Dirk
c5ac8c9227
workaround due to problem with blanks in $SWURL
...
SWURL contained for historical reasons trailing blanks
for released versions.
This caused an error in pr_boldurl --> html_out which
didn't write the trailing style info and didn't close
the href tag (travis complained.)
This patch removes the trailing blank but it doesn't
fix the error
2017-09-20 10:47:18 +02:00
Dirk
11b4f67d7e
version number
2017-09-20 07:11:11 +02:00
Dirk Wetter and GitHub
f9c72ea85e
Update Readme.md
2017-09-19 16:22:09 +02:00
Dirk
11d7645754
changed for 2.9.5
2017-09-19 16:13:38 +02:00
Dirk
b9b09f586e
added MS CA store, see #825
...
Finally complete, thx @naumanshah03
2017-09-19 15:15:54 +02:00
Dirk Wetter and GitHub
f48deaaa9d
Update README.md
2017-09-19 14:50:08 +02:00
Dirk
4972cda2af
FIX #762 (replace which by 'type -p')
2017-09-19 00:08:33 +02:00
Dirk
1c10ad0124
remove echoing ~ /usr/bin/timeout
2017-09-18 23:38:06 +02:00
Dirk
b222fe8f53
Merge branch '2.9dev' of github.com:drwetter/testssl.sh into 2.9dev
2017-09-18 23:34:12 +02:00
Dirk Wetter and GitHub
95af735862
Update README.md
2017-09-18 23:33:25 +02:00
Dirk Wetter and GitHub
3caa73c1b8
Update README.md
2017-09-18 23:32:35 +02:00
Dirk
bd55830a7e
FIX #823 , for jabber try PTR record first or fail
2017-09-18 23:25:07 +02:00
Dirk
f014a1853b
missing update from 985c845486
2017-09-18 23:01:37 +02:00
Dirk Wetter and GitHub
7294df927f
Merge pull request #677 from dcooper16/no_sni
...
Just get non-SNI certificate once
2017-09-18 21:14:34 +02:00
Dirk Wetter and GitHub
a395f91f0e
Merge pull request #777 from dcooper16/fix772
...
Fix #772
2017-09-18 18:36:53 +02:00
Dirk
6b1d81d28d
imor housekeeping for `fileout() in run_http_header()`
2017-09-18 18:18:05 +02:00
Dirk Wetter and GitHub
200440a28f
Merge pull request #820 from seccubus/insecure_redirect
...
Fixed file output error in case of insecure redirect
2017-09-18 18:01:43 +02:00
Dirk
f372b4b775
FIX #622
...
If the host negotiated SSLv3 reading of the ServerKeyExchange message failed
and as a consequence determination of the DH key
2017-09-18 17:50:06 +02:00
Dirk
8b076e9841
relect what to do for updtaing ca_hashes.txt
2017-09-18 14:20:56 +02:00
Dirk
985c845486
update of certificate stores, except MS
2017-09-18 14:18:00 +02:00
Dirk
26c77cc3c2
any openssl will do
2017-09-18 14:02:12 +02:00
Dirk
c4e5533ab0
FIX #822
2017-09-15 21:20:42 +02:00
Dirk
837a6fb31c
fix travis build in fad8c63
2017-09-15 15:38:11 +02:00
Dirk
fad8c631ef
consistently open the file with echo here as well
...
see CSVFILE (and request #822 )
2017-09-15 15:09:13 +02:00
Dirk Wetter and GitHub
90cd8cd3e2
Merge pull request #796 from sdann/mysql_standard_cipher
...
Catch MySQL (yaSSL) server bug when testing standard cipher categories
2017-09-15 14:02:26 +02:00
Dirk
50287ef2c4
fix for empty/malformed socket replies
...
During protocol check if a sever answered unexpected with
closing the conenction or another malformed reply the
output was not ok as DETECTED_TLS_VERSION was empty.
This fixes it by filling the variable with a string in ``parse_tls_serverhello()``
and then check in higher level (``run_protocols()``) the content.
Also it seems that I forgot in the commit from yesterday one ``&&`` to
commit in ``run_breach()``
2017-09-01 16:13:32 +02:00
Dirk
ee8c5e51a1
fix vulnerability output for breach and x509 based client auth
...
and polish output in ``run_renego()``
2017-08-31 17:22:10 +02:00
Dirk
9345b55865
added ALL_CLIENTS for client siumulation
2017-08-30 23:40:47 +02:00
Dirk Wetter
25f1293756
client simulation update
...
file renamed (dash is more consistent)
env var "ALL_CLIENTS" now shows every browser (or client) during
client simulation
2017-08-30 23:04:52 +02:00
Dirk Wetter
4379174970
rename generated file, comment it better + take care of one GREASE cipher
2017-08-30 23:02:21 +02:00
Dirk Wetter
54539e9da3
rename client simulation file (das is more consistent)
...
update client simulation: now has every client from SSLlabs and
it is properly ordered
2017-08-30 23:00:32 +02:00
Dirk Wetter
e45d80eb40
reordering of global vars, warning for client simulation of run w openssl more clear
2017-08-30 21:09:52 +02:00
Dirk Wetter
8be7dcbf09
Reorder client simulation data (see #776 ) and update README
2017-08-30 20:35:15 +02:00
Dirk Wetter and GitHub
da16b6a2e2
Merge pull request #818 from dcooper16/aria-ciphers
...
Add OpenSSL names for ARIA ciphers
2017-08-30 17:27:29 +02:00
Dirk Wetter
2b055e4425
FIX #778
...
read the session ticket lifetime and based on that emit a proper output
2017-08-30 12:54:52 +02:00
Dirk Wetter
3e2d321e68
FIX #789
2017-08-30 12:24:13 +02:00
Dirk
5f2043eb02
slight change in wording to "problem" for #817
2017-08-29 16:04:05 +02:00
Dirk Wetter and GitHub
515844208f
Merge pull request #817 from dcooper16/fileout_insert_warning
...
Use of fileout_insert_warning()
2017-08-29 16:02:29 +02:00
Dirk Wetter and GitHub
d534447da2
Merge pull request #816 from dcooper16/cipher_match_json
...
Fix single cipher and JSON pretty
2017-08-29 11:18:48 +02:00
Dirk
b5c92e9a90
renaming the id of client simul to be consistent with previously used function at least
2017-08-28 21:14:39 +02:00
Dirk
6bb3494d98
addressing @dcooper's remark in #815
2017-08-28 21:09:09 +02:00
Dirk
0933cfd041
further fixes WARNING in fileout (should be WARN)
2017-08-28 20:54:08 +02:00
Dirk
078f4a9992
Merge branch '2.9dev' of github.com:drwetter/testssl.sh into 2.9dev
2017-08-28 18:38:19 +02:00
Dirk
16dae3511e
FIX #815
...
Extra client side warning led to a non-valid JSON pretty output. This fixes
this bug by adding an extra object. The objects are named "clientProblem${NUMBER}".
By "extra client side" I mean extra warnings which are not happening during regular
tests -- those are no extra ones and should just warn with ``fileout()`` instead
of ``fileout_insert_warning()``.
Also some ``fileout arg1 WARN`` were patched: WARN is not a finding. It is just
a report that either on the client side something doesn't work as expected or
the server could not be checked during a particular test. WARNING doesn't
exist at all, WARn should be used instead.
Some lines where a warning output to JSON or CSV was missing, was added.
2017-08-28 18:25:45 +02:00
Dirk Wetter and GitHub
9f994cc9a4
Update Readme.md
2017-08-26 11:20:46 +02:00
Dirk Wetter and GitHub
5ea2b7c612
typo
2017-08-13 11:32:24 +02:00
Dirk Wetter and GitHub
484e5bef7a
Merge pull request #813 from dcooper16/update_readme
...
Update README.md for etc directory
2017-08-05 11:16:50 +02:00
Dirk Wetter and GitHub
6776a66603
Merge pull request #811 from dcooper16/certificate_transparency
...
Certificate Transparency
2017-08-03 21:55:28 +02:00
Dirk Wetter and GitHub
a81b99fd04
Merge pull request #809 from dcooper16/parse_tls_serverhello_debug_levels
...
parse_tls_serverhello(), dh_bits, debug level 2
2017-08-02 09:30:46 +02:00
Dirk
8b378ea218
FIX #808
2017-08-01 21:42:33 +02:00
Dirk
4536678b82
FIX (again) 804 and PRTG monitoring server
2017-08-01 15:37:40 +02:00
Dirk
6a4fd280bf
FIX #802
2017-08-01 13:23:21 +02:00
Dirk
9540224722
adding comments for David's PR #807 and pointing to the cipher list in #806
2017-07-31 12:59:36 +02:00
Dirk Wetter and GitHub
9c1fe0589c
Merge pull request #807 from dcooper16/fix_806
...
Fix #806
2017-07-31 12:50:19 +02:00
Dirk
4276030500
STARTTLS improvements and no protocol detections
...
- add forgotten servive FTP and XMPP
- polish other services
- after TLS 1.2 run is finished run a check whether no protocol has been detected and ask the user for confirmation to proceed
2017-07-30 22:46:17 +02:00
Dirk Wetter and GitHub
eeda1ef684
Merge pull request #805 from dcooper16/client_sim_ssl2_server
...
Client simulation and SSLv2 servers
2017-07-27 17:34:42 +02:00
Dirk Wetter and GitHub
64f6591210
Merge pull request #800 from dcooper16/fix_client_sim_sslv2
...
Fix client simulations with SSLv2 ClientHello
2017-07-27 12:58:23 +02:00
Dirk
8b2dfb81c5
reflect 37c8ee8c4e: debug level 2 is showing only minimal information like rough status and errors
2017-07-26 23:13:57 +02:00
Dirk
37c8ee8c4e
Straigthen DEBUG level 2
...
FIX #786
Fixed all other occurences so that debug level 2 is showing only minimal information like rough status and errors
Better line breaks for level 2
In ``client_simulation_sockets()`` and ``tls_sockets()`` moved debug output into if statements (may save a bit of time)
Replaced "$DEBUG -eq" by "$DEBUG -ge"
Removed obsolete hb_rounds in ``run_heartbleed()``
Adjusted wide output in vulnerabilities
2017-07-26 22:37:50 +02:00
Dirk
2932e1f29e
FIX #798
2017-07-26 09:55:49 +02:00
Dirk
d783bd5856
reminder after #759 has been addressed
2017-07-25 21:53:05 +02:00
Dirk Wetter and GitHub
b60e25fbea
Merge pull request #801 from dcooper16/std_cipherlists_has_server_protocol
...
std_cipherlists() and has_server_protocol()
2017-07-25 21:48:52 +02:00
Dirk
512cb81325
typo in comment for run_std_cipherlists()
2017-07-25 20:38:02 +02:00
Dirk Wetter and GitHub
468e96f419
Merge pull request #787 from sdann/fix_has_server_protocol
...
Fix logic in has_server_protocol()
2017-07-25 16:27:36 +02:00
Dirk
b7f4b23c23
commenting #797
2017-07-25 16:19:36 +02:00
Dirk Wetter and GitHub
007d54fa26
Merge pull request #797 from dcooper16/yaSSL_client_simulation
...
yaSSL and client simulation
2017-07-25 16:15:29 +02:00
Dirk
3adb5ac71f
Logic for POODLE && TLS_FALLBACK_SCSV
...
If vulnernable to POODLE and has no TLS_FALLBACK_SCSV ==> HIGH.
If only run the fallback check and it has none, still label it as MEDIUM but issue
a clear warning that test under this circumstances is incomplete.
2017-07-25 10:54:01 +02:00
Dirk
615a93e69e
in html mode the sed statement for the server banner had and error resulting in sed messages like "unknown option to s"
2017-07-22 20:57:32 +02:00
Dirk
4e3b2318ab
FIX #795 awk had word match, didn't work and wasn't needed
...
If certicate was determined before running dorwn, we needed to remove "SHA256 " (regression)
2017-07-20 19:13:06 +02:00
Dirk
baeca77021
drown additions
...
* also provide links to censys.io if there's drown detected
* remove SHOW_CENSYS_LINK variable
* calculate fingerprint upfront (if not done yet)
2017-07-20 17:44:00 +02:00
Dirk
ad1dd01466
polishing #784 and #788
...
Also introduced the global BAD_SERVER_HELLO_CIPHER which can be later used
for notifying crappy cipher negotiations
2017-07-19 18:46:46 +02:00
Dirk Wetter and GitHub
fc7a89e659
Merge pull request #788 from sdann/mysql_ccs_injection
...
Fix CCS Injection detection for MySQL (yaSSL)
2017-07-19 18:37:51 +02:00
Dirk Wetter and GitHub
cc5d8a708e
Merge pull request #792 from dcooper16/last_extension_not_empty
...
Make sure last ClientHello extension is not empty
2017-07-19 17:33:31 +02:00
Dirk Wetter and GitHub
507e59dc97
Update CREDITS.md
2017-07-13 14:02:33 +02:00
Dirk Wetter and GitHub
17513abfe8
Update CREDITS.md
2017-07-13 14:00:41 +02:00
Dirk Wetter and GitHub
fb6901a792
Update Readme.md
2017-07-13 13:56:14 +02:00
Dirk Wetter and GitHub
dc0db33588
Installation section and polish
2017-07-13 13:55:22 +02:00
Dirk
9d1e7d1f29
Merge branch '2.9dev' of github.com:drwetter/testssl.sh into 2.9dev
2017-07-13 12:37:52 +02:00
Dirk
28fe4c48de
manpage not for editing
...
Generated via ``ronn -r testssl.1.md`` from the md source. Can be viewed
e.g. by ``nroff -man testssl.1 [| less]``
2017-07-13 12:35:13 +02:00
Dirk
f2d07ec22b
First draft of the manpage
...
Until the content is finalized the plan is to keep it in MD format.
For medium terms it is something which needs to be reconsidered
as markdown as the source format for documentation has too many limits.
Happy for suggestions here.
In the meantime here's what needs to be done:
* finalizing (see comments)
* proofreading 1: accuracy, logic, more content related
* proofreading 2: grammar, spelling
* more? pls let me know
2017-07-13 12:27:28 +02:00
Dirk Wetter and GitHub
7339e43b18
Merge pull request #784 from dcooper16/fix_782
...
Handle server returning unsupported cipher
2017-07-13 09:15:07 +02:00
Dirk Wetter and GitHub
413751c806
Merge pull request #785 from dcooper16/parse_tls_serverhello_bugfix
...
Remove extra line break in debugging output
2017-07-13 09:10:30 +02:00
Dirk Wetter and GitHub
9244f2c83c
Merge pull request #783 from sdann/mysql_starttls
...
Add mysql (sockets) starttls support
2017-07-12 09:32:31 +02:00
Dirk Wetter and GitHub
bddf5b2404
Merge pull request #775 from dcooper16/hpkp_bugfix
...
run_hpkp() bug fix
2017-07-11 23:21:51 +02:00
Dirk
deb7fd52a9
making some socket timeouts configurable through ENV, thus synching it with the documentation
2017-07-11 10:03:33 +02:00
Dirk
637812a022
bali out if both flat and pretty JSON outout was specified
2017-07-10 10:57:48 +02:00
Dirk
bc0c1dc553
FIX #779
2017-07-06 13:02:27 +02:00
Dirk Wetter and GitHub
7aaadf731c
Merge pull request #773 from sdann/postgres_cleanup
...
Postgres cleanup
2017-07-01 10:43:05 +02:00
Dirk Wetter and GitHub
4cb48a1399
Merge branch '2.9dev' into postgres_cleanup
2017-07-01 10:25:28 +02:00
Dirk
02488884bb
added experimental label for MySQL STARTTLS protocol
2017-07-01 10:11:34 +02:00
Dirk Wetter and GitHub
152c5c225c
Merge pull request #774 from sdann/mysql_starttls
...
Add mysql (openssl) starttls support
2017-07-01 10:05:05 +02:00
Dirk
2d007e4c8b
increased verbosity for some standard cipher lists
2017-06-29 17:58:58 +02:00
Dirk
62ce04adf0
remove redundant option "false" in --warnings
2017-06-28 20:28:23 +02:00
Dirk
9d699d1248
straighten server header markup
2017-06-22 13:39:37 +02:00
Dirk
ff63700c6e
add few more header flags, work on #765
2017-06-20 23:18:15 +02:00
Dirk
4cb435a549
added several insecurity headers
2017-06-20 11:31:22 +02:00
Dirk
f53c3c1377
removed separate option for SPDY and HTTP/2 , addressing #767
2017-06-20 08:43:35 +02:00
Dirk
4c73afeef8
fix for nmap file parser (not properly assigned ip variable)
2017-06-14 09:24:20 +02:00
Dirk
7094c4436f
also now honor different ports per host from nmap file.
...
testssl.sh is taking an educated guess which port makes sense to scan,
which one not and for which one to use which starttls handshake upfront.
This minimizes needless sscans and error messages.
2017-06-13 18:42:07 +02:00
Dirk
531b4453ef
new function for guessing "port --> invoking" assignments
2017-06-13 15:19:28 +02:00