Commit Graph

  • 8d812f5dc0 Merge pull request #1764 from keisentraut/fix-1762 Dirk Wetter 2020-11-02 21:46:51 +01:00
  • 5949a0465a fix #1762: X-XSS-Protection is rated as INFO, fixed bug introduced in last commit Klaus Eisentraut 2020-11-02 19:58:49 +01:00
  • 6f3c957fe7 fix #1762: Stop labeling X-XSS-Protection as green Klaus Eisentraut 2020-10-30 22:45:16 +01:00
  • f3abf77ed8 Merge pull request #1761 from keisentraut/fix-1757-3.0 Dirk Wetter 2020-10-29 20:28:23 +01:00
  • e3cd36a63b Merge pull request #1760 from keisentraut/fix-1757 Dirk Wetter 2020-10-29 20:27:19 +01:00
  • 44fd73bfcd fix #1757: manpage: --c has one dash to much (backport 3.0) Klaus Eisentraut 2020-10-29 20:21:05 +01:00
  • d130d70e8b fix #1757: manpage: --c has one dash to much Klaus Eisentraut 2020-10-29 20:05:44 +01:00
  • 0cf5a49762 Merge pull request #1759 from drwetter/fix_1754_3.0 Dirk Wetter 2020-10-28 15:05:51 +01:00
  • 3c97412a61 Address complaint by Travis + RC4 SSLv2 ciphers shortcut Dirk Wetter 2020-10-28 11:45:41 +01:00
  • 084a29409d Merge pull request #1758 from drwetter/fix_1754 Dirk Wetter 2020-10-28 11:43:30 +01:00
  • faad7128a7 If we are sure we don't have sslv2 we don't need to test any RC4 SSLv2 ciphers Dirk Wetter 2020-10-28 10:13:22 +01:00
  • 3cd1273439 Address complaint by Travis Dirk Wetter 2020-10-28 09:52:10 +01:00
  • 4ddc90d98d Fix run_freak() when sslv2 server hello is empty (3.0 branch) Dirk 2020-10-27 22:48:50 +01:00
  • 888f4f9c5a Fix run_freak() when sslv2 server hello is empty Dirk 2020-10-27 22:36:42 +01:00
  • d531981e31 Merge pull request #1756 from drwetter/fix_1755 Dirk Wetter 2020-10-26 21:45:41 +01:00
  • 45b5d7a5d8 Fix issue with host certificate expiration Dirk 2020-10-26 21:32:09 +01:00
  • 4af901683a Merge pull request #1751 from tosticated/ssl_renego_mod Dirk Wetter 2020-10-20 21:00:02 +02:00
  • 45059ed769 Merge branch '3.1dev' into ssl_renego_mod tosticated 2020-10-20 19:40:58 +02:00
  • 3e2d1b943d Fixed whitespaces/tabs tosticated 2020-10-20 13:03:30 +02:00
  • 1049fe2330 Merge pull request #1749 from definity/3.1dev Dirk Wetter 2020-10-20 11:34:39 +02:00
  • a252eeb11d Updated changelog j 2020-10-19 22:37:10 +02:00
  • e82d4e07ca Modified ssl renegotiation attempts to be variable, and default 6. j 2020-10-19 22:12:59 +02:00
  • 4d6dba79e6 Update man pages and CHANGELOG Chad Brigance 2020-10-19 07:32:41 +00:00
  • e51301d9ee Merge pull request #1748 from definity/3.1dev Dirk Wetter 2020-10-17 17:04:49 +02:00
  • 59c24e33b0 fixed missing <user agent> in help text Chad Brigance 2020-10-16 19:29:54 +00:00
  • 11b30b9335 Added support for custom user agent Chad Brigance 2020-10-16 15:35:46 +00:00
  • b873441238 Merge pull request #1746 from horazont/feature/xmpp-sni Dirk Wetter 2020-10-16 09:34:45 +02:00
  • 769837bdaf Force SNI to be the --xmpphost if passed Jonas Schäfer 2020-10-15 21:54:38 +02:00
  • b4c9437e95 Merge pull request #1741 from drwetter/intermediate_cert_improvements Dirk Wetter 2020-10-03 10:21:31 +02:00
  • 4ca4e075a2 Use test::diff so that errors are spotted better Dirk 2020-10-02 13:07:13 +02:00
  • c3f8207d93 Fix Travis + mv issuer line down Dirk 2020-10-02 13:00:21 +02:00
  • d5a64ff4b6 Further improvements to intermediate certs Dirk 2020-10-02 08:43:17 +02:00
  • a7bcf9ec7f Further improvements to certificate_info() Dirk 2020-10-01 17:49:14 +02:00
  • 67afa6c372 MOre points added to complete intermediate cert section Dirk 2020-10-01 00:13:31 +02:00
  • 5eee67291e Outsourcing of certificate date properties determination Dirk 2020-09-30 15:44:23 +02:00
  • b625df87c1 Move determination of fingerprint and serial to determine_cert_fingerprint_serial() Dirk 2020-09-28 20:38:37 +02:00
  • 9094665768 Start for improving handling of intermediate certs Dirk 2020-09-28 20:17:11 +02:00
  • 3d07f55f56 Merge pull request #1731 from drwetter/winshock_cipher_improvements Dirk Wetter 2020-09-22 17:35:31 +02:00
  • 3d22115d92 Fix travis Dirk 2020-09-22 16:40:59 +02:00
  • 721d046a7f Add the $EXPERIMENTAL part to winshock Dirk 2020-09-22 15:24:41 +02:00
  • 7d8cf71a94 Further robustness check to winshock (#1719) Dirk 2020-09-22 13:04:18 +02:00
  • cd9b98ca70 Merge pull request #1727 from drwetter/fix_1725_SCIR_3.0 Dirk Wetter 2020-09-16 20:13:33 +02:00
  • 8d4042c6b6 Merge pull request #1726 from drwetter/fix_1725_SCIR Dirk Wetter 2020-09-16 20:13:10 +02:00
  • 08feaf4a0c Fix Secure Client-Initiated Renegotiation false positive (3.0 branch) Dirk 2020-09-16 18:13:47 +02:00
  • ade010d4e7 Fix Secure Client-Initiated Renegotiation false positive Dirk 2020-09-16 18:06:21 +02:00
  • d4a3a67f70 Merge pull request #1723 from drwetter/winshock_cipher_improvements Dirk Wetter 2020-09-14 20:59:17 +02:00
  • 53bef583c6 add GCM in cipher description (debug info) Dirk 2020-09-14 19:33:07 +02:00
  • 772420cb42 Add two ECDHE_RSA GCM ciphersuites to prevent FPs for winshock Dirk 2020-09-14 19:26:18 +02:00
  • 6fe8764f8d upd alpine to 3.12 Vitalii Tverdokhlib 2020-09-12 18:04:33 +03:00
  • e62a9b8446 Merge pull request #1721 from drwetter/run_ws_default_fix Dirk Wetter 2020-09-09 15:30:05 +02:00
  • 2bdcdd5371 Winshock should now run also per default Dirk Wetter 2020-09-09 15:29:12 +02:00
  • 4a120d9a45 Merge pull request #1720 from drwetter/winshock_fingerprint_improvements Dirk Wetter 2020-09-09 13:22:07 +02:00
  • 023005f011 remove false positive for winshock bc of wrong protocol Dirk Wetter 2020-09-09 12:15:23 +02:00
  • edf669711f Merge pull request #1718 from drwetter/winshock Dirk Wetter 2020-09-08 22:11:36 +02:00
  • 0e54075a6a Reverse double dash option for vulnerabilities (cmd line) Dirk Wetter 2020-09-08 22:09:57 +02:00
  • 1f8e65104c Add winshock to documentation Dirk Wetter 2020-09-08 22:08:05 +02:00
  • 794bbe30af Merge pull request #1710 from tosticated/3.1dev Dirk Wetter 2020-09-08 15:37:07 +02:00
  • ad8a52ec4f Updated changelog and credits tosticated 2020-09-08 15:34:30 +02:00
  • fe7b51a3e2 remove hint in winshock Dirk Wetter 2020-09-08 13:42:50 +02:00
  • a1a0605082 add winshock Dirk Wetter 2020-09-08 13:42:33 +02:00
  • a511da4ce8 New feature: winshock Dirk Wetter 2020-09-08 12:37:50 +02:00
  • b6bab1e1b5 Merge pull request #1715 from drwetter/not_run_allciphers_et_al Dirk Wetter 2020-09-07 21:17:01 +02:00
  • e5d0b3eeac Modify default for full 9 yrds run Dirk Wetter 2020-09-07 09:54:34 +02:00
  • eafeb904f4 Fix emptying of SERVICE variable in determine_service() Dirk Wetter 2020-09-03 14:22:53 +02:00
  • 35b79f65ee Add documentation for STARTTLS injection's cmd line flag Dirk Wetter 2020-09-02 18:23:11 +02:00
  • 4a167f6ac5 Add openssl 1.1.1g into alpine docker image for STARTTLS injection Dirk Wetter 2020-09-02 17:44:11 +02:00
  • 3e6b1b971a Make Travis work again (STARTTLS injection) Dirk Wetter 2020-09-02 17:35:42 +02:00
  • 1912230173 Show that we need socat for this check Dirk Wetter 2020-08-31 18:29:59 +02:00
  • 7f4cf42ff4 Works now also for POP3 / IMAP Dirk Wetter 2020-08-31 17:14:56 +02:00
  • d424b0c649 Merge pull request #1711 from dcooper16/fix1699 Dirk Wetter 2020-08-31 17:08:10 +02:00
  • c0581afeeb Merge pull request #1712 from dcooper16/fix1699_3.0 Dirk Wetter 2020-08-31 17:07:46 +02:00
  • b7dab55b6c Fix #1699 in 3.0 branch David Cooper 2020-08-31 10:42:11 -04:00
  • 3973bc3364 Fix #1699 David Cooper 2020-08-31 10:35:19 -04:00
  • 47e9814baa Added check for certificate validity longer than 398 days tosticated 2020-08-31 16:21:32 +02:00
  • e3b62341ba Merge branch '3.1dev' of https://github.com/tosticated/testssl.sh into 3.1dev tosticated 2020-08-31 16:20:59 +02:00
  • 63620276cd Added check for certificate validity longer than 398 days tosticated 2020-08-31 16:20:27 +02:00
  • b315f5ac03 Added check for certificate validity longer than 398 days tosticated 2020-08-31 16:11:30 +02:00
  • a65e55522f Add sending payloads for POP and IMAP for starttls injection Dirk Wetter 2020-08-29 10:20:35 +02:00
  • 5560e17b01 Cleanup stuff in run_starttls_injection() and more Dirk Wetter 2020-08-29 09:17:17 +02:00
  • 32b5219206 Finalized SMTP Dirk Wetter 2020-08-28 18:25:51 +02:00
  • 6c966a5a7f Implementation of STARTTLS injection fo smtp Dirk Wetter 2020-08-28 00:50:06 +02:00
  • 4f8fe42f0c Prepared smtp/lmtp to prepare for addition commands after STARTTLS Dirk Wetter 2020-08-27 23:00:50 +02:00
  • 09fb279510 Merge pull request #1707 from geert-hendrickx-be/3.1dev Dirk Wetter 2020-08-26 18:59:43 +02:00
  • 09c276ffa2 hostname is not defined by POSIX, use portable uname -n instead. Geert Hendrickx 2020-08-26 18:40:47 +02:00
  • af5cad9183 Additions to find_openssl_binary() for a new openssl version / cleanup() Dirk Wetter 2020-08-24 16:22:04 +02:00
  • b4cbe7674a Merge pull request #1704 from drwetter/add_ca_dir Dirk Wetter 2020-08-20 09:19:25 +02:00
  • ecc6cd8160 Allow dir with PEM files for --add-CA Dirk Wetter 2020-08-18 21:52:59 +02:00
  • 565c93e53b Merge pull request #1703 from drwetter/rapydblok Dirk Wetter 2020-08-14 10:21:36 +02:00
  • 7830a22b27 Merge pull request #1702 from drwetter/unrecognized_option--version Dirk Wetter 2020-08-14 10:20:48 +02:00
  • e76de12047 Add https://inspect.rapydblok.com Dirk 2020-08-13 20:58:15 +02:00
  • 1d954233bd Document is in utf-8 Dirk Wetter 2020-08-13 20:43:54 +02:00
  • 953e1bd0ff Phrase --version & friends as standalone Dirk Wetter 2020-08-13 18:11:24 +02:00
  • a2929211b2 Merge pull request #1697 from drwetter/no_starttls_detection2 Dirk Wetter 2020-08-11 16:27:24 +02:00
  • ee7a21ef76 Merge pull request #1698 from drwetter/mitigate_javastore4rating Dirk Wetter 2020-08-11 16:25:25 +02:00
  • 1915a7b624 STARTTLS Dirk Wetter 2020-08-11 15:41:20 +02:00
  • 4653613211 Add mitigate_javastore4rating Dirk Wetter 2020-08-11 15:36:43 +02:00
  • c4841c83eb Don't penalize rating for CAs which aren't in the Java store Dirk Wetter 2020-08-11 15:30:53 +02:00
  • ac6b64ce36 Trying to address no STARTTLS offerings (2) Dirk Wetter 2020-08-11 12:01:28 +02:00
  • 186dcfa735 Merge pull request #1696 from dcooper16/fewer_external_function_calls Dirk Wetter 2020-08-07 13:17:38 +02:00
  • fd5928af47 Use fewer external function calls David Cooper 2020-08-06 07:50:01 -04:00