Dirk Wetter and GitHub
bd4575e14d
Merge pull request #724 from oerdnj/2.9dev
...
Fix prln usage to outln
2017-04-25 16:27:47 +02:00
Dirk
8ea8513529
fixed in Testing server preferences --> Negotiated cipher the empty TMPfile which led to an ugly error
...
fixed in Session Resumption for tickets if no extension=no resumption: there was 1x LF too much
2017-04-24 19:18:39 +02:00
Dirk Wetter and GitHub
7a99549e80
Merge pull request #721 from dcooper16/client_simulation_wide_option
...
Add wide option for client simulations
2017-04-24 16:26:08 +02:00
Dirk
01489b9ca1
special treatment for empty serverhello for ticketbleed
2017-04-24 09:25:23 +02:00
Dirk
2db8e8e8b1
use HAS_NO_SSL2
2017-04-22 22:14:06 +02:00
Dirk
c8cd1318e9
FIX #719 , still work to do for ticketbleed ( #655 )
2017-04-22 15:39:18 +02:00
Dirk
f8e1ad0b7f
add missing #
2017-04-22 15:19:39 +02:00
Dirk
584c933493
updated user agent for sneaky
2017-04-21 11:31:42 +02:00
Dirk
7de5e0113b
check in
2017-04-21 11:29:20 +02:00
Dirk
28660f7a77
corrected pr_warningln
2017-04-20 17:29:07 +02:00
Dirk
1d992f3620
preview from clientsim branch, important to add now
2017-04-20 17:24:07 +02:00
Dirk
7c676dfc63
FIX #717 -- doubel meaning fo '-h'
2017-04-19 19:46:54 +02:00
Dirk Wetter and GitHub
869ec9b9c3
Merge pull request #685 from dcooper16/openssl_location
...
Populate OPENSSL_LOCATION in find_openssl_binary
2017-04-19 18:23:14 +02:00
Dirk Wetter and GitHub
219a07a620
Merge pull request #716 from gniltaws/2.9dev
...
Use $TESTSSL_INSTALL_DIR instead of $RUN_DIR in find_openssl_binary() - Second Try
2017-04-19 18:05:03 +02:00
Dirk Wetter and GitHub
828dda79f3
Merge pull request #715 from dcooper16/travis_check_for_html
...
Add Travis test for HTML output
2017-04-19 16:01:07 +02:00
Dirk
c4a2ba8b49
vuln count adjusted
2017-04-19 01:21:13 +02:00
Dirk Wetter and GitHub
51497c9dfb
Merge pull request #714 from drwetter/revert-712-travis_check_for_html
...
Revert "Add Travis test for HTML output"
2017-04-19 00:55:35 +02:00
Dirk Wetter and GitHub
9164230186
Revert "Add Travis test for HTML output"
2017-04-19 00:53:38 +02:00
Dirk Wetter and GitHub
5285c26759
Merge pull request #712 from dcooper16/travis_check_for_html
...
Add Travis test for HTML output
2017-04-19 00:38:27 +02:00
Dirk
9ff868b083
fix travis
2017-04-19 00:35:55 +02:00
Dirk
2469603a7f
save also 1x connect for heartbleed() by reusing a previoulsy identified protocol
2017-04-19 00:30:09 +02:00
Dirk
de79bd6b0e
implemented ticketbleed (experimental). Renamed other vulnerabilty checks to easier memorize each check:
...
-H is now --heartbleed instead of --headers,
-B is now --breach instead of --heartbleed,
-T is now --ticketbleed (was previously --breach)
bugs fix for run_ccs_injection() where the tls protocols wa not properly passed to the ClientHello
Made use of already determined protocol ( this time only from determine_optimal_proto() ) ==> we shpould use this in run_protocols() too!)
for run_ccs_injection + run_ticketbleed(). For achieving this determine_optimal_proto() needed to be modified so that it adds a protocol
to PROTOS_OFFERED (all_failed is now boolean there)
added two easy functions for converting dec to hex
sockread_fast() is for testing which should make socket erads faster -- albeit it could potentially block the whole thing
2017-04-18 23:15:32 +02:00
Dirk
ac5b9a8a78
minor polishing, correct handshake length
2017-04-18 23:06:12 +02:00
Dirk
dd9b3919fc
PoC uploaded
2017-04-16 20:38:47 +02:00
Dirk
4b833b7b6e
code readability improvements
2017-04-14 11:26:01 +02:00
Dirk Wetter and GitHub
3d8c8769a9
Merge pull request #709 from dcooper16/fix_616
...
Fix #616
2017-04-14 11:04:54 +02:00
Dirk Wetter and GitHub
0b9c04350d
Merge pull request #710 from dcooper16/debug_output_in_html
...
No debugging text in HTML output
2017-04-14 11:03:48 +02:00
Dirk Wetter and GitHub
df953dca25
Merge pull request #711 from dcooper16/color_in_headers
...
Use of color in emphasize_stuff_in_headers()
2017-04-13 22:22:59 +02:00
Dirk Wetter and GitHub
34a512a363
Merge pull request #708 from dcooper16/use_get_cipher
...
Use get_cipher() helper function
2017-04-13 16:50:42 +02:00
Dirk
5168fab693
minor polishing
2017-04-12 21:50:55 +02:00
Dirk Wetter and GitHub
d2b70f7289
Merge pull request #706 from dcooper16/fix_702
...
Fix #702
2017-04-12 21:33:36 +02:00
Dirk Wetter and GitHub
9f7ab1cef6
Merge pull request #707 from dcooper16/more_702_fixes
...
More fixes for #702
2017-04-12 21:19:17 +02:00
Dirk
036bf2e53c
revamped run_std_cipherlists(). There are now less catagories, less overlap and it's more modern:
...
NULL ciphers (no encryption)
Anonymous NULL Ciphers (no authentication)
Export ciphers (w/o ADH+NULL)
LOW: 64 Bit + DES encryption (w/o export)
Weak 128 Bit ciphers
Triple DES Ciphers (Medium)
High grade encryption
Strong grade encryption (AEAD ciphers)
2017-04-12 21:00:08 +02:00
Dirk
ed2aa6698d
comments added for #705
2017-04-11 18:48:23 +02:00
Dirk Wetter and GitHub
3820e2c25c
Merge pull request #705 from dcooper16/read_tls_data
...
Don't read tls_data.txt inside function
2017-04-11 18:40:01 +02:00
Dirk
5054cc33f3
rename *test_just_one as @AlGreed suggestted in #703
2017-04-10 14:45:39 +02:00
Dirk
0bbbd5217a
swapped -f and -s
...
-f is now forward secrecy
-s is standard cipher lists
2017-04-08 09:14:56 +02:00
Dirk
55713e4929
use per default a lf before the first fatal message
2017-04-07 10:26:41 +02:00
Dirk
c75a2cd838
In addition to #701 add quotes for correcting cmdline parsing -- especially for supplied filenames/arguments
...
(HTML,CSV,JOSN,PROXY).
Also strip off leading http:// | https:// for --proxy
2017-04-07 09:49:44 +02:00
Dirk Wetter and GitHub
dc629202bb
Merge pull request #701 from dcooper16/wordsplitting_filenames
...
Handle word splitting of log file names.
2017-04-07 08:54:07 +02:00
Dirk Wetter and GitHub
9c13d2a3a2
Merge pull request #700 from dcooper16/fix_696
...
Fix #696
2017-04-07 08:52:38 +02:00
Dirk Wetter and GitHub
46ca4b272d
Merge pull request #699 from dcooper16/fix_695
...
Fix #695
2017-04-07 08:38:52 +02:00
Dirk
e2f5d5c3cf
updated comments
2017-04-06 11:33:54 +02:00
Dirk
3351f8832c
mute the error message using bash3, see #697 (2.9dev)
2017-04-06 11:23:57 +02:00
Dirk Wetter and GitHub
c188408f8e
Merge pull request #698 from dcooper16/mass_testing_parallel
...
Mass testing in parallel
2017-04-06 10:25:38 +02:00
Dirk
8a2967c62e
make use of swapped out tls data file
...
(main() sill needs a bit of work)
2017-04-06 09:47:09 +02:00
Dirk
61d42b022c
fix missing space in banner and suppress empty version string
2017-04-05 20:39:35 +02:00
Dirk
ec55cdea14
"post-fix" for #697 (2.9dev)
2017-04-05 20:20:00 +02:00
Dirk
bfb0f4bc7d
FIX #697 in 2.9dev (bash hiccup @ tolower)
2017-04-05 17:28:06 +02:00
Dirk
b1ce11d76e
in addition to #694 : using the predefined variable
2017-04-05 14:48:35 +02:00
Dirk
6b0f389225
fix #694 (CSP and HTTP header friends were cut off @ last colon)
...
introduced strip_leading_space() / strip_trailing_space()
2017-04-05 14:42:55 +02:00
Dirk
7549f10c79
added explanation for #692
2017-04-04 20:23:28 +02:00
Dirk Wetter and GitHub
c593f06f6d
Merge pull request #692 from dcooper16/fix_html
...
Fix HTML
2017-04-04 20:18:05 +02:00
Dirk
8213e2436c
addressed #691 for 2.9dev
2017-04-04 09:54:47 +02:00
Dirk
498dda94ce
using get_san_dns_from_cert()
2017-04-01 10:38:04 +02:00
Dirk
6b601e22c7
adding Referrer-Policy header ( FIX #604 )
...
introduced get_san_dns_from_cert()
added two stub function get_session_ticket_lifetime_from_serverhello
2017-03-31 17:04:04 +02:00
Dirk Wetter and GitHub
75c794546d
Merge pull request #689 from dcooper16/run_server_defaults_cleanup
...
Cleanup variable definitions in run_server_defaults()
2017-03-31 12:53:46 +02:00
Dirk
a480e5f699
count_ciphers is now un-sed'ed, minor improvements
2017-03-31 12:24:25 +02:00
Dirk Wetter and GitHub
10ac0ffed4
Merge pull request #687 from dcooper16/child_mass_testing_env_variable
...
Child mass testing env variable
2017-03-31 08:44:15 +02:00
Dirk
7953bfda5e
correct DEBUGTIME
2017-03-29 11:17:24 +02:00
Dirk
05ea5675b8
one line per variable type
2017-03-29 10:44:22 +02:00
Dirk Wetter and GitHub
2f8bc2e77a
Merge pull request #686 from dcooper16/out_row_aligned_max_width
...
out_row_aligned_max_width()
2017-03-29 10:39:04 +02:00
Dirk
53de1dc7c4
clarified help()
2017-03-28 12:07:45 +02:00
Dirk
e2d5dc7778
part 2/2: fix for #653
2017-03-27 21:31:54 +02:00
Dirk Wetter and GitHub
7df453c7f3
Merge pull request #683 from dcooper16/missing_html_banner
...
Missing HTML banner
2017-03-27 21:12:35 +02:00
Dirk
38cf16854d
FIX #682
2017-03-27 17:35:45 +02:00
Dirk
bcc597dbab
clarify help #680
2017-03-27 11:37:18 +02:00
Dirk
c0af8b113f
FIX #680
2017-03-27 11:29:21 +02:00
Dirk
7543aa30fb
make travis mute again / introduce DEBUG_ALLINONE to use script for debug output all in one file
2017-03-27 08:59:29 +02:00
Dirk
9f1877b192
save work (still double footer, see #653 )
2017-03-27 00:54:38 +02:00
Dirk
a8b2dfec40
allow '=' after --htmlfile
2017-03-27 00:34:42 +02:00
Dirk
13ba1ce966
partly (1/2) fixing #653
2017-03-27 00:30:42 +02:00
Dirk
c281956f6e
ifix xtrace
2017-03-26 19:34:02 +02:00
Dirk
e268a1564a
* include runtime per default in "Done" banner
...
* enable better performance analysis
* minor polish
2017-03-25 19:37:30 +01:00
Dirk
10bbbd9334
minor cleanups
2017-03-25 13:23:21 +01:00
Dirk Wetter and GitHub
039b293790
Merge pull request #679 from dcooper16/std_cipherlists_debug
...
Fix std_cipherlists with debug
2017-03-25 12:36:46 +01:00
Dirk
4ae1597b2b
FIX #543
2017-03-25 12:26:08 +01:00
Dirk Wetter and GitHub
edaffc85ec
Merge pull request #674 from dcooper16/fix_client_simulation
...
Fix client simulation
2017-03-24 18:45:40 +01:00
Dirk Wetter and GitHub
3514c9d98d
Merge pull request #672 from dcooper16/minor_bugs
...
Fix two minor bugs
2017-03-24 08:00:33 +01:00
Dirk Wetter and GitHub
3879338040
Merge pull request #670 from dcooper16/client_sim_name_printing
...
Use printf to print browser names
2017-03-24 07:52:54 +01:00
Dirk
d5bb4edd80
* FIX #654 (no logfile when -file is specified)
...
* filename has now instead of just the number p+#
* minor polishing
2017-03-23 16:36:29 +01:00
Dirk Wetter and GitHub
0d511e40e4
Merge pull request #669 from dcooper16/extract_tls_extensions
...
Cleanup extraction of TLS extensions
2017-03-23 08:56:13 +01:00
Dirk
43463da4fc
improvements for performance measurements (small solution)
...
- in gerneral better performance measurements , starts from the real beginning (almost)
- allows results to put into file (MEASURE_TIME_FILE=google.txt testssl.sh google.com)
2017-03-22 16:02:48 +01:00
Dirk
27d0570fb5
- changed performance debugging options (small solution) so that the last delta is being shown
...
- PS4 improved: has now a performance debugging options (big solution)
- PS4 with proper alignment
- SCAN_TIME is now global so that it can be used not only by JSON-PRETTY (small performance debugging options uses it)
- prepare_debug() has now debugging stuff only, rest went to prepare_arrays()
2017-03-21 12:44:03 +01:00
Dirk
8c0b0083d0
further separation of data / code
2017-03-21 09:15:30 +01:00
Dirk
273361fbb9
raw time assements via env var MEASURE_TIME=true
2017-03-20 22:53:18 +01:00
Dirk
60a8e0a190
monor resorting and cosmetic improvements
2017-03-19 09:47:49 +01:00
Dirk
bb5b778ee1
update/resort
2017-03-19 09:36:19 +01:00
Dirk
73a094fcc7
FIX #648 (retrieve cipher and protocol from ServerHello) --> saves ~1 second and makes code better to read
...
other readabilty improvements
2017-03-18 22:24:35 +01:00
Dirk
8be47e484b
replace some "echo $x" by HERE statement "<<<"
2017-03-18 21:01:55 +01:00
Dirk
c618b9a954
fix CR for standard cipherlists with debug=1
2017-03-18 16:09:22 +01:00
Dirk
21a51b4ff0
Merge branch '2.9dev' of github.com:drwetter/testssl.sh into 2.9dev
2017-03-18 15:58:30 +01:00
Dirk
407c4383bf
- externalized client simulation data
...
- fixed *_fixme()
2017-03-18 15:57:16 +01:00
Dirk Wetter and GitHub
4a6c7de3b7
native HTML support
2017-03-18 15:07:02 +01:00
Dirk Wetter and GitHub
30e68311fc
Merge pull request #658 from AlGreed/2.9dev
...
Fixed #657 : Severity flag for JSON-PRETTY produces malformad JSON object
2017-03-18 13:12:40 +01:00
Dirk Wetter and GitHub
9d06b1a0f5
Merge pull request #665 from drwetter/2.9dev_html
...
merge 2.9dev_html into 2.9dev
2017-03-18 13:04:42 +01:00
Dirk
84a4fafe1e
fixed merge conflicts
2017-03-18 12:54:01 +01:00
Dirk Wetter and GitHub
71f446b170
Merge pull request #662 from dcooper16/normalize_ciphercode_html
...
Speedup normalize_ciphercode()
2017-03-17 21:20:12 +01:00
Dirk Wetter and GitHub
1c9670857b
Merge pull request #661 from dcooper16/normalize_ciphercode
...
Speedup normalize_ciphercode()
2017-03-17 21:19:23 +01:00
Dirk Wetter and GitHub
c148a93361
Merge pull request #656 from dcooper16/show_finding
...
Add spaces in show_finding()
2017-03-17 17:39:34 +01:00