Commit Graph
100 Commits
Author SHA1 Message Date
Dirk fccc24e232 - VERBOSE -eq 1 is now DEBUG -eq 2 (VERBOSE completely removed)
- DEBUG has now four modes 1: just keep files 2: VERBOSE -eq 1 3: head hexdumps and other stuff, 4: full debugging
- env and internal stuff $TEMPDIR
2015-01-21 12:53:00 +01:00
Dirk d9075f198a Merge branch 'master' of github.com:drwetter/testssl.sh 2015-01-20 22:10:22 +01:00
Dirk f0bd69ca40 - BEAST finally works
- handling of spaces in output
- different ciphers
- FIX: setopt also for RC4 (proper handling of ret value)
2015-01-20 21:59:21 +01:00
Dirk 10ea361b9c first prototype BEAST | FIX: maketempf in initialize_engine | FIX: exit statements in main w/ more meaning/shorter 2015-01-20 21:51:49 +01:00
Dirk Wetter c280d9a528 Update Readme.md 2015-01-16 17:18:38 +01:00
Dirk Wetter cc9046064c Update Readme.md 2015-01-16 17:16:22 +01:00
Dirk d129531371 fine tuning on banner 2015-01-15 20:29:46 +01:00
Dirk 4c72e059b8 - FIX: grep -a if we hit binary content with http_header (also if otherwise specified)
- NEW: can specify URL (used for header matters and breach)
- FIX: better handling of >1 cookies
2015-01-14 12:23:53 +01:00
Dirk 549d523728 * NEW: cookie flags (experimental) [URL is missing]
* FIX: 30x handling for http_header (hint for final URL if stalled)
* FIX: proper display of app-banners if >1
2015-01-14 09:48:44 +01:00
Dirk 400f06b64f SNI is not anymore 2do (removed misleading comment) 2015-01-12 23:28:38 +01:00
Dirk c8e4db1a39 debugging more fine grained 2015-01-12 23:15:26 +01:00
Dirk 16c14de324 now with SNI! 2015-01-12 22:56:15 +01:00
Dirk d5ed01a3ab now checker fo SSLv3 to TLSV1.2
(SNI missing for now)
2015-01-10 22:08:11 +01:00
Dirk 0fd4e06f21 typo in tempdir led to missing gost cipher 2015-01-08 14:16:22 +01:00
Dirk bcda178bd7 working prototype for SSLv2 client hello + parsing server hello in bash 2015-01-07 23:57:16 +01:00
Dirk 64cafd40f0 Merge branch 'master' of https://github.com/drwetter/testssl.sh 2015-01-07 23:30:24 +01:00
Dirk c01ec13e2e - moved utils to separate dir 2015-01-07 23:29:05 +01:00
Dirk 1ad9251e5e safer batch processing if port isn't available 2015-01-07 23:16:45 +01:00
Dirk 37fea08022 Merge remote-tracking branch 'origin/revert-48-master' 2015-01-07 23:09:57 +01:00
Dirk b78362e41f safer bacth processing if port isn't available 2015-01-06 16:25:19 +01:00
Dirk Wetter afa5669c89 Revert "Change question logic on non-SSL port" 2015-01-06 16:10:21 +01:00
Dirk Wetter d7d884c16e Merge pull request #48 from lwindolf/master
Change question logic on non-SSL port
2015-01-06 16:01:07 +01:00
Dirk c48944c5fb - check for CN wrt SNI / no SNI
- fix different responses for CACert
2014-12-23 09:59:03 +01:00
Dirk Wetter 70f0e3e4a4 Update Readme.md 2014-12-19 15:52:05 +01:00
Dirk Wetter 8eace3988c Update Readme.md 2014-12-19 15:51:32 +01:00
Dirk Wetter 489fbfce9e Update Readme.md 2014-12-09 14:25:38 +01:00
Dirk 8dd2425ada - RELEASE: final 2.2
- change of cmd line order for STARTTLS
- help more clear
2014-12-08 10:32:51 +01:00
Dirk 05d7047865 - BUGFIX: potential stalling in HTTP Header query
- BUGFIX: HTTP specific vuln. won't be checked if service is not http (we still
check crime and also spdy => gmail has spdy for pop and imap)
- Feature: service detection: HTTP, IMAP, POP, SMTP
- alignment in rDNS output corrected
- minor cleanup / improvements
2014-11-30 01:30:20 +01:00
Dirk e2067d1663 - BUGFIX: BSD now has proper heartbleed and ccs injection detection
- significant code improvement of hex-byte parser <-> socket sender
- BUGFIX: BSD now doesn't put an extra \n if rfc map file is missing
- bumped to 2.1rc3, hoping that'll be the last
2014-11-27 21:33:33 +01:00
Dirk ba76dad503 - for colors: double square brackets (might save a fork to "[ or "test"
- in terms of debugging cleaned up listciphers/std_cipherlists
- in other terms too
2014-11-25 13:12:24 +01:00
Dirk Wetter d948039237 Update Readme.md 2014-11-24 16:43:11 +01:00
Dirk Wetter 18cd3a7a21 Merge pull request #37 from yurivict/master
Fixed errors when COLOR=0 caused 'printf' to break due to leading dashes interpreted as command line options
2014-11-24 15:16:42 +01:00
Dirk Wetter 7649b20a0d Merge pull request #36 from PeterMosmans/bugfix
Fixed minor redirection typo for 'which' command
2014-11-22 18:31:09 +01:00
Dirk 00ff1b57a0 - increase first read buffer -- otherwise it's how up at hb reply and lead to false positives 2014-11-20 18:55:51 +01:00
Dirk 80079edf41 color codes for protocols and default ciphers reflect better a rating
- fix: heartbleed function needed a $TMPFILE for determining the TLS protocol
 - version bumped to 2.1rc2
2014-11-20 10:46:55 +01:00
Dirk db17669b99 - fix in cleanup (while debug)
- wrong cmd line option --> help instread of error
2014-11-19 22:23:13 +01:00
Dirk 9d5d77c813 - protocol check stream lined: similar now for every protocol
- NPN/SPDY is not green anymore
2014-11-19 18:04:43 +01:00
Dirk ab7074aefd - protocol w/o cipher (only SSLv2 so far)
- for EVERY protocol now check whether $openssl supports it
- better fail for PFS if there are no local ciphers
2014-11-19 17:08:59 +01:00
Dirk 9fe6b9a917 @oparoz 2014-11-19 13:26:48 +01:00
Dirk 93c05e9d12 - banner (opensssl version build date, platform) slightly changed
- even clearer warning upon old openssl version (MacOSX!)
- oparoz hexdump patch
- heartbleed doenst do a precheck anymore --> just sockets as it may lead to false negatives
  if the client was complied with it disabled (FreeBSD)
2014-11-19 13:22:22 +01:00
Dirk 6a0e41d252 - FreeBSD fixes (getent, printf) 2014-11-18 23:14:17 +01:00
Dirk 30a0f1abf7 - Peter 2014-11-18 20:24:10 +01:00
Dirk 4a5de4fd72 small cleanup 2014-11-18 20:23:17 +01:00
Dirk 6b8b63b4a5 Merge branch 'master' of github.com:drwetter/testssl.sh 2014-11-18 16:40:14 +01:00
Dirk Wetter 3abb5a0650 Merge pull request #30 from PeterMosmans/cleanup
Make sure that cleanup() function is always called
2014-11-18 16:39:32 +01:00
Dirk Wetter 68eddd7226 Merge pull request #29 from PeterMosmans/msys
Added compatilibility with MSYS2 on Windows
2014-11-18 16:30:18 +01:00
Dirk b50cba45dc - stripping of leading 0 in testssl.sh needed to be reflected by this file 2014-11-18 11:04:57 +01:00
Dirk abb57e8bde - prettyprint_local now also can do word pattern matching
- help improved
- put the stripping of leading 0 into normalize_cipher_code where it belonged
- the latter makes a modified mapping-rfc.txt necessary!
2014-11-18 11:03:03 +01:00
Dirk 730656bbbb - hexcode in neat list now w/o leading 0
- help cleaned up and clearer (& removing tabs)
- test_just_one with headline
2014-11-18 10:29:11 +01:00
Dirk Wetter 23a7f0a289 Update CREDITS.md 2014-11-17 18:59:57 +01:00
Dirk 9c35c200b7 next step in color handling: 2=full color, 1: b/w, 0: no ESC codes at all 2014-11-17 18:49:56 +01:00
Dirk 7eafd76fa7 2014-11-17 18:47:39 +01:00
Dirk ee1f7ceedd - omit the "**" in non colored mode
- query COLOR properly (env)
2014-11-17 17:43:59 +01:00
Dirk b0a4345e6c warning upon "no ssl enabled server" clearer; we check only for return code of s_client. Fails if certificate needed 2014-11-17 17:05:43 +01:00
Dirk 2b009d6ac5 better documentation 2014-11-03 21:45:48 +01:00
Dirk d956a53628 NEW: first working implementation of "-x <list_of_csv_hexcodes> server" with a catch: none a/v local cipher 2014-11-02 23:37:17 +01:00
Dirk 2a2d962874 TLS_FALLBACK_SCSV 2014-10-30 21:15:30 +01:00
Dirk a31d96abea TLS_FALLBACK_SCSV 2014-10-30 21:14:50 +01:00
Dirk d2ff6eaf25 FIX for RUN_DIR, bumped up version to 2.1beta 2014-10-30 21:12:18 +01:00
Dirk 365796007c NEW: HPKP 2014-10-29 21:24:43 +01:00
Dirk 1a2dc2bdc8 FIXED: too much spaces in "Local problem: No .. configured" 2014-10-23 15:52:06 +02:00
Dirk f7c2f0c196 FIXED: When there is no support in openssl for SSLv2 the error message and the next protocol test get on the same line 2014-10-23 15:40:15 +02:00
Dirk e6e52cf1fd Merge branch 'master' of github.com:drwetter/testssl.sh 2014-10-17 22:17:04 +02:00
Dirk 52ad39144f be clear that no TLS_FALLBACK_SCSV support yet 2014-10-17 22:16:37 +02:00
Dirk Wetter ac6d02b5cf forgot the apple users 2014-10-17 14:28:05 +02:00
Dirk Wetter b901c4e86d better+ c&p 2014-10-16 16:47:54 +02:00
Dirk Wetter dba5ef1ff8 better c&p 2014-10-16 16:46:01 +02:00
Dirk 9e8cd27e46 POODLE hack 2014-10-15 13:10:06 +02:00
Dirk 3be53fc1ec - FIX for getent line 2014-10-15 11:56:40 +02:00
Dirk d047a063cf - regression on libressl fix fdor openssl fixed 2014-10-14 16:28:18 +02:00
Dirk c3a7023782 - mm: patch for libressl 2014-10-14 16:08:11 +02:00
Dirk bc2ef40a0e another error message suppressed (DNS) and properly handled internally 2014-10-09 11:22:23 +02:00
Dirk e88561a2a6 - FIX: socket reset (ccs, hb) made formatting look not ok 2014-10-08 14:30:31 +02:00
Dirk 4ed226621b BUGFIX: socket buffer wasn't empty, could have led to false negatives 2014-10-08 13:07:12 +02:00
Dirk 11f9411f50 - for seldom cases of two hsts header we don't throw an error but take the first one 2014-10-08 01:03:14 +02:00
Dirk 52ee5415d1 - removed netcat dependency, availability check with bash sockets only. Should work on RH'ish distros better now 2014-10-07 12:04:21 +02:00
Dirk 21c7abd10d - for clarification hint to license file 2014-10-07 11:15:05 +02:00
Dirk 4dd03a56b9 - BUGFIX: supplying ip addresses only works again 2014-10-07 11:14:39 +02:00
Dirk Wetter 2a9e6ec3a2 ALPHA version of cert checker. TO BE INTGRATED INTO testssl.sh 2014-09-25 16:54:47 +02:00
Dirk Wetter 84af820830 - clearer output 2014-09-25 16:24:21 +02:00
Dirk Wetter b1d7ed0329 - this is devel, signature @ production release only 2014-09-25 16:23:41 +02:00
Dirk 2a5b5e97dc - only numbers for hsts (thx to Olivier) 2014-09-24 11:17:28 +02:00
Dirk 58cca3ddb9 - jobcontrol for heartbleed and CCS test --> no blocking anymore 2014-09-16 22:18:09 +02:00
Dirk Wetter 58398ec954 Update Readme.md 2014-09-01 10:22:48 +02:00
Dirk Wetter 10db86bd5c Update Readme.md 2014-09-01 10:21:48 +02:00
Dirk Wetter 978f1e1985 Update Readme.md 2014-09-01 10:21:31 +02:00
Dirk df7ee3ce3c - fortezza added 2014-08-29 15:10:39 +02:00
Dirk ed152cd4f2 - update for 0x9? 2014-08-29 15:06:05 +02:00
Dirk 5433272e2a 2014-08-29 15:03:55 +02:00
Dirk 7deabada6d * added ocsp stapling in server defaults test 2014-08-29 15:01:00 +02:00
Dirk 91c1ed2f69 Merge branch 'master' of github.com:drwetter/testssl.sh 2014-08-29 15:00:10 +02:00
Dirk 6aeec03427 * added ocsp stapling in server defaults test
* non-working prototype of testing a single cipher via hexcode
2014-08-29 14:57:20 +02:00
Dirk Wetter a652385310 Update Readme.md 2014-07-18 22:48:46 +02:00
Dirk Wetter cb9c0b3b85 2014-07-16 19:06:26 +02:00
Dirk Wetter 41466d2f99 - except minor points now compatible to MacOSX and *BSD
- Russian GOST cipher support added
- more see CHANGELOG.txt
2014-07-16 19:04:15 +02:00
Dirk Wetter 90074b5764 Update Readme.md
typos
2014-07-16 18:49:46 +02:00
Dirk Wetter 8d27ef3ea3 Update Readme.md
typos
2014-07-16 18:43:14 +02:00
Dirk Wetter f5204c3163 Update Readme.md
typos
2014-07-16 18:42:43 +02:00
Dirk Wetter 2e9673de94 Update Readme.md
typos
2014-07-16 18:41:21 +02:00
Dirk Wetter f54e68576d - 2014-07-16 18:38:23 +02:00