Commit Graph
100 Commits
Author SHA1 Message Date
Dirk Wetter c80fc50728 Update Readme.md 2015-02-10 13:18:02 +01:00
Dirk d4c3266486 - sha2 like mozilla 2015-02-10 12:43:08 +01:00
Dirk 32ca73f982 Merge branch 'master' of github.com:drwetter/testssl.sh 2015-02-10 12:40:14 +01:00
Dirk Wetter d5c4aca6f0 Update Readme.md 2015-02-10 12:39:54 +01:00
Dirk Wetter 30b7390654 Update Readme.md 2015-02-10 12:39:20 +01:00
Dirk Wetter bbb832ae59 Update Readme.md 2015-02-10 12:39:02 +01:00
Dirk 1e75ac8be3 - vanilla as a workaround for bug #38 2015-02-10 12:37:03 +01:00
Dirk Wetter 80c21abcac Update Readme.md 2015-02-10 12:34:35 +01:00
Dirk Wetter f47b589fe9 Update Readme.md 2015-02-10 12:20:59 +01:00
Dirk Wetter 76ad830d1a Update Readme.md 2015-02-10 12:00:02 +01:00
Dirk Wetter 2272a34557 Update Readme.md 2015-02-10 11:59:47 +01:00
Dirk ed04b636da - starttls for ldap now also supported 2015-02-09 14:02:02 +01:00
Dirk Wetter 0b23307683 Merge pull request #57 from schuetzm/patch-1
Trivial typo fix
2015-02-09 13:52:11 +01:00
Dirk Wetter 857880218d Update Readme.md
Bug #38
2015-02-05 10:06:27 +01:00
Dirk Wetter 2b35b66551 Delete openssl32-1.0.2pm.chacha+poly 2015-02-05 10:02:54 +01:00
Dirk 82410b7214 - updated to 1.0.2 stable from pm
- still bug #38: https://github.com/drwetter/testssl.sh/issues/38
2015-02-05 09:58:33 +01:00
Dirk bbec58bb02 Merge branch 'master' of github.com:drwetter/testssl.sh
Conflicts:
	openssl-bins/openssl-1.0.2-chacha.pm/openssl32-1.0.2pm-krb5.chacha+poly.asc
	openssl-bins/openssl-1.0.2-chacha.pm/openssl64-1.0.2pm-krb5.chacha+poly.asc
2015-02-05 09:54:24 +01:00
Dirk 6b1d5a732b - updated to 1.0.2 stable from pm
- still bug #38: https://github.com/drwetter/testssl.sh/issues/38
2015-02-05 09:48:42 +01:00
Dirk Wetter c4a5caadbc Delete openssl64-1.0.2pm.chacha+poly.asc 2015-02-05 09:48:28 +01:00
Dirk Wetter 7340103bd8 Delete openssl64-1.0.2pm.chacha+poly 2015-02-05 09:48:17 +01:00
Dirk Wetter aeeb63c694 Delete openssl64-1.0.2pm-krb5.chacha+poly.asc 2015-02-05 09:48:05 +01:00
Dirk Wetter ef466364c3 Delete openssl32-1.0.2pm.chacha+poly.asc 2015-02-05 09:47:55 +01:00
Dirk Wetter b7864fc05e Delete openssl32-1.0.2pm.chacha+poly 2015-02-05 09:47:43 +01:00
Dirk Wetter 3d9bbfee02 Delete openssl32-1.0.2pm-krb5.chacha+poly.asc 2015-02-05 09:47:28 +01:00
Dirk 731e5fefb4 - updated to 1.0.2 stable from pm
- still bug #38: https://github.com/drwetter/testssl.sh/issues/38
2015-02-05 09:41:56 +01:00
Dirk 711cc96172 Merge branch 'master' of github.com:drwetter/testssl.sh 2015-02-05 09:35:26 +01:00
Dirk a41a04b36e - updated to 1.0.2 stable from pm
- still bug: https://github.com/drwetter/testssl.sh/issues/38
2015-02-05 09:33:36 +01:00
Dirk Wetter e0429cc3fe Update Readme.md
new stable 1.0.2 branch, also with 4 more ciphers
2015-02-05 09:22:01 +01:00
Dirk f30d7568e7 - checking protoype of tls sockets but not called/working yet
- small fixes $DEBUG
2015-02-04 09:48:34 +01:00
Dirk 1b8d96f1d8 - NEW: certificate fingerprints + serial 2015-02-03 23:46:47 +01:00
Dirk d2b833b2fa - TLS 1.0/1.1 is not green anymore, only TLS 1.2 is the real one!
- no bold for 3DES and medium
- nslookup for MSYS2 etc. having no hosts (and fixing error message if host doesn't exist)
2015-02-03 23:20:59 +01:00
Dirk 188e7f9095 Merge branch 'master' of github.com:drwetter/testssl.sh 2015-01-30 16:27:27 +01:00
Dirk 4f1ca24bd2 FIX: experiration threshold < 30 days 2015-01-30 16:26:55 +01:00
Dirk Wetter 0ea64faa12 Update Readme.md 2015-01-30 10:35:07 +01:00
Dirk 85bc14c946 - FIX: STARTTLS is the criteria for using bash sslv2 or not, not the service 2015-01-29 23:24:49 +01:00
Dirk 16c804d4ca FIX: BEAST (supports higher protocols only when CBC ciphers detected)
- FIX: URL in app banner
 - cosmetic issue: display also if one cookie was issue the number 1
2015-01-29 23:20:58 +01:00
Dirk 89012a7a42 * NEW: protocol check SSLv2 in bash sockets per default (HTTP)
(fallback to openssl with SSL_NATIVE=1)
2015-01-29 10:46:16 +01:00
Dirk b2e8e0175a @nvsofts for LibreSSL patch 2015-01-29 09:34:32 +01:00
Dirk 5e864c28b4 * NEW: emphasize any numbers in http header output
* internal renaming of color functions ( --> pr_*)
* new color switches (tput)
* $COLOR is treated as integer not string
* for some issues color adjusted accordingly (red --> brown/yellow)
2015-01-29 09:33:35 +01:00
Dirk 3abaad5eb1 Merge branch 'master' of github.com:drwetter/testssl.sh 2015-01-28 15:31:13 +01:00
Dirk Wetter c01576c2d4 Merge pull request #53 from gitter-badger/gitter-badge
Add a Gitter chat badge to Readme.md
2015-01-28 09:28:50 +01:00
Dirk Wetter 5163d10a66 Merge pull request #54 from nvsofts/fix_libressl_gost
Fix GOST handling in LibreSSL
2015-01-28 09:24:32 +01:00
Dirk Wetter dedb95b122 Update Readme.md 2015-01-26 12:37:00 +01:00
Dirk d35e2f95b8 fix for wrong # of HttpOnly cookie 2015-01-23 15:09:35 +01:00
Dirk 84caf9ffd1 fix for double line and double application banner 2015-01-23 12:17:27 +01:00
Dirk f3eb84c078 Merge branch 'master' of github.com:drwetter/testssl.sh 2015-01-23 12:02:12 +01:00
Dirk baadfd0492 BREACH is not labeled as experimental anymore as it works reliably
- so is heartbleed
 - FIX: shopt is removed in rc4 as most of the bash shells segfault here (bug!)
 - not tested anymore for HTTP within starttls, instead displaying here a line
2015-01-23 12:01:32 +01:00
Dirk 6c6511ddb2 - VERBOSE -eq 1 is now DEBUG -eq 2 (VERBOSE completely removed)
- DEBUG has now four modes 1: just keep files 2: VERBOSE -eq 1 3: head hexdumps and other stuff, 4: full debugging
- env and internal stuff $TEMPDIR
2015-01-21 12:53:00 +01:00
Dirk Wetter d825bd85f7 Update Readme.md 2015-01-20 22:13:15 +01:00
Dirk 82764845f2 Merge branch 'master' of github.com:drwetter/testssl.sh 2015-01-20 22:10:22 +01:00
Dirk d5924eedc4 - BEAST finally works
- handling of spaces in output
- different ciphers
- FIX: setopt also for RC4 (proper handling of ret value)
2015-01-20 21:59:21 +01:00
Dirk 28330dc6fc first prototype BEAST | FIX: maketempf in initialize_engine | FIX: exit statements in main w/ more meaning/shorter 2015-01-20 21:51:49 +01:00
Dirk Wetter 1032c3756a Update Readme.md 2015-01-16 17:18:38 +01:00
Dirk Wetter b0c6062cb7 Update Readme.md 2015-01-16 17:16:22 +01:00
Dirk 5853202efd fine tuning on banner 2015-01-15 20:29:46 +01:00
Dirk 4c6f0d9a50 - FIX: grep -a if we hit binary content with http_header (also if otherwise specified)
- NEW: can specify URL (used for header matters and breach)
- FIX: better handling of >1 cookies
2015-01-14 12:23:53 +01:00
Dirk 3d81a7b5ec * NEW: cookie flags (experimental) [URL is missing]
* FIX: 30x handling for http_header (hint for final URL if stalled)
* FIX: proper display of app-banners if >1
2015-01-14 09:48:44 +01:00
Dirk 44d8f67998 SNI is not anymore 2do (removed misleading comment) 2015-01-12 23:28:38 +01:00
Dirk 84204a80a3 debugging more fine grained 2015-01-12 23:15:26 +01:00
Dirk ac6a67a299 now with SNI! 2015-01-12 22:56:15 +01:00
Dirk f0747dd2fc now checker fo SSLv3 to TLSV1.2
(SNI missing for now)
2015-01-10 22:08:11 +01:00
Dirk cedeff2b42 typo in tempdir led to missing gost cipher 2015-01-08 14:16:22 +01:00
Dirk 446f7bf152 working prototype for SSLv2 client hello + parsing server hello in bash 2015-01-07 23:57:16 +01:00
Dirk 62f20a6cd2 Merge branch 'master' of https://github.com/drwetter/testssl.sh 2015-01-07 23:30:24 +01:00
Dirk 5044412f39 - moved utils to separate dir 2015-01-07 23:29:05 +01:00
Dirk decade9986 safer batch processing if port isn't available 2015-01-07 23:16:45 +01:00
Dirk aa546b520e Merge remote-tracking branch 'origin/revert-48-master' 2015-01-07 23:09:57 +01:00
Dirk 8a3e0267ba safer bacth processing if port isn't available 2015-01-06 16:25:19 +01:00
Dirk Wetter 2556377398 Revert "Change question logic on non-SSL port" 2015-01-06 16:10:21 +01:00
Dirk Wetter e816e4877a Merge pull request #48 from lwindolf/master
Change question logic on non-SSL port
2015-01-06 16:01:07 +01:00
Dirk eae1b2810f - check for CN wrt SNI / no SNI
- fix different responses for CACert
2014-12-23 09:59:03 +01:00
Dirk Wetter 9e53070598 Update Readme.md 2014-12-19 15:52:05 +01:00
Dirk Wetter c2ef5d1da8 Update Readme.md 2014-12-19 15:51:32 +01:00
Dirk Wetter 5d66eeef05 Update Readme.md 2014-12-09 14:25:38 +01:00
Dirk b40c0b7178 - RELEASE: final 2.2
- change of cmd line order for STARTTLS
- help more clear
2014-12-08 10:32:51 +01:00
Dirk b3efb3c4b0 - BUGFIX: potential stalling in HTTP Header query
- BUGFIX: HTTP specific vuln. won't be checked if service is not http (we still
check crime and also spdy => gmail has spdy for pop and imap)
- Feature: service detection: HTTP, IMAP, POP, SMTP
- alignment in rDNS output corrected
- minor cleanup / improvements
2014-11-30 01:30:20 +01:00
Dirk 27f06f8d50 - BUGFIX: BSD now has proper heartbleed and ccs injection detection
- significant code improvement of hex-byte parser <-> socket sender
- BUGFIX: BSD now doesn't put an extra \n if rfc map file is missing
- bumped to 2.1rc3, hoping that'll be the last
2014-11-27 21:33:33 +01:00
Dirk c034cd8a95 - for colors: double square brackets (might save a fork to "[ or "test"
- in terms of debugging cleaned up listciphers/std_cipherlists
- in other terms too
2014-11-25 13:12:24 +01:00
Dirk Wetter 5228986b25 Update Readme.md 2014-11-24 16:43:11 +01:00
Dirk Wetter b242876597 Merge pull request #37 from yurivict/master
Fixed errors when COLOR=0 caused 'printf' to break due to leading dashes interpreted as command line options
2014-11-24 15:16:42 +01:00
Dirk Wetter 7cf2030c20 Merge pull request #36 from PeterMosmans/bugfix
Fixed minor redirection typo for 'which' command
2014-11-22 18:31:09 +01:00
Dirk 4c3cc0df8e - increase first read buffer -- otherwise it's how up at hb reply and lead to false positives 2014-11-20 18:55:51 +01:00
Dirk d4265742b1 color codes for protocols and default ciphers reflect better a rating
- fix: heartbleed function needed a $TMPFILE for determining the TLS protocol
 - version bumped to 2.1rc2
2014-11-20 10:46:55 +01:00
Dirk 5dd4a8f3fa - fix in cleanup (while debug)
- wrong cmd line option --> help instread of error
2014-11-19 22:23:13 +01:00
Dirk 05877dca93 - protocol check stream lined: similar now for every protocol
- NPN/SPDY is not green anymore
2014-11-19 18:04:43 +01:00
Dirk d77b667489 - protocol w/o cipher (only SSLv2 so far)
- for EVERY protocol now check whether $openssl supports it
- better fail for PFS if there are no local ciphers
2014-11-19 17:08:59 +01:00
Dirk 52ef1fe684 @oparoz 2014-11-19 13:26:48 +01:00
Dirk 99e472ac01 - banner (opensssl version build date, platform) slightly changed
- even clearer warning upon old openssl version (MacOSX!)
- oparoz hexdump patch
- heartbleed doenst do a precheck anymore --> just sockets as it may lead to false negatives
  if the client was complied with it disabled (FreeBSD)
2014-11-19 13:22:22 +01:00
Dirk f2c44803ed - FreeBSD fixes (getent, printf) 2014-11-18 23:14:17 +01:00
Dirk 59bdf48823 - Peter 2014-11-18 20:24:10 +01:00
Dirk 41a480abb4 small cleanup 2014-11-18 20:23:17 +01:00
Dirk 8756151a26 Merge branch 'master' of github.com:drwetter/testssl.sh 2014-11-18 16:40:14 +01:00
Dirk Wetter 3d6eda97de Merge pull request #30 from PeterMosmans/cleanup
Make sure that cleanup() function is always called
2014-11-18 16:39:32 +01:00
Dirk Wetter f067944f2a Merge pull request #29 from PeterMosmans/msys
Added compatilibility with MSYS2 on Windows
2014-11-18 16:30:18 +01:00
Dirk 7b45311c30 - stripping of leading 0 in testssl.sh needed to be reflected by this file 2014-11-18 11:04:57 +01:00
Dirk 049a945abc - prettyprint_local now also can do word pattern matching
- help improved
- put the stripping of leading 0 into normalize_cipher_code where it belonged
- the latter makes a modified mapping-rfc.txt necessary!
2014-11-18 11:03:03 +01:00
Dirk f45d85617b - hexcode in neat list now w/o leading 0
- help cleaned up and clearer (& removing tabs)
- test_just_one with headline
2014-11-18 10:29:11 +01:00
Dirk Wetter 2e6c0a45cd Update CREDITS.md 2014-11-17 18:59:57 +01:00
Dirk 7414b5b310 next step in color handling: 2=full color, 1: b/w, 0: no ESC codes at all 2014-11-17 18:49:56 +01:00
Dirk eee56b4bd4 2014-11-17 18:47:39 +01:00