter/revert-712-travis_check_for_html
...
Revert "Add Travis test for HTML output"
2017-04-19 00:55:35 +02:00
Dirk Wetter and GitHub
9164230186
Revert "Add Travis test for HTML output"
2017-04-19 00:53:38 +02:00
Dirk Wetter and GitHub
5285c26759
Merge pull request #712 from dcooper16/travis_check_for_html
...
Add Travis test for HTML output
2017-04-19 00:38:27 +02:00
Dirk
9ff868b083
fix travis
2017-04-19 00:35:55 +02:00
Dirk
2469603a7f
save also 1x connect for heartbleed() by reusing a previoulsy identified protocol
2017-04-19 00:30:09 +02:00
Dirk
de79bd6b0e
implemented ticketbleed (experimental). Renamed other vulnerabilty checks to easier memorize each check:
...
-H is now --heartbleed instead of --headers,
-B is now --breach instead of --heartbleed,
-T is now --ticketbleed (was previously --breach)
bugs fix for run_ccs_injection() where the tls protocols wa not properly passed to the ClientHello
Made use of already determined protocol ( this time only from determine_optimal_proto() ) ==> we shpould use this in run_protocols() too!)
for run_ccs_injection + run_ticketbleed(). For achieving this determine_optimal_proto() needed to be modified so that it adds a protocol
to PROTOS_OFFERED (all_failed is now boolean there)
added two easy functions for converting dec to hex
sockread_fast() is for testing which should make socket erads faster -- albeit it could potentially block the whole thing
2017-04-18 23:15:32 +02:00
Dirk
ac5b9a8a78
minor polishing, correct handshake length
2017-04-18 23:06:12 +02:00
Dirk
dd9b3919fc
PoC uploaded
2017-04-16 20:38:47 +02:00
Dirk
4b833b7b6e
code readability improvements
2017-04-14 11:26:01 +02:00
Dirk Wetter and GitHub
3d8c8769a9
Merge pull request #709 from dcooper16/fix_616
...
Fix #616
2017-04-14 11:04:54 +02:00
Dirk Wetter and GitHub
0b9c04350d
Merge pull request #710 from dcooper16/debug_output_in_html
...
No debugging text in HTML output
2017-04-14 11:03:48 +02:00
Dirk Wetter and GitHub
df953dca25
Merge pull request #711 from dcooper16/color_in_headers
...
Use of color in emphasize_stuff_in_headers()
2017-04-13 22:22:59 +02:00
Dirk Wetter and GitHub
34a512a363
Merge pull request #708 from dcooper16/use_get_cipher
...
Use get_cipher() helper function
2017-04-13 16:50:42 +02:00
Dirk
5168fab693
minor polishing
2017-04-12 21:50:55 +02:00
Dirk Wetter and GitHub
d2b70f7289
Merge pull request #706 from dcooper16/fix_702
...
Fix #702
2017-04-12 21:33:36 +02:00
Dirk Wetter and GitHub
9f7ab1cef6
Merge pull request #707 from dcooper16/more_702_fixes
...
More fixes for #702
2017-04-12 21:19:17 +02:00
Dirk
036bf2e53c
revamped run_std_cipherlists(). There are now less catagories, less overlap and it's more modern:
...
NULL ciphers (no encryption)
Anonymous NULL Ciphers (no authentication)
Export ciphers (w/o ADH+NULL)
LOW: 64 Bit + DES encryption (w/o export)
Weak 128 Bit ciphers
Triple DES Ciphers (Medium)
High grade encryption
Strong grade encryption (AEAD ciphers)
2017-04-12 21:00:08 +02:00
Dirk
ed2aa6698d
comments added for #705
2017-04-11 18:48:23 +02:00
Dirk Wetter and GitHub
3820e2c25c
Merge pull request #705 from dcooper16/read_tls_data
...
Don't read tls_data.txt inside function
2017-04-11 18:40:01 +02:00
Dirk
5054cc33f3
rename *test_just_one as @AlGreed suggestted in #703
2017-04-10 14:45:39 +02:00
Dirk
0bbbd5217a
swapped -f and -s
...
-f is now forward secrecy
-s is standard cipher lists
2017-04-08 09:14:56 +02:00
Dirk
55713e4929
use per default a lf before the first fatal message
2017-04-07 10:26:41 +02:00
Dirk
c75a2cd838
In addition to #701 add quotes for correcting cmdline parsing -- especially for supplied filenames/arguments
...
(HTML,CSV,JOSN,PROXY).
Also strip off leading http:// | https:// for --proxy
2017-04-07 09:49:44 +02:00
Dirk Wetter and GitHub
dc629202bb
Merge pull request #701 from dcooper16/wordsplitting_filenames
...
Handle word splitting of log file names.
2017-04-07 08:54:07 +02:00
Dirk Wetter and GitHub
9c13d2a3a2
Merge pull request #700 from dcooper16/fix_696
...
Fix #696
2017-04-07 08:52:38 +02:00
Dirk Wetter and GitHub
46ca4b272d
Merge pull request #699 from dcooper16/fix_695
...
Fix #695
2017-04-07 08:38:52 +02:00
Dirk
e2f5d5c3cf
updated comments
2017-04-06 11:33:54 +02:00
Dirk
3351f8832c
mute the error message using bash3, see #697 (2.9dev)
2017-04-06 11:23:57 +02:00
Dirk Wetter and GitHub
c188408f8e
Merge pull request #698 from dcooper16/mass_testing_parallel
...
Mass testing in parallel
2017-04-06 10:25:38 +02:00
Dirk
8a2967c62e
make use of swapped out tls data file
...
(main() sill needs a bit of work)
2017-04-06 09:47:09 +02:00
Dirk
61d42b022c
fix missing space in banner and suppress empty version string
2017-04-05 20:39:35 +02:00
Dirk
ec55cdea14
"post-fix" for #697 (2.9dev)
2017-04-05 20:20:00 +02:00
Dirk
bfb0f4bc7d
FIX #697 in 2.9dev (bash hiccup @ tolower)
2017-04-05 17:28:06 +02:00
Dirk
b1ce11d76e
in addition to #694 : using the predefined variable
2017-04-05 14:48:35 +02:00
Dirk
6b0f389225
fix #694 (CSP and HTTP header friends were cut off @ last colon)
...
introduced strip_leading_space() / strip_trailing_space()
2017-04-05 14:42:55 +02:00
Dirk
7549f10c79
added explanation for #692
2017-04-04 20:23:28 +02:00
Dirk Wetter and GitHub
c593f06f6d
Merge pull request #692 from dcooper16/fix_html
...
Fix HTML
2017-04-04 20:18:05 +02:00
Dirk
8213e2436c
addressed #691 for 2.9dev
2017-04-04 09:54:47 +02:00
Dirk
498dda94ce
using get_san_dns_from_cert()
2017-04-01 10:38:04 +02:00