Dirk
c751e9f459
typo
2015-04-21 08:14:36 +02:00
Dirk
5bec0a16c9
- better compatibility with windows 2003 server
...
- all long options are advertised now as with dashes and not underscore
- cosmetic stuff
2015-04-20 10:05:01 +02:00
Dirk
7b6dba6369
FIX for #82
2015-04-18 23:03:16 +02:00
Dirk Wetter
3f0f489f50
Indicated freeze
2015-04-16 21:05:23 +02:00
Dirk
5625ee536e
- BUGFIX: IIS server lead to false pisitive if SSLv3 was enabled
...
(timeout was faster then socket resply)
- FIX: CORS header not labeled as green
- NEW: Now also STARTTLS works with all cmd line options and is absolutely doing the same stuff!
(integrated starttls() into parse_hn_port() )
- option --mx needed to be changed because of starttls
- regression fix: exec for socket doesn't play nice with stderr redirect
(probably bash bug)
- added some env options to cmd line as long args (--assuming-http,--ssl_native,
--color, debug, --sneaky, --warnings)
- threw away getent as it doesn't work under Linux && not network && localhost
(replaced by grep)
- SSL-POODLE is not labeled anymore experimental
- HB+CCS are called while checking STARTTLS but given a hint that its not yet supported
- added more env vars to debug output
- cleanups
2015-04-16 20:36:17 +02:00
Dirk
f682c5ceea
- FIX regression: more_flags execution was missing
...
- FIX regression: capitalized/all lowercase headers weren't detected
- if socksend is blocked (IDS) output looks better and is reported as test didn't succeed
- no secure cookie or Httponly will be marked as brown
- tput color yellow is now brown
2015-04-14 13:16:43 +02:00
Dirk
9d5168dbb5
- more robust grep >=2.20, e.g Debian 8.0 (thx @stevenb18)
...
- FIX: false positive for breach while testing google.com (referer header was hardcoded to google.com)
2015-04-14 10:15:07 +02:00
Dirk
683e9dccab
- FIX (regression): -V
...
- logic of some ENV variables changed (attention!)
- included some ENV as long options (not in the help yet)
- decentralized http check for breach
- if openssl is not executable it bails out better now
- help function now exits
2015-04-13 22:55:40 +02:00
Dirk
1043c40a60
Merge branch 'master' of github.com:drwetter/testssl.sh
2015-04-10 15:16:20 +02:00
Dirk
a12d39769f
- underline CN, SAN and issuer deutschepost case (see sourceforge.net/p/ssllabs/mailman/message/33764851/)
2015-04-10 15:15:47 +02:00
Dirk Wetter
bfcd684e19
Update Readme.md
2015-04-10 10:13:30 +02:00
Dirk Wetter
9ebf112858
Update Readme.md
2015-04-09 22:24:57 +02:00
Dirk
53e0955dfb
FIX: missing server preferences, NEW: each cipher server preferences per protocol!
2015-04-09 22:08:48 +02:00
Dirk
7f984ea83f
-
2015-04-09 21:45:22 +02:00
Dirk
a98161acc9
- fixes to changes from Peter's better cmd line parsing
...
- cosmetc improvements (vulneraibilities)
2015-04-09 21:42:52 +02:00
Dirk Wetter
eb73ffc053
Merge pull request #79 from PeterMosmans/refactoring
...
Refactored major parts of code
2015-04-09 21:38:29 +02:00
Dirk
84aca9d9a3
FIX #80 : show HTTP 401
2015-04-02 13:35:22 +02:00
Dirk
2cc56c4d1f
NEW: added security headers
2015-04-02 13:04:57 +02:00
Dirk
8da96f78f2
- got rid of "strings"
2015-04-02 12:19:24 +02:00
Dirk
4bbd19ba03
- updated binaries from Peter. Necessary because handshake under rare circumstances
...
failed (routines:tls1_setup_key_block:cipher or hash unavailable:t1_enc.c:802.
SLES 12 server, some ciphers under TLS 1.2
2015-04-02 11:46:12 +02:00
Dirk
940f51e74b
protocol check via sockets now also for SSLv3
2015-03-31 10:34:30 +02:00
Dirk
9ed58b6202
cleanups / bsd date in tls time
2015-03-30 23:09:19 +02:00
Dirk
6c30386278
rechi
2015-03-30 15:03:29 +02:00
Dirk
d9ae35fc7e
open fixes from Rechi (pull request $67)
2015-03-30 14:59:44 +02:00
Dirk Wetter
7f4fc5902e
Merge pull request #75 from feld/tr
...
Using square brackets in tr results in trying to match/replace them
2015-03-19 09:14:54 +01:00
Dirk Wetter
f4c9f692d2
Merge pull request #76 from feld/printf
...
Fix variable directly referenced in printf
2015-03-19 09:14:32 +01:00
Dirk
0d3b7f343f
Дилян
2015-03-17 22:14:05 +01:00
Dirk
2d0bfca343
- FIX for 3des cipher report (thx Дилян)
2015-03-17 22:12:25 +01:00
Dirk
ca6ca5d47e
- added two pairs of ciphers to server preference (thx Dilian)
2015-03-17 22:02:23 +01:00
Dirk
2faad9de9a
- working tls handshake with bash sockets (not yet in production, hint: see option "-q" in the bottom)
2015-03-17 18:11:18 +01:00
Dirk
c159af7f42
- check whether openssl is executable
...
- spaces to tabs
- adding hint to "aha" in help
2015-03-17 15:14:58 +01:00
Dirk
263535520f
- FIX for date --> applied to other BSD systems too
...
- FIX for SNI output as it doensn';t make sense for non HTTP servives
- lines for RC4 and PFS shortenedA
- display all MX records to test before testing
- removed LOCERR, added CCS_MAX_WAITSOCK, HEARTBLEED_MAX_WAITSOCK
2015-03-17 12:22:21 +01:00
Dirk
f8ba69f9fb
- some internal code internal cleanups
...
- minor cosmetic output corrections
- preparation for bash sockets for SSLv3 to TLS 1.2
2015-03-16 00:22:51 +01:00
Dirk
4556108a72
further improvements through shellcheck
2015-03-15 16:59:29 +01:00
Dirk
68695bbad3
FIX #74 for sed BSD: doesn't like inline \n
...
headline for BEAST was missing
2015-03-15 16:10:14 +01:00
Dirk
655944bd4d
- FIX: regression for wc -l w/o cat (3x)
...
- removal of unneccessary waitpid, inline
2015-03-15 14:41:34 +01:00
Dirk
fbd383f345
- prework for checking hpkp fingerprints
2015-03-15 10:18:37 +01:00
Dirk
5cd4b8f73e
- Shellcheck static analysis by Mark
2015-03-15 09:04:49 +01:00
Dirk Wetter
bf411d8c11
Merge pull request #73 from feld/master
...
Shellcheck static analysis
2015-03-15 08:56:01 +01:00
Dirk
b5a568da62
- @feld
2015-03-13 12:21:06 +01:00
Dirk
c1ca5a641b
- FIX garbled output for servers with a TLS reply on SSLv2 socket call
2015-03-13 12:20:19 +01:00
Dirk Wetter
74d984cebc
Merge pull request #72 from feld/feld
...
Minor optimizations to reduce unnecessary forking
2015-03-13 11:00:52 +01:00
Dirk
d8d8318f6d
FIX for #71 (proper workaround for lastpipe in rc4, pfs, and cbc)
2015-03-09 08:07:45 +01:00
Dirk
77e28922c1
- NEW: proper check for freak CVE-2015-0204
...
- NEW: check for number of keys for hpkp
- cleanup hsts+hpkp
2015-03-07 09:51:55 +01:00
Dirk
f23904b35f
- MX record: the lower the # the higher the priority (thx, rechi)
2015-03-03 07:21:30 +01:00
Dirk
77ed44207c
- see #41
2015-03-02 14:44:02 +01:00
Dirk
55e8908234
- finalize mx records, FIX : #41
2015-03-02 14:42:28 +01:00
Dirk Wetter
2614c093d7
Merge pull request #66 from Rechi/master
...
Check MX Records (#41 )
2015-03-02 14:13:33 +01:00
Dirk
37fa44cecf
- remark about rc4 rfc
2015-03-02 14:09:34 +01:00
Dirk Wetter
3f55de1483
Update Readme.md
2015-03-02 13:59:45 +01:00
Dirk
29214c7a1f
- better detection for ssl poodle
...
- change of shorticut from zero to letter o
2015-02-27 21:21:39 +01:00
Dirk Wetter
87f821e390
Merge pull request #65 from schuetzm/fix-nrsaved
...
Don't let error message slip through when no certs have been downloaded
2015-02-24 18:28:09 +01:00
Dirk Wetter
868c813055
Merge pull request #64 from PeterMosmans/spellingfix
...
FIX: minor spelling issue
2015-02-24 10:03:32 +01:00
Dirk
8aa8254c2d
- FIX #62 (CentOS 7/RHEL: engine failure), was not usable b4
2015-02-23 10:40:10 +01:00
Dirk
d0d7bb47e2
- FIXED : #47 ("double" linefeed if RFC mapping file is not present)
2015-02-22 23:05:40 +01:00
Dirk
e2448ea95d
- NEW: tells how many certificates provides (and grabs them with DEBUG=1)
...
- COLOR for no cipher order is red now
- "VULNERABLE" comes now always with "NOT ok"
2015-02-21 11:47:12 +01:00
Dirk
1be281c404
- FIXED : #38 , new openssl from Peter Mosmans makes the workaround unneccessary
2015-02-21 10:46:30 +01:00
Dirk
a255462812
- to tell the difference between the sets of binaries
2015-02-21 10:39:27 +01:00
Dirk
bacb3b69ba
- FIXED : #38 , new openssl from peter mosmans makes the workaround unneccessary
2015-02-21 10:38:04 +01:00
Dirk Wetter
cacb200049
Update Readme.md
2015-02-15 14:10:11 +01:00
Dirk
b261c1079a
- Fix #55 (302 detection for URL)
2015-02-15 14:00:13 +01:00
Dirk
f203b8b299
- Fix #46 (preload lists HPKP and HSTS)
...
- word match for includeSubDomains (useful if one specified the keyword wrong)
2015-02-15 13:37:44 +01:00
Dirk
b0a40ae1e8
- FIX #60 : mod_security CRS doesn't complain anymore
2015-02-15 13:14:11 +01:00
Dirk
ab48c66f74
- certificate sha2 fingerprint added ( #59 , @@kyhwana)
...
- sha1 fp: removed colons as long serials after it look ugly (lf)
2015-02-15 12:58:51 +01:00
Dirk
e5a015b842
- workaround for issue #58 , same in http_header
...
- FIX: if a web site returned IMAP e.g. in HTML code it may have led to the assumption IMAP is the service ;-/
2015-02-13 16:01:46 +01:00
Dirk
d15d5b0c6f
- FIX regression: CRIME check
...
- FIX: port ended up sometimes as URL part
- also if it runs http a line is displayed as confirmation that HTTP was detected
2015-02-12 13:40:53 +01:00
Dirk
db99cc8c0c
- new build with proper banner string
2015-02-12 11:12:49 +01:00
Dirk Wetter
7d6adee53f
Update Readme.md
2015-02-12 10:50:52 +01:00
Dirk Wetter
bc1cf841e3
Update Readme.md
2015-02-12 09:45:26 +01:00
Dirk
d9e4873fda
- WORKAROUND for bug in PeterMosmans OPENSSL chacha/poly version: not testing EXPORT40/EXPORT then
2015-02-12 09:32:47 +01:00
Dirk
d98aa626e7
- NEW: check for Secure Client-Initiated Renegotiation
...
- debugging #1 : PS4 and debugme
- debugging statement tmpfile_handle where missing #2
2015-02-11 09:43:04 +01:00
Dirk Wetter
c80fc50728
Update Readme.md
2015-02-10 13:18:02 +01:00
Dirk
d4c3266486
- sha2 like mozilla
2015-02-10 12:43:08 +01:00
Dirk
32ca73f982
Merge branch 'master' of github.com:drwetter/testssl.sh
2015-02-10 12:40:14 +01:00
Dirk Wetter
d5c4aca6f0
Update Readme.md
2015-02-10 12:39:54 +01:00
Dirk Wetter
30b7390654
Update Readme.md
2015-02-10 12:39:20 +01:00
Dirk Wetter
bbb832ae59
Update Readme.md
2015-02-10 12:39:02 +01:00
Dirk
1e75ac8be3
- vanilla as a workaround for bug #38
2015-02-10 12:37:03 +01:00
Dirk Wetter
80c21abcac
Update Readme.md
2015-02-10 12:34:35 +01:00
Dirk Wetter
f47b589fe9
Update Readme.md
2015-02-10 12:20:59 +01:00
Dirk Wetter
76ad830d1a
Update Readme.md
2015-02-10 12:00:02 +01:00
Dirk Wetter
2272a34557
Update Readme.md
2015-02-10 11:59:47 +01:00
Dirk
ed04b636da
- starttls for ldap now also supported
2015-02-09 14:02:02 +01:00
Dirk Wetter
0b23307683
Merge pull request #57 from schuetzm/patch-1
...
Trivial typo fix
2015-02-09 13:52:11 +01:00
Dirk Wetter
857880218d
Update Readme.md
...
Bug #38
2015-02-05 10:06:27 +01:00
Dirk Wetter
2b35b66551
Delete openssl32-1.0.2pm.chacha+poly
2015-02-05 10:02:54 +01:00
Dirk
82410b7214
- updated to 1.0.2 stable from pm
...
- still bug #38 : https://github.com/drwetter/testssl.sh/issues/38
2015-02-05 09:58:33 +01:00
Dirk
bbec58bb02
Merge branch 'master' of github.com:drwetter/testssl.sh
...
Conflicts:
openssl-bins/openssl-1.0.2-chacha.pm/openssl32-1.0.2pm-krb5.chacha+poly.asc
openssl-bins/openssl-1.0.2-chacha.pm/openssl64-1.0.2pm-krb5.chacha+poly.asc
2015-02-05 09:54:24 +01:00
Dirk
6b1d5a732b
- updated to 1.0.2 stable from pm
...
- still bug #38 : https://github.com/drwetter/testssl.sh/issues/38
2015-02-05 09:48:42 +01:00
Dirk Wetter
c4a5caadbc
Delete openssl64-1.0.2pm.chacha+poly.asc
2015-02-05 09:48:28 +01:00
Dirk Wetter
7340103bd8
Delete openssl64-1.0.2pm.chacha+poly
2015-02-05 09:48:17 +01:00
Dirk Wetter
aeeb63c694
Delete openssl64-1.0.2pm-krb5.chacha+poly.asc
2015-02-05 09:48:05 +01:00
Dirk Wetter
ef466364c3
Delete openssl32-1.0.2pm.chacha+poly.asc
2015-02-05 09:47:55 +01:00
Dirk Wetter
b7864fc05e
Delete openssl32-1.0.2pm.chacha+poly
2015-02-05 09:47:43 +01:00
Dirk Wetter
3d9bbfee02
Delete openssl32-1.0.2pm-krb5.chacha+poly.asc
2015-02-05 09:47:28 +01:00
Dirk
731e5fefb4
- updated to 1.0.2 stable from pm
...
- still bug #38 : https://github.com/drwetter/testssl.sh/issues/38
2015-02-05 09:41:56 +01:00
Dirk
711cc96172
Merge branch 'master' of github.com:drwetter/testssl.sh
2015-02-05 09:35:26 +01:00
Dirk
a41a04b36e
- updated to 1.0.2 stable from pm
...
- still bug: https://github.com/drwetter/testssl.sh/issues/38
2015-02-05 09:33:36 +01:00
Dirk Wetter
e0429cc3fe
Update Readme.md
...
new stable 1.0.2 branch, also with 4 more ciphers
2015-02-05 09:22:01 +01:00
Dirk
f30d7568e7
- checking protoype of tls sockets but not called/working yet
...
- small fixes $DEBUG
2015-02-04 09:48:34 +01:00