Commit Graph
96 Commits
Author SHA1 Message Date
Dirk Wetter 5d66eeef05 Update Readme.md 2014-12-09 14:25:38 +01:00
Dirk b40c0b7178 - RELEASE: final 2.2
- change of cmd line order for STARTTLS
- help more clear
2014-12-08 10:32:51 +01:00
Dirk b3efb3c4b0 - BUGFIX: potential stalling in HTTP Header query
- BUGFIX: HTTP specific vuln. won't be checked if service is not http (we still
check crime and also spdy => gmail has spdy for pop and imap)
- Feature: service detection: HTTP, IMAP, POP, SMTP
- alignment in rDNS output corrected
- minor cleanup / improvements
2014-11-30 01:30:20 +01:00
Dirk 27f06f8d50 - BUGFIX: BSD now has proper heartbleed and ccs injection detection
- significant code improvement of hex-byte parser <-> socket sender
- BUGFIX: BSD now doesn't put an extra \n if rfc map file is missing
- bumped to 2.1rc3, hoping that'll be the last
2014-11-27 21:33:33 +01:00
Dirk c034cd8a95 - for colors: double square brackets (might save a fork to "[ or "test"
- in terms of debugging cleaned up listciphers/std_cipherlists
- in other terms too
2014-11-25 13:12:24 +01:00
Dirk Wetter 5228986b25 Update Readme.md 2014-11-24 16:43:11 +01:00
Dirk Wetter b242876597 Merge pull request #37 from yurivict/master
Fixed errors when COLOR=0 caused 'printf' to break due to leading dashes interpreted as command line options
2014-11-24 15:16:42 +01:00
Dirk Wetter 7cf2030c20 Merge pull request #36 from PeterMosmans/bugfix
Fixed minor redirection typo for 'which' command
2014-11-22 18:31:09 +01:00
Dirk 4c3cc0df8e - increase first read buffer -- otherwise it's how up at hb reply and lead to false positives 2014-11-20 18:55:51 +01:00
Dirk d4265742b1 color codes for protocols and default ciphers reflect better a rating
- fix: heartbleed function needed a $TMPFILE for determining the TLS protocol
 - version bumped to 2.1rc2
2014-11-20 10:46:55 +01:00
Dirk 5dd4a8f3fa - fix in cleanup (while debug)
- wrong cmd line option --> help instread of error
2014-11-19 22:23:13 +01:00
Dirk 05877dca93 - protocol check stream lined: similar now for every protocol
- NPN/SPDY is not green anymore
2014-11-19 18:04:43 +01:00
Dirk d77b667489 - protocol w/o cipher (only SSLv2 so far)
- for EVERY protocol now check whether $openssl supports it
- better fail for PFS if there are no local ciphers
2014-11-19 17:08:59 +01:00
Dirk 52ef1fe684 @oparoz 2014-11-19 13:26:48 +01:00
Dirk 99e472ac01 - banner (opensssl version build date, platform) slightly changed
- even clearer warning upon old openssl version (MacOSX!)
- oparoz hexdump patch
- heartbleed doenst do a precheck anymore --> just sockets as it may lead to false negatives
  if the client was complied with it disabled (FreeBSD)
2014-11-19 13:22:22 +01:00
Dirk f2c44803ed - FreeBSD fixes (getent, printf) 2014-11-18 23:14:17 +01:00
Dirk 59bdf48823 - Peter 2014-11-18 20:24:10 +01:00
Dirk 41a480abb4 small cleanup 2014-11-18 20:23:17 +01:00
Dirk 8756151a26 Merge branch 'master' of github.com:drwetter/testssl.sh 2014-11-18 16:40:14 +01:00
Dirk Wetter 3d6eda97de Merge pull request #30 from PeterMosmans/cleanup
Make sure that cleanup() function is always called
2014-11-18 16:39:32 +01:00
Dirk Wetter f067944f2a Merge pull request #29 from PeterMosmans/msys
Added compatilibility with MSYS2 on Windows
2014-11-18 16:30:18 +01:00
Dirk 7b45311c30 - stripping of leading 0 in testssl.sh needed to be reflected by this file 2014-11-18 11:04:57 +01:00
Dirk 049a945abc - prettyprint_local now also can do word pattern matching
- help improved
- put the stripping of leading 0 into normalize_cipher_code where it belonged
- the latter makes a modified mapping-rfc.txt necessary!
2014-11-18 11:03:03 +01:00
Dirk f45d85617b - hexcode in neat list now w/o leading 0
- help cleaned up and clearer (& removing tabs)
- test_just_one with headline
2014-11-18 10:29:11 +01:00
Dirk Wetter 2e6c0a45cd Update CREDITS.md 2014-11-17 18:59:57 +01:00
Dirk 7414b5b310 next step in color handling: 2=full color, 1: b/w, 0: no ESC codes at all 2014-11-17 18:49:56 +01:00
Dirk eee56b4bd4 2014-11-17 18:47:39 +01:00
Dirk fc4c2e5446 - omit the "**" in non colored mode
- query COLOR properly (env)
2014-11-17 17:43:59 +01:00
Dirk a7bbc6c39a warning upon "no ssl enabled server" clearer; we check only for return code of s_client. Fails if certificate needed 2014-11-17 17:05:43 +01:00
Dirk b2cd4bfd4c better documentation 2014-11-03 21:45:48 +01:00
Dirk 481af083a3 NEW: first working implementation of "-x <list_of_csv_hexcodes> server" with a catch: none a/v local cipher 2014-11-02 23:37:17 +01:00
Dirk a2cd77c4ee TLS_FALLBACK_SCSV 2014-10-30 21:15:30 +01:00
Dirk 3b783323d5 TLS_FALLBACK_SCSV 2014-10-30 21:14:50 +01:00
Dirk 5984e86f81 FIX for RUN_DIR, bumped up version to 2.1beta 2014-10-30 21:12:18 +01:00
Dirk f56f81090a NEW: HPKP 2014-10-29 21:24:43 +01:00
Dirk ef5bf00094 FIXED: too much spaces in "Local problem: No .. configured" 2014-10-23 15:52:06 +02:00
Dirk 6737cd230c FIXED: When there is no support in openssl for SSLv2 the error message and the next protocol test get on the same line 2014-10-23 15:40:15 +02:00
Dirk abef156191 Merge branch 'master' of github.com:drwetter/testssl.sh 2014-10-17 22:17:04 +02:00
Dirk 1720fed5fe be clear that no TLS_FALLBACK_SCSV support yet 2014-10-17 22:16:37 +02:00
Dirk Wetter cfc8ed1117 forgot the apple users 2014-10-17 14:28:05 +02:00
Dirk Wetter 4b6d83415b better+ c&p 2014-10-16 16:47:54 +02:00
Dirk Wetter 9714c93ee0 better c&p 2014-10-16 16:46:01 +02:00
Dirk 86e0141f72 POODLE hack 2014-10-15 13:10:06 +02:00
Dirk 192867554e - FIX for getent line 2014-10-15 11:56:40 +02:00
Dirk 5e76322840 - regression on libressl fix fdor openssl fixed 2014-10-14 16:28:18 +02:00
Dirk df06f45432 - mm: patch for libressl 2014-10-14 16:08:11 +02:00
Dirk 905e1540ab another error message suppressed (DNS) and properly handled internally 2014-10-09 11:22:23 +02:00
Dirk 08202a5768 - FIX: socket reset (ccs, hb) made formatting look not ok 2014-10-08 14:30:31 +02:00
Dirk 397b115a47 BUGFIX: socket buffer wasn't empty, could have led to false negatives 2014-10-08 13:07:12 +02:00
Dirk 4ae510650d - for seldom cases of two hsts header we don't throw an error but take the first one 2014-10-08 01:03:14 +02:00
Dirk e06251a1d3 - removed netcat dependency, availability check with bash sockets only. Should work on RH'ish distros better now 2014-10-07 12:04:21 +02:00
Dirk 7162d9448f - for clarification hint to license file 2014-10-07 11:15:05 +02:00
Dirk 723ab08258 - BUGFIX: supplying ip addresses only works again 2014-10-07 11:14:39 +02:00
Dirk Wetter e117fd9612 ALPHA version of cert checker. TO BE INTGRATED INTO testssl.sh 2014-09-25 16:54:47 +02:00
Dirk Wetter 3dee100ac2 - clearer output 2014-09-25 16:24:21 +02:00
Dirk Wetter 10aef1ad93 - this is devel, signature @ production release only 2014-09-25 16:23:41 +02:00
Dirk 455cd2fe62 - only numbers for hsts (thx to Olivier) 2014-09-24 11:17:28 +02:00
Dirk fb40dad089 - jobcontrol for heartbleed and CCS test --> no blocking anymore 2014-09-16 22:18:09 +02:00
Dirk Wetter 777f635e80 Update Readme.md 2014-09-01 10:22:48 +02:00
Dirk Wetter d04036bfad Update Readme.md 2014-09-01 10:21:48 +02:00
Dirk Wetter 75245cb8c1 Update Readme.md 2014-09-01 10:21:31 +02:00
Dirk d6e59d648a - fortezza added 2014-08-29 15:10:39 +02:00
Dirk ab42075aee - update for 0x9? 2014-08-29 15:06:05 +02:00
Dirk 7776ae2181 2014-08-29 15:03:55 +02:00
Dirk 98b7e390f1 * added ocsp stapling in server defaults test 2014-08-29 15:01:00 +02:00
Dirk b740b9872a Merge branch 'master' of github.com:drwetter/testssl.sh 2014-08-29 15:00:10 +02:00
Dirk a7fe0b48b5 * added ocsp stapling in server defaults test
* non-working prototype of testing a single cipher via hexcode
2014-08-29 14:57:20 +02:00
Dirk Wetter 6a0b8f97ba Update Readme.md 2014-07-18 22:48:46 +02:00
Dirk Wetter e8c40f8c1d 2014-07-16 19:06:26 +02:00
Dirk Wetter 93503a1b43 - except minor points now compatible to MacOSX and *BSD
- Russian GOST cipher support added
- more see CHANGELOG.txt
2014-07-16 19:04:15 +02:00
Dirk Wetter 00039e3e7c Update Readme.md
typos
2014-07-16 18:49:46 +02:00
Dirk Wetter 62da07d887 Update Readme.md
typos
2014-07-16 18:43:14 +02:00
Dirk Wetter a5daccaca5 Update Readme.md
typos
2014-07-16 18:42:43 +02:00
Dirk Wetter 4964a42b25 Update Readme.md
typos
2014-07-16 18:41:21 +02:00
Dirk Wetter d8edb06798 - 2014-07-16 18:38:23 +02:00
Dirk Wetter 599ec9c781 - delivered this patches to Peter, so no worries anymore 2014-07-16 18:36:38 +02:00
Dirk Wetter 818cd4b014 - reflects the new tree from Peter Mosmans 2014-07-16 18:35:42 +02:00
Dirk Wetter d03e8a2133 - whopping 191 ciphers now (inckl. Kerberos and GOST) 2014-07-16 18:34:31 +02:00
Dirk Wetter 0c93a531da Update Readme.md
typos
2014-07-14 20:19:03 +02:00
Dirk Wetter 8b9f66cec2 - trust rules 2014-07-04 19:24:25 +02:00
Dirk 311dfbf0d2 Delete openssl 2014-07-04 19:21:27 +02:00
Dirk Wetter ebbef07785 - typos 2014-07-04 14:37:15 +02:00
Dirk Wetter 2fe95cbe29 - typos 2014-07-04 14:15:45 +02:00
Dirk Wetter d188b1f831 - typos 2014-07-04 12:27:17 +02:00
Dirk Wetter eca6b24ab7 - typos 2014-07-04 12:24:27 +02:00
Dirk Wetter 833b253faf - formatting corrected 2014-07-04 12:15:13 +02:00
Dirk Wetter efcc03928d - new binaries with:
- chaha20+ploy1305, thx to Peter Mosmans
  - openssl starttls krb-telnet support (thx to Stefan Zehl)
  - openssl starttls xmpp starttls/sni patch (thx to Stefan Zehl)
- record breaking 167 ciphers (including kerberos)
2014-07-04 11:59:01 +02:00
Dirk Wetter 064b207488 - cosmetic stuff 2014-07-03 17:13:29 +02:00
Dirk Wetter 62d869f12e - MD rules 2014-07-03 17:08:20 +02:00
Dirk Wetter d10825053b - minor typos 2014-07-03 16:47:35 +02:00
Dirk Wetter dd3d0bef33 - older openssl bins with ~150 cipher suites. More to come soon 2014-07-03 16:38:34 +02:00
Dirk 07b363d74b Merge pull request #8 from dmitris/master
minor typos fixed
2014-07-03 13:51:39 +02:00
Dirk Wetter 9ea9f3c956 - a short one 2014-07-02 09:40:02 +02:00
Dirk Wetter 9a689bbffc - first try to commit here 2014-07-01 16:28:16 +02:00
Dirk ed895bde26 Delete README.md 2014-07-01 16:25:09 +02:00
drwt 1842d6d3aa Initial commit 2014-07-01 13:55:26 +02:00