Dirk Wetter and GitHub
d83f310baf
Merge pull request #872 from dcooper16/fix_871
...
Fix #871
2017-10-20 15:42:16 +02:00
Dirk
52e02d9d43
CAA work
...
This fixes #865 and improves #588 . All CAA records are now shown,
also with old DNS binaries.
2017-10-18 18:43:54 +02:00
Dirk
4b187d6253
fix travis error in 8ceb1b5
2017-10-18 17:13:05 +02:00
Dirk
8ceb1b5ad8
use bash internal functions for #864
2017-10-18 15:25:43 +02:00
Dirk Wetter and GitHub
76248493a0
Merge pull request #863 from dcooper16/run_server_preference_ssl3_bugfix
...
run_server_preference() bug fix
2017-10-18 13:42:54 +02:00
Dirk Wetter and GitHub
5b6344f6fb
Merge pull request #864 from seccubus/recursive_caa
...
Make CAA record lookups resolve the entire DNS tree (Fixes #862 )
2017-10-18 13:42:02 +02:00
Dirk Wetter and GitHub
4adc96b2f7
Merge pull request #856 from dcooper16/run_cipher_per_proto_tls13
...
Add TLSv1.3 support to run_cipher_per_proto()
2017-10-14 09:21:09 +02:00
Dirk Wetter and GitHub
ac3ff349c9
Merge pull request #859 from dcooper16/rc4
...
run_rc4() and #660
2017-10-14 09:17:19 +02:00
Dirk Wetter and GitHub
cd4009fed9
Merge pull request #854 from dcooper16/tls13_run_std_cipherlists
...
Add TLSv1.3 support for run_std_cipherlists()
2017-10-14 09:15:16 +02:00
Dirk Wetter and GitHub
22fd594334
Merge pull request #857 from dcooper16/use_bash_internal
...
Use bash internal functions
2017-10-12 11:34:20 +02:00
Dirk Wetter and GitHub
2129af0537
Merge pull request #858 from dcooper16/sweet32
...
Fix #660 for run_sweet32()
2017-10-12 10:24:34 +02:00
Dirk Wetter and GitHub
430917d59f
Merge pull request #855 from dcooper16/use_bash_string_manipulation
...
Use bash internal functions
2017-10-11 17:28:17 +02:00
Dirk Wetter and GitHub
38b2089c49
Merge pull request #853 from dcooper16/no_sock_reply_file
...
Don't maintain SOCK_REPLY_FILE in non-debug mode
2017-10-11 14:49:10 +02:00
Dirk
6bd1c26a14
FIX #851
2017-10-10 19:54:36 +02:00
Dirk Wetter and GitHub
49fcb0d724
Merge pull request #850 from dcooper16/fix_typo
...
Fix typo
2017-10-10 17:28:25 +02:00
Dirk
785e94912d
replace grep -q by internal bash operator
...
and provide the alias SETX for DEBUG_ALLINONE
2017-10-09 15:13:46 +02:00
Dirk Wetter and GitHub
985c21dfb7
Merge pull request #844 from dcooper16/has_server_protocol_fixes
...
has_server_protocol() fixes
2017-10-09 15:09:17 +02:00
Dirk Wetter and GitHub
1758d18672
Merge pull request #842 from dcooper16/tls13_part1
...
Initial support for TLSv1.3
2017-10-09 14:53:32 +02:00
Dirk
6f896a057b
add missing \n for html output
2017-10-08 22:03:29 +02:00
Dirk
e8e4609495
function safe_echo
...
In order to santize input better there's a fucntion
now which does the work . ``safe_echo()``.
It is actually the same as ``tml_out()`` but is a bit snappier.
2017-10-08 21:40:28 +02:00
Dirk Wetter and GitHub
833f724689
Merge pull request #843 from dcooper16/client_sim_data_error
...
Fix incorrect client simulation data
2017-10-04 13:05:32 +02:00
Dirk Wetter and GitHub
f1efe6b7ba
Merge pull request #833 from dcooper16/no_ossl_config
...
Suppress config file warning
2017-10-03 11:14:52 +02:00
Dirk
d5e03299e5
Merge branch '2.9dev' of github.com:drwetter/testssl.sh into 2.9dev
2017-10-02 15:19:40 +02:00
Dirk
12c47d1912
FIX #401 , first part
2017-10-02 15:18:31 +02:00
Dirk
5b294618c0
first part of #371
2017-10-02 15:11:58 +02:00
Dirk
59d4a9fa65
fix borken conflict resolving editing
2017-10-02 14:58:30 +02:00
Dirk
411accb66d
manually resolved conflict from #839 + change it to new logic
2017-10-02 14:55:57 +02:00
Dirk
f3dc53f554
Complete $PROTOS_OFFERED / has_server_protocol(), FIX #759
...
The logic is complete now, so that if a protocol has been detected as
supported or not supported it will save a few cycles not to test
this protocol again.
There's probably -- also besides #839 space for improvements. The
advantage of this solution is that ``has_server_protocol()`` also
marks a protocol as tested if the result of the test is negative.
2017-10-02 13:48:55 +02:00
Dirk Wetter and GitHub
36236b6def
Merge pull request #838 from dcooper16/remove_extra_space
...
Remove extra space in BEAST output
2017-09-28 09:12:37 +02:00
Dirk
af94d46232
minor additions wrt LibreSSL and OpenBSD
2017-09-27 09:26:36 +02:00
Dirk
e32479818d
mentioning BiGIP cookies and MongoDB
2017-09-27 09:25:22 +02:00
Dirk Wetter and GitHub
ce0a00be37
reordered features
2017-09-27 09:07:21 +02:00
Dirk Wetter and GitHub
fa5700644b
Merge pull request #837 from sdann/mongodb_detection
...
Add support for MongoDB service detection
2017-09-27 08:37:58 +02:00
Dirk Wetter and GitHub
5a6646ca98
f5 cookie
2017-09-25 22:07:40 +02:00
Dirk Wetter and GitHub
2c76025ade
Merge pull request #836 from drwetter/bigip
...
F5 cookie detection
2017-09-25 20:02:03 +02:00
Dirk
dbab397645
finalized work on integrating my f5 cookie decoder
...
see https://github.com/drwetter/F5-BIGIP-Decoder
2017-09-25 19:51:10 +02:00
Dirk
f6cf96d916
polish help for -g option
2017-09-23 12:54:44 +02:00
Dirk
68509694d4
NO_ENGINE ( #834 ) and GREASE ( #814 )
2017-09-23 11:55:09 +02:00
Dirk
4523eea398
More LibreSSL patches
...
As dcooper16 noted in #834 there are checks which test for openssl versions
but don't take LibreSSL in account. This adds checks to it for several
LibreSSL versions (>=2.1.x) which are known to support ``determine_trust()``
and it HAS_DH_BITS.
Moreover engine check has been improved. Older LibreSSL versions (2.1 specifically)
had different error messages, so the previous checks failed. There's also
a CMD_LINE flag now where one can switch the engine support off: NO_ENGINE .
run_renogo from #834 is still an open issue.
2017-09-23 11:34:37 +02:00
Dirk
695d02157a
FIX #829 (OpenBSD fixes)
...
All three issues fixed. Terminal code were actually
tow problems: Logging in from Linux with a 256 color xterm
makes tput set AF from OpenBSD hiccup. And the detection
of not-ncurses style underline e.g. was not working under OpenBSD.
The engine fix was done by David Cooper (see #831 ).
There's also a name of the binary now (OpenSSL/LibreSSL) for tracking
the flavor used.
2017-09-22 18:48:38 +02:00
Dirk
d3c3d65e1f
wording client simulation
2017-09-22 10:32:28 +02:00
Dirk
3abbddbad7
F5 cookie detection works for testcases. Output needs to be worked on
2017-09-21 10:19:47 +02:00
Dirk Wetter and GitHub
3e69304e6d
Merge pull request #828 from dcooper16/correct_typos
...
Correct typos
2017-09-20 20:06:59 +02:00
Dirk
a330fafb3b
regression fix: output for CVE-2015-3197 was missing in DROWN
2017-09-20 17:22:54 +02:00
Dirk
84c112561b
workaround due to problem with blanks in $SWURL
...
SWURL contained for historical reasons trailing blanks
for released versions.
This caused an error in pr_boldurl --> html_out which
didn't write the trailing style info and didn't close
the href tag (travis complained.)
This patch removes the trailing blank but it doesn't
fix the error.
2017-09-20 10:56:33 +02:00
Dirk
02f4f1bae1
reflect GREASE commit by David
2017-09-19 17:34:22 +02:00
Dirk Wetter and GitHub
55db191a2d
Merge pull request #814 from dcooper16/grease
...
GREASE
2017-09-19 17:24:00 +02:00
Dirk
b9b09f586e
added MS CA store, see #825
...
Finally complete, thx @naumanshah03
2017-09-19 15:15:54 +02:00
Dirk Wetter and GitHub
f48deaaa9d
Update README.md
2017-09-19 14:50:08 +02:00
Dirk
4972cda2af
FIX #762 (replace which by 'type -p')
2017-09-19 00:08:33 +02:00
Dirk
1c10ad0124
remove echoing ~ /usr/bin/timeout
2017-09-18 23:38:06 +02:00
Dirk
b222fe8f53
Merge branch '2.9dev' of github.com:drwetter/testssl.sh into 2.9dev
2017-09-18 23:34:12 +02:00
Dirk Wetter and GitHub
95af735862
Update README.md
2017-09-18 23:33:25 +02:00
Dirk Wetter and GitHub
3caa73c1b8
Update README.md
2017-09-18 23:32:35 +02:00
Dirk
bd55830a7e
FIX #823 , for jabber try PTR record first or fail
2017-09-18 23:25:07 +02:00
Dirk
f014a1853b
missing update from 985c845486
2017-09-18 23:01:37 +02:00
Dirk Wetter and GitHub
7294df927f
Merge pull request #677 from dcooper16/no_sni
...
Just get non-SNI certificate once
2017-09-18 21:14:34 +02:00
Dirk Wetter and GitHub
a395f91f0e
Merge pull request #777 from dcooper16/fix772
...
Fix #772
2017-09-18 18:36:53 +02:00
Dirk
6b1d81d28d
imor housekeeping for `fileout() in run_http_header()`
2017-09-18 18:18:05 +02:00
Dirk Wetter and GitHub
200440a28f
Merge pull request #820 from seccubus/insecure_redirect
...
Fixed file output error in case of insecure redirect
2017-09-18 18:01:43 +02:00
Dirk
f372b4b775
FIX #622
...
If the host negotiated SSLv3 reading of the ServerKeyExchange message failed
and as a consequence determination of the DH key
2017-09-18 17:50:06 +02:00
Dirk
8b076e9841
relect what to do for updtaing ca_hashes.txt
2017-09-18 14:20:56 +02:00
Dirk
985c845486
update of certificate stores, except MS
2017-09-18 14:18:00 +02:00
Dirk
26c77cc3c2
any openssl will do
2017-09-18 14:02:12 +02:00
Dirk
c4e5533ab0
FIX #822
2017-09-15 21:20:42 +02:00
Dirk
837a6fb31c
fix travis build in fad8c63
2017-09-15 15:38:11 +02:00
Dirk
fad8c631ef
consistently open the file with echo here as well
...
see CSVFILE (and request #822 )
2017-09-15 15:09:13 +02:00
Dirk Wetter and GitHub
90cd8cd3e2
Merge pull request #796 from sdann/mysql_standard_cipher
...
Catch MySQL (yaSSL) server bug when testing standard cipher categories
2017-09-15 14:02:26 +02:00
Dirk
50287ef2c4
fix for empty/malformed socket replies
...
During protocol check if a sever answered unexpected with
closing the conenction or another malformed reply the
output was not ok as DETECTED_TLS_VERSION was empty.
This fixes it by filling the variable with a string in ``parse_tls_serverhello()``
and then check in higher level (``run_protocols()``) the content.
Also it seems that I forgot in the commit from yesterday one ``&&`` to
commit in ``run_breach()``
2017-09-01 16:13:32 +02:00
Dirk
ee8c5e51a1
fix vulnerability output for breach and x509 based client auth
...
and polish output in ``run_renego()``
2017-08-31 17:22:10 +02:00
Dirk
9345b55865
added ALL_CLIENTS for client siumulation
2017-08-30 23:40:47 +02:00
Dirk Wetter
25f1293756
client simulation update
...
file renamed (dash is more consistent)
env var "ALL_CLIENTS" now shows every browser (or client) during
client simulation
2017-08-30 23:04:52 +02:00
Dirk Wetter
4379174970
rename generated file, comment it better + take care of one GREASE cipher
2017-08-30 23:02:21 +02:00
Dirk Wetter
54539e9da3
rename client simulation file (das is more consistent)
...
update client simulation: now has every client from SSLlabs and
it is properly ordered
2017-08-30 23:00:32 +02:00
Dirk Wetter
e45d80eb40
reordering of global vars, warning for client simulation of run w openssl more clear
2017-08-30 21:09:52 +02:00
Dirk Wetter
8be7dcbf09
Reorder client simulation data (see #776 ) and update README
2017-08-30 20:35:15 +02:00
Dirk Wetter and GitHub
da16b6a2e2
Merge pull request #818 from dcooper16/aria-ciphers
...
Add OpenSSL names for ARIA ciphers
2017-08-30 17:27:29 +02:00
Dirk Wetter
2b055e4425
FIX #778
...
read the session ticket lifetime and based on that emit a proper output
2017-08-30 12:54:52 +02:00
Dirk Wetter
3e2d321e68
FIX #789
2017-08-30 12:24:13 +02:00
Dirk
5f2043eb02
slight change in wording to "problem" for #817
2017-08-29 16:04:05 +02:00
Dirk Wetter and GitHub
515844208f
Merge pull request #817 from dcooper16/fileout_insert_warning
...
Use of fileout_insert_warning()
2017-08-29 16:02:29 +02:00
Dirk Wetter and GitHub
d534447da2
Merge pull request #816 from dcooper16/cipher_match_json
...
Fix single cipher and JSON pretty
2017-08-29 11:18:48 +02:00
Dirk
b5c92e9a90
renaming the id of client simul to be consistent with previously used function at least
2017-08-28 21:14:39 +02:00
Dirk
6bb3494d98
addressing @dcooper's remark in #815
2017-08-28 21:09:09 +02:00
Dirk
0933cfd041
further fixes WARNING in fileout (should be WARN)
2017-08-28 20:54:08 +02:00
Dirk
078f4a9992
Merge branch '2.9dev' of github.com:drwetter/testssl.sh into 2.9dev
2017-08-28 18:38:19 +02:00
Dirk
16dae3511e
FIX #815
...
Extra client side warning led to a non-valid JSON pretty output. This fixes
this bug by adding an extra object. The objects are named "clientProblem${NUMBER}".
By "extra client side" I mean extra warnings which are not happening during regular
tests -- those are no extra ones and should just warn with ``fileout()`` instead
of ``fileout_insert_warning()``.
Also some ``fileout arg1 WARN`` were patched: WARN is not a finding. It is just
a report that either on the client side something doesn't work as expected or
the server could not be checked during a particular test. WARNING doesn't
exist at all, WARn should be used instead.
Some lines where a warning output to JSON or CSV was missing, was added.
2017-08-28 18:25:45 +02:00
Dirk Wetter and GitHub
9f994cc9a4
Update Readme.md
2017-08-26 11:20:46 +02:00
Dirk Wetter and GitHub
5ea2b7c612
typo
2017-08-13 11:32:24 +02:00
Dirk Wetter and GitHub
484e5bef7a
Merge pull request #813 from dcooper16/update_readme
...
Update README.md for etc directory
2017-08-05 11:16:50 +02:00
Dirk Wetter and GitHub
6776a66603
Merge pull request #811 from dcooper16/certificate_transparency
...
Certificate Transparency
2017-08-03 21:55:28 +02:00
Dirk Wetter and GitHub
a81b99fd04
Merge pull request #809 from dcooper16/parse_tls_serverhello_debug_levels
...
parse_tls_serverhello(), dh_bits, debug level 2
2017-08-02 09:30:46 +02:00
Dirk
8b378ea218
FIX #808
2017-08-01 21:42:33 +02:00
Dirk
4536678b82
FIX (again) 804 and PRTG monitoring server
2017-08-01 15:37:40 +02:00
Dirk
6a4fd280bf
FIX #802
2017-08-01 13:23:21 +02:00
Dirk
9540224722
adding comments for David's PR #807 and pointing to the cipher list in #806
2017-07-31 12:59:36 +02:00
Dirk Wetter and GitHub
9c1fe0589c
Merge pull request #807 from dcooper16/fix_806
...
Fix #806
2017-07-31 12:50:19 +02:00
Dirk
4276030500
STARTTLS improvements and no protocol detections
...
- add forgotten servive FTP and XMPP
- polish other services
- after TLS 1.2 run is finished run a check whether no protocol has been detected and ask the user for confirmation to proceed
2017-07-30 22:46:17 +02:00
Dirk Wetter and GitHub
eeda1ef684
Merge pull request #805 from dcooper16/client_sim_ssl2_server
...
Client simulation and SSLv2 servers
2017-07-27 17:34:42 +02:00
Dirk Wetter and GitHub
64f6591210
Merge pull request #800 from dcooper16/fix_client_sim_sslv2
...
Fix client simulations with SSLv2 ClientHello
2017-07-27 12:58:23 +02:00