Dirk
60a8e0a190
monor resorting and cosmetic improvements
2017-03-19 09:47:49 +01:00
Dirk
bb5b778ee1
update/resort
2017-03-19 09:36:19 +01:00
Dirk
73a094fcc7
FIX #648 (retrieve cipher and protocol from ServerHello) --> saves ~1 second and makes code better to read
...
other readabilty improvements
2017-03-18 22:24:35 +01:00
Dirk
8be47e484b
replace some "echo $x" by HERE statement "<<<"
2017-03-18 21:01:55 +01:00
Dirk
c618b9a954
fix CR for standard cipherlists with debug=1
2017-03-18 16:09:22 +01:00
Dirk
21a51b4ff0
Merge branch '2.9dev' of github.com:drwetter/testssl.sh into 2.9dev
2017-03-18 15:58:30 +01:00
Dirk
407c4383bf
- externalized client simulation data
...
- fixed *_fixme()
2017-03-18 15:57:16 +01:00
Dirk Wetter and GitHub
4a6c7de3b7
native HTML support
2017-03-18 15:07:02 +01:00
Dirk Wetter and GitHub
30e68311fc
Merge pull request #658 from AlGreed/2.9dev
...
Fixed #657 : Severity flag for JSON-PRETTY produces malformad JSON object
2017-03-18 13:12:40 +01:00
Dirk Wetter and GitHub
9d06b1a0f5
Merge pull request #665 from drwetter/2.9dev_html
...
merge 2.9dev_html into 2.9dev
2017-03-18 13:04:42 +01:00
Dirk
84a4fafe1e
fixed merge conflicts
2017-03-18 12:54:01 +01:00
Dirk Wetter and GitHub
71f446b170
Merge pull request #662 from dcooper16/normalize_ciphercode_html
...
Speedup normalize_ciphercode()
2017-03-17 21:20:12 +01:00
Dirk Wetter and GitHub
1c9670857b
Merge pull request #661 from dcooper16/normalize_ciphercode
...
Speedup normalize_ciphercode()
2017-03-17 21:19:23 +01:00
Dirk Wetter and GitHub
c148a93361
Merge pull request #656 from dcooper16/show_finding
...
Add spaces in show_finding()
2017-03-17 17:39:34 +01:00
Dirk Wetter and GitHub
939b6f0cb9
Merge pull request #652 from dcooper16/html_headers_and_footers
...
Fix HTML headers and footers
2017-03-02 09:38:35 +01:00
Dirk Wetter and GitHub
20f29fd780
Merge pull request #651 from dcooper16/html_reserved
...
Handle HTML reserved characters in headers
2017-03-01 09:40:42 +01:00
Dirk
ca6cb0bf81
updated from #632 from dcooper16/negotiated_cipher
2017-02-28 18:33:17 +01:00
Dirk Wetter and GitHub
27aa25711d
Merge pull request #632 from dcooper16/negotiated_cipher
...
Negotiated cipher per proto bugfix
2017-02-28 15:42:28 +01:00
Dirk
79a8a02328
adding spring boot header detection
2017-02-27 19:16:29 +01:00
Dirk
ac193a8ef0
adding spring boot header detection
2017-02-27 19:12:59 +01:00
Dirk Wetter and GitHub
84d142a6cf
Merge pull request #650 from dcooper16/emphasize_stuff_in_headers
...
Redo emphasize_stuff_in_headers()
2017-02-27 17:33:46 +01:00
Dirk Wetter and GitHub
854e55e15b
Merge pull request #649 from dcooper16/PR_646
...
Merge PR #646 into 2.9dev_html
2017-02-27 16:38:59 +01:00
Dirk
2232929bc5
Polish #646
...
"=~" doesn't need quotes if there's a text string one wants to match against (and shellcheck complains
about this)
pr_magenta shouldn't be used anymore as the logic what color we use should be done
some place else.
2017-02-27 13:43:23 +01:00
Dirk Wetter and GitHub
f7c3139545
Merge pull request #646 from dcooper16/rfc-only
...
Add option to print only the RFC cipher names
2017-02-27 13:30:11 +01:00
Dirk
4727a69a62
fixed segfaults
2017-02-25 17:15:18 +01:00
Dirk
8d66786e42
Just saving my workJust saving my work ...
...
This branch is for getting the HTML patch from @dcooper16 into 2.9dev
Change to David's PR:
* removed HTMLHEADER. We always want that (in fact for flat JSON this is missing and needs to be added)
* not sure what this change does to --file
* changing of names They were redundant sometimes (pr_*_term )
* some formatting for readbility
Open points:
* there's a loop and a segfault --> tm_done_best
* HTMLHEADER: --file
* the former sed statement aroung L1900 for the header was way more readable. The combined
html+terminal version is just too much. Maybe a switch whether HTML is requested
is better so that this can be separated.
* Then e.g. "<span style=\"color:olive;font-weight:bold" can be kept in a variable
* any reason we need the text length here?
* what went into main here is too much. Actuallly what I put already in there bothered
me as too much logic and not obvious dependencies are in here. Now it's worse :-)
Can't this be just similar to JSON or CSV -- a seperate function with hooks
not in main()?
* minor thing: TERM_WIDTH is for HTML is maybe not the best. But that can be
tackled later
2017-02-25 16:31:30 +01:00
Dirk
b10942a92e
Merge branch 'generate_html' of https://github.com/dcooper16/testssl.sh into dcooper16-generate_html
2017-02-25 12:21:33 +01:00
Dirk Wetter and GitHub
1072e41b0b
Merge pull request #647 from gniltaws/2.9dev
...
Add missing herestring redirect (<<<) in find_openssl_binary function
2017-02-24 23:06:20 +01:00
Dirk Wetter and GitHub
ca18433959
Update README.md
2017-02-24 17:55:20 +01:00
Dirk Wetter
3f0a98b635
Generated from utils/update_client_sim_data.pl and manually massaged ;-)
...
Note that the internal data from testssl.sh will disappear
2017-02-24 17:45:23 +01:00
Dirk Wetter
e7e9a3ed66
addressing #645 before #554 has been addressed
2017-02-24 16:26:22 +01:00
Dirk Wetter
4361bb7cce
housekeeping/ cleanup
2017-02-24 16:22:59 +01:00
Dirk
b4f59e91be
FIX #621
2017-02-23 17:19:52 +01:00
Dirk Wetter and GitHub
8919b419e5
Merge pull request #642 from dcooper16/wrap_long_lines
...
Wrap long lines in display_rdns_etc()
2017-02-21 22:51:24 +01:00
Dirk Wetter and GitHub
6457775b5f
Merge pull request #644 from dcooper16/fix643
...
Fix issue #643
2017-02-21 22:46:34 +01:00
Dirk
be079acb5e
- collect more TLS extensions
2017-02-21 11:16:14 +01:00
Dirk
34053e27cd
Merge branch '2.9dev' of github.com:drwetter/testssl.sh into 2.9dev
2017-02-21 08:50:46 +01:00
Dirk
0ce7a3b7d2
see diff ;-)
2017-02-21 08:50:09 +01:00
Dirk Wetter and GitHub
6b90152f52
Merge pull request #639 from dcooper16/must_staple
...
OCSP must staple
2017-02-20 12:31:16 +01:00
Dirk Wetter and GitHub
52a0d44b90
Merge pull request #637 from dcooper16/print_negotiaed_cipher
...
Printing Negotiated cipher
2017-02-20 11:46:24 +01:00
Dirk
bfbaba4ea7
- trying to address #640 . Better a bit pessimistic here...
2017-02-20 09:44:52 +01:00
Dirk
c284185c56
- try to address #638
2017-02-18 13:22:17 +01:00
Dirk
d2cbbaf0b1
- FIX #636
...
- polish
2017-02-16 19:10:59 +01:00
Dirk Wetter and GitHub
a973386c0a
Merge pull request #635 from dcooper16/run_protocols_bugfix
...
run_protocols() bug fix
2017-02-15 19:44:53 +01:00
Dirk
c204a0b942
--proxy=auto takes now the value from https_proxy
...
- made DNS lookups safe (CNAME) and awk'd them almost completely ;-)
- invocation of just testssl.sh shows help again
2017-02-15 19:40:06 +01:00
Dirk Wetter and GitHub
502601c95e
Merge pull request #633 from k0ste/2.9dev_newfeature
...
DNS CAA: drill query support.
2017-02-15 14:01:36 +01:00
Dirk
4b193119b3
- made CCS I more robust, FIX #313
...
- removed cats ;-) FIX #352
2017-02-14 21:56:31 +01:00
Dirk
422171a0fa
- fixed bug where terminal width was not inherited in file batch mode so that terminal wdith appeared to be 80 chars
...
- hint when URI is missing
- PFS_CIPHERs rather locally
2017-02-14 20:40:38 +01:00
Dirk
a22e4e5228
- fix heartbleed detection which sometimes case false psoitives over slow connections like sattelite links, partially addressing #352
...
- start revamping run)ccs_injection
- fix missing space in BEAST after protocol
2017-02-14 19:45:14 +01:00
Dirk Wetter and GitHub
67fb3feff8
Merge pull request #630 from dcooper16/show_rfc_
...
Option to show RFC cipher names
2017-02-14 09:28:15 +01:00
Dirk Wetter and GitHub
971c8e8b63
Update Readme.md
2017-02-13 09:33:50 +01:00
Dirk Wetter and GitHub
c252d5ab28
Update Readme.md
2017-02-13 09:33:03 +01:00
Dirk
7d6f1eb46f
polishing #628 , mostly make sure we automatically align to terminal width
2017-02-13 09:06:10 +01:00
Dirk Wetter and GitHub
21cd97b08a
Merge pull request #628 from dcooper16/format_long_lines
...
Wrap long lines
2017-02-13 08:52:07 +01:00
Dirk
d2f688e925
CAA RR belongs also in JSON, see #588
2017-02-11 14:16:18 +01:00
Dirk
8dabc28280
also made sure that all old dns binaries work (SLES 11, FreeBSD 9)
2017-02-11 14:01:51 +01:00
Dirk
386aa92448
keep detected status of WSL / bash on windows in a variable, see also #620
2017-02-08 09:08:05 +01:00
Dirk
0200100750
see #620
2017-02-08 08:58:28 +01:00
Dirk Wetter and GitHub
0b7e9b18b8
Merge pull request #620 from teward/2.9dev
...
Attempt to force system binaries for WSL
2017-02-08 08:54:20 +01:00
Dirk Wetter and GitHub
0810f2a719
Merge pull request #609 from dcooper16/handle_supported_groups
...
Handle renaming of the Supported Elliptic Curves Extension
2017-02-08 08:11:23 +01:00
Dirk
0d993427a3
- enabling TLS 1.2 via sockets
...
- enabling sockets in run_protocols STARTTLS per default
- minor output polishing
2017-02-07 23:08:29 +01:00
Dirk Wetter and GitHub
edb358b3e0
Merge pull request #595 from dcooper16/rename_ephemeral_DH_ciphers
...
Rename cipher lists for run_logjam()
2017-02-07 17:51:07 +01:00
Dirk
48e264a193
fixed regression #611
2017-02-06 17:47:17 +01:00
Dirk
54e0395969
Reverse #600 but leave the hook in here, ANSI code for strikethru
2017-02-06 11:06:59 +01:00
Dirk Wetter and GitHub
03daa1be35
Merge pull request #608 from dcooper16/neat_list_camelliagcm
...
Fix neat_list() for Camellia GCM
2017-02-06 10:41:01 +01:00
Dirk
a9cddd7afb
see #611
2017-02-04 15:11:03 +01:00
Dirk Wetter and GitHub
e95f9a8d0a
Merge pull request #611 from dcooper16/print_two_CRL_or_OCSP_URI
...
Fix Two CRL and/or two OCSP URLs
2017-02-04 15:06:18 +01:00
Dirk
3a21097cc5
HTTP/1.1 GET handler for #254
2017-02-04 14:13:33 +01:00
Dirk Wetter and GitHub
59c3286775
Merge pull request #612 from dcooper16/update_fix_587
...
Update fix to 587
2017-02-04 12:14:09 +01:00
Dirk
5046b80414
first draft of LUCKY13 (128 cipher limit has to be addressed)
2017-02-03 22:36:04 +01:00
Dirk
cb1d133528
preparing for lucky13
2017-02-03 17:40:35 +01:00
Dirk
925e1061b2
- renamed pr_svrty_minor --> pr_svrty_low to reflect the level literally
...
- minor polishing
2017-02-03 13:03:22 +01:00
Dirk
b9232fd5d0
Fix TLS_FALLBACK_SCSV detection for non RFC compliants F5 loadbalancers. They pass now the test but get additonally penalized for their non compliance, see also https://github.com/drwetter/testssl.sh/issues/121#issuecomment-113790270
2017-02-03 11:47:21 +01:00
Dirk
ec7aa2481a
- SWEET32. Note this is still NOT COMPLETE (ciphers!) and needs more testing
2017-02-02 14:42:06 +01:00
Dirk Wetter and GitHub
c0cf622aff
Merge pull request #600 from dcooper16/unsupported_ciphers_in_litegrey
...
Print unsupported ciphers in light grey
2017-01-30 18:29:57 +01:00
Dirk
a7dff83160
$NODE is fine, removing $MX_HOSTNAME, #603
2017-01-29 10:46:35 +01:00
Dirk Wetter and GitHub
1e16ac8ad6
Merge pull request #603 from AlGreed/2.9dev
...
Better output for --MX in JSON-PRETTY
2017-01-29 10:40:23 +01:00
Dirk Wetter and GitHub
2ea3789b91
Merge pull request #602 from AlGreed/2.9dev
...
Support of multiple servers for JSON-PRETTY
2017-01-28 10:27:45 +01:00
Dirk Wetter and GitHub
0bb792225e
Merge pull request #599 from dcooper16/fix_tls_sockets_typo
...
Fix typo in tls_sockets()
2017-01-25 15:00:33 +01:00
Dirk Wetter and GitHub
bc31639179
Merge pull request #545 from dcooper16/cipher_order_sockets
...
Use sockets to determine cipher order
2017-01-24 20:26:05 +01:00
Dirk
2a5d56a9d6
help aviod misunderstanding, see #594 and some reordering
2017-01-24 08:37:19 +01:00
Dirk
4911aaf05b
Fix #593
2017-01-23 11:33:18 +01:00
Dirk Wetter and GitHub
8988411fbc
Merge pull request #565 from dcooper16/run_server_preference_sockets
...
Use sockets in run_server_preference()
2017-01-21 19:55:37 +01:00
Dirk
f80e1ecfdb
- enable CAA per default ( #588 )
...
- hex2ascii() for converting strings
- swap quoted output in -S to italic (mostly)
2017-01-21 19:43:07 +01:00
Dirk
f2303a0d79
- poodle output polishing
...
- minor polish of #552
2017-01-21 18:08:31 +01:00
Dirk Wetter and GitHub
d448ebbc77
Merge pull request #552 from dcooper16/run_beast_sockets
...
run_beast() speedup + sockets
2017-01-21 18:01:55 +01:00
Dirk
2b440f15ea
- polishing #570
...
- run_logjam() terminates if no local DH export ciphers are configured
2017-01-21 16:52:02 +01:00
Dirk Wetter and GitHub
20cc3bc435
Merge pull request #570 from dcooper16/run_ssl_poodle_sockets
...
Use sockets for run_ssl_poodle()
2017-01-21 14:37:36 +01:00
Dirk
f3666a13c5
- add crypotsense prefined DH groups
...
- final FIX #589
2017-01-20 18:14:48 +01:00
Dirk
e083fab130
- run_logjam(): run_logjam(0 fixed error where logjam couldn't parse "ServerKeyExchange" message using SSL_NATIVE -- if TLS != 1.2 was returned
...
- run_logjam(): determine dh bit size and based on this mark the common primes as more or less vulnerable
- run_logjam(): renamed remaining dhe variable to dh
- further house keeping in run_logjam()
2017-01-19 14:45:19 +01:00
Dirk Wetter and GitHub
9c3ab427b6
Merge pull request #590 from dcooper16/dhe_cipher_list
...
Generate list of all DHE ciphers
2017-01-18 22:08:43 +01:00
Dirk
e3d183e909
-output correction run_logjam
...
- rename dhe to dh
2017-01-18 22:05:27 +01:00
Dirk
05d27ff1be
- FIX for the last mess submitted ;-)
2017-01-18 18:09:39 +01:00
Dirk
61b16a078a
- file etc/common-primes was not edited correctly!
2017-01-18 16:38:09 +01:00
Dirk
8bf7b6b31b
forgot to save work, followup to 4433345b16 , #120 , #589
2017-01-18 16:23:18 +01:00
Dirk
4433345b16
- first implementation (draft) of LOGJAM common primes, see #589 , #120
...
- output polishing of run_drown()
- polishing of run_logjam()
- decrease severity to high for LOGJAM, see CVE rating
2017-01-18 15:53:01 +01:00
Dirk
b1c80512e6
first bunch of common primes, see #589 + #576 + #120 . License of nmap is also GPLv2: no conflicts
2017-01-18 12:44:15 +01:00
Dirk
e9916dd1f4
- FIX #566
...
- reorder get_<DNS>_record() for better overview
- move CMDLINE__IP away from main into determine_ip_addresses() where it belongs to
2017-01-17 13:57:14 +01:00
Dirk
e7a35934ae
add lf before -E
2017-01-17 12:00:18 +01:00
Dirk Wetter and GitHub
5ea5ae5a53
Merge pull request #571 from dcooper16/run_freak_sockets
...
Use sockets for run_freak()
2017-01-17 11:41:50 +01:00