testssl.sh/t/baseline_data/testssl.csv
2025-01-27 21:36:40 +01:00

18 KiB

1idfqdn/ipportseverityfindingcvecwe
2DNS_HTTPS_rrecordtestssl.sh/81.169.166.184443OK1 . alpn='h2'
3servicetestssl.sh/81.169.166.184443INFOHTTP
4pre_128ciphertestssl.sh/81.169.166.184443INFONo 128 cipher limit bug
5SSLv2testssl.sh/81.169.166.184443OKnot offered
6SSLv3testssl.sh/81.169.166.184443OKnot offered
7TLS1testssl.sh/81.169.166.184443LOWoffered (deprecated)
8TLS1_1testssl.sh/81.169.166.184443LOWoffered (deprecated)
9TLS1_2testssl.sh/81.169.166.184443OKoffered
10TLS1_3testssl.sh/81.169.166.184443OKoffered with final
11NPNtestssl.sh/81.169.166.184443INFOoffered with h2, http/1.1 (advertised)
12ALPN_HTTP2testssl.sh/81.169.166.184443OKh2
13ALPNtestssl.sh/81.169.166.184443INFOhttp/1.1
14cipherlist_NULLtestssl.sh/81.169.166.184443OKnot offeredCWE-327
15cipherlist_aNULLtestssl.sh/81.169.166.184443OKnot offeredCWE-327
16cipherlist_EXPORTtestssl.sh/81.169.166.184443OKnot offeredCWE-327
17cipherlist_LOWtestssl.sh/81.169.166.184443OKnot offeredCWE-327
18cipherlist_3DES_IDEAtestssl.sh/81.169.166.184443INFOnot offeredCWE-310
19cipherlist_OBSOLETEDtestssl.sh/81.169.166.184443LOWofferedCWE-310
20cipherlist_STRONG_NOFStestssl.sh/81.169.166.184443OKoffered
21cipherlist_STRONG_FStestssl.sh/81.169.166.184443OKoffered
22cipher_order-tls1testssl.sh/81.169.166.184443OKserver
23cipher-tls1_xc014testssl.sh/81.169.166.184443LOWTLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
24cipher-tls1_xc013testssl.sh/81.169.166.184443LOWTLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
25cipher-tls1_x88testssl.sh/81.169.166.184443LOWTLSv1 x88 DHE-RSA-CAMELLIA256-SHA DH 2048 Camellia 256 TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
26cipher-tls1_x45testssl.sh/81.169.166.184443LOWTLSv1 x45 DHE-RSA-CAMELLIA128-SHA DH 2048 Camellia 128 TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
27cipher-tls1_x39testssl.sh/81.169.166.184443LOWTLSv1 x39 DHE-RSA-AES256-SHA DH 2048 AES 256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA
28cipher-tls1_x33testssl.sh/81.169.166.184443LOWTLSv1 x33 DHE-RSA-AES128-SHA DH 2048 AES 128 TLS_DHE_RSA_WITH_AES_128_CBC_SHA
29cipher-tls1_x35testssl.sh/81.169.166.184443LOWTLSv1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
30cipherorder_TLSv1testssl.sh/81.169.166.184443INFOECDHE-RSA-AES256-SHA ECDHE-RSA-AES128-SHA DHE-RSA-CAMELLIA256-SHA DHE-RSA-CAMELLIA128-SHA DHE-RSA-AES256-SHA DHE-RSA-AES128-SHA AES256-SHA
31cipher_order-tls1_1testssl.sh/81.169.166.184443OKserver
32cipher-tls1_1_xc014testssl.sh/81.169.166.184443LOWTLSv1.1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
33cipher-tls1_1_xc013testssl.sh/81.169.166.184443LOWTLSv1.1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
34cipher-tls1_1_x88testssl.sh/81.169.166.184443LOWTLSv1.1 x88 DHE-RSA-CAMELLIA256-SHA DH 2048 Camellia 256 TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
35cipher-tls1_1_x45testssl.sh/81.169.166.184443LOWTLSv1.1 x45 DHE-RSA-CAMELLIA128-SHA DH 2048 Camellia 128 TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
36cipher-tls1_1_x39testssl.sh/81.169.166.184443LOWTLSv1.1 x39 DHE-RSA-AES256-SHA DH 2048 AES 256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA
37cipher-tls1_1_x33testssl.sh/81.169.166.184443LOWTLSv1.1 x33 DHE-RSA-AES128-SHA DH 2048 AES 128 TLS_DHE_RSA_WITH_AES_128_CBC_SHA
38cipher-tls1_1_x35testssl.sh/81.169.166.184443LOWTLSv1.1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
39cipherorder_TLSv1_1testssl.sh/81.169.166.184443INFOECDHE-RSA-AES256-SHA ECDHE-RSA-AES128-SHA DHE-RSA-CAMELLIA256-SHA DHE-RSA-CAMELLIA128-SHA DHE-RSA-AES256-SHA DHE-RSA-AES128-SHA AES256-SHA
40cipher_order-tls1_2testssl.sh/81.169.166.184443OKserver
41cipher-tls1_2_xc030testssl.sh/81.169.166.184443OKTLSv1.2 xc030 ECDHE-RSA-AES256-GCM-SHA384 ECDH 256 AESGCM 256 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
42cipher-tls1_2_xc02ftestssl.sh/81.169.166.184443OKTLSv1.2 xc02f ECDHE-RSA-AES128-GCM-SHA256 ECDH 256 AESGCM 128 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
43cipher-tls1_2_x9ftestssl.sh/81.169.166.184443OKTLSv1.2 x9f DHE-RSA-AES256-GCM-SHA384 DH 2048 AESGCM 256 TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
44cipher-tls1_2_x9etestssl.sh/81.169.166.184443OKTLSv1.2 x9e DHE-RSA-AES128-GCM-SHA256 DH 2048 AESGCM 128 TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
45cipher-tls1_2_xc028testssl.sh/81.169.166.184443LOWTLSv1.2 xc028 ECDHE-RSA-AES256-SHA384 ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
46cipher-tls1_2_xc014testssl.sh/81.169.166.184443LOWTLSv1.2 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
47cipher-tls1_2_xc013testssl.sh/81.169.166.184443LOWTLSv1.2 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
48cipher-tls1_2_x88testssl.sh/81.169.166.184443LOWTLSv1.2 x88 DHE-RSA-CAMELLIA256-SHA DH 2048 Camellia 256 TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
49cipher-tls1_2_x45testssl.sh/81.169.166.184443LOWTLSv1.2 x45 DHE-RSA-CAMELLIA128-SHA DH 2048 Camellia 128 TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
50cipher-tls1_2_x6btestssl.sh/81.169.166.184443LOWTLSv1.2 x6b DHE-RSA-AES256-SHA256 DH 2048 AES 256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
51cipher-tls1_2_x39testssl.sh/81.169.166.184443LOWTLSv1.2 x39 DHE-RSA-AES256-SHA DH 2048 AES 256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA
52cipher-tls1_2_x67testssl.sh/81.169.166.184443LOWTLSv1.2 x67 DHE-RSA-AES128-SHA256 DH 2048 AES 128 TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
53cipher-tls1_2_x33testssl.sh/81.169.166.184443LOWTLSv1.2 x33 DHE-RSA-AES128-SHA DH 2048 AES 128 TLS_DHE_RSA_WITH_AES_128_CBC_SHA
54cipher-tls1_2_x9dtestssl.sh/81.169.166.184443OKTLSv1.2 x9d AES256-GCM-SHA384 RSA AESGCM 256 TLS_RSA_WITH_AES_256_GCM_SHA384
55cipher-tls1_2_x9ctestssl.sh/81.169.166.184443OKTLSv1.2 x9c AES128-GCM-SHA256 RSA AESGCM 128 TLS_RSA_WITH_AES_128_GCM_SHA256
56cipher-tls1_2_x3dtestssl.sh/81.169.166.184443LOWTLSv1.2 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256
57cipher-tls1_2_x35testssl.sh/81.169.166.184443LOWTLSv1.2 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
58cipherorder_TLSv1_2testssl.sh/81.169.166.184443INFOECDHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-AES128-GCM-SHA256 DHE-RSA-AES256-GCM-SHA384 DHE-RSA-AES128-GCM-SHA256 ECDHE-RSA-AES256-SHA384 ECDHE-RSA-AES256-SHA ECDHE-RSA-AES128-SHA DHE-RSA-CAMELLIA256-SHA DHE-RSA-CAMELLIA128-SHA DHE-RSA-AES256-SHA256 DHE-RSA-AES256-SHA DHE-RSA-AES128-SHA256 DHE-RSA-AES128-SHA AES256-GCM-SHA384 AES128-GCM-SHA256 AES256-SHA256 AES256-SHA
59cipher_order-tls1_3testssl.sh/81.169.166.184443OKserver
60cipher-tls1_3_x1302testssl.sh/81.169.166.184443OKTLSv1.3 x1302 TLS_AES_256_GCM_SHA384 ECDH 253 AESGCM 256 TLS_AES_256_GCM_SHA384
61cipher-tls1_3_x1303testssl.sh/81.169.166.184443OKTLSv1.3 x1303 TLS_CHACHA20_POLY1305_SHA256 ECDH 253 ChaCha20 256 TLS_CHACHA20_POLY1305_SHA256
62cipher-tls1_3_x1301testssl.sh/81.169.166.184443OKTLSv1.3 x1301 TLS_AES_128_GCM_SHA256 ECDH 253 AESGCM 128 TLS_AES_128_GCM_SHA256
63cipherorder_TLSv1_3testssl.sh/81.169.166.184443INFOTLS_AES_256_GCM_SHA384 TLS_CHACHA20_POLY1305_SHA256 TLS_AES_128_GCM_SHA256
64prioritize_chacha_TLSv1_3testssl.sh/81.169.166.184443INFOfalse
65cipher_ordertestssl.sh/81.169.166.184443OKserver
66FStestssl.sh/81.169.166.184443OKoffered
67FS_cipherstestssl.sh/81.169.166.184443INFOTLS_AES_256_GCM_SHA384 TLS_CHACHA20_POLY1305_SHA256 ECDHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-AES256-SHA384 ECDHE-RSA-AES256-SHA DHE-RSA-AES256-GCM-SHA384 DHE-RSA-AES256-SHA256 DHE-RSA-AES256-SHA DHE-RSA-CAMELLIA256-SHA TLS_AES_128_GCM_SHA256 ECDHE-RSA-AES128-GCM-SHA256 ECDHE-RSA-AES128-SHA DHE-RSA-AES128-GCM-SHA256 DHE-RSA-AES128-SHA256 DHE-RSA-AES128-SHA DHE-RSA-CAMELLIA128-SHA
68FS_ECDHE_curvestestssl.sh/81.169.166.184443OKprime256v1 secp384r1 secp521r1 X25519 X448
69DH_groupstestssl.sh/81.169.166.184443OKUnknown DH group (2048 bits)
70FS_TLS12_sig_algstestssl.sh/81.169.166.184443INFORSA-PSS-RSAE+SHA256 RSA-PSS-RSAE+SHA384 RSA-PSS-RSAE+SHA512 RSA+SHA256 RSA+SHA384 RSA+SHA512 RSA+SHA224
71FS_TLS13_sig_algstestssl.sh/81.169.166.184443INFORSA-PSS-RSAE+SHA256 RSA-PSS-RSAE+SHA384 RSA-PSS-RSAE+SHA512
72HTTP_status_codetestssl.sh/81.169.166.184443INFO200 OK ('/')
73HTTP_clock_skewtestssl.sh/81.169.166.184443INFO0 seconds from localtime
74HTTP_headerTimetestssl.sh/81.169.166.184443INFO1738009918
75HSTS_timetestssl.sh/81.169.166.184443OK362 days (=31337000 seconds) > 15552000 seconds
76HSTS_subdomainstestssl.sh/81.169.166.184443INFOonly for this domain
77HSTS_preloadtestssl.sh/81.169.166.184443INFOdomain is NOT marked for preloading
78HPKPtestssl.sh/81.169.166.184443INFONo support for HTTP Public Key Pinning
79banner_servertestssl.sh/81.169.166.184443INFONever trust a banner
80banner_applicationtestssl.sh/81.169.166.184443INFOX-Powered-By: A portion of humor
81cookie_counttestssl.sh/81.169.166.184443INFO0 at '/'
82X-Frame-Optionstestssl.sh/81.169.166.184443OKDENY
83X-Content-Type-Optionstestssl.sh/81.169.166.184443OKnosniff
84Content-Security-Policytestssl.sh/81.169.166.184443OKscript-src 'unsafe-inline'; style-src 'unsafe-inline' 'self'; object-src 'self'; base-uri 'none'; form-action 'none'; img-src 'self' ; default-src 'self'; frame-ancestors 'self'; upgrade-insecure-requests;
85Cross-Origin-Opener-Policytestssl.sh/81.169.166.184443INFOsame-origin-allow-popups
86Cross-Origin-Resource-Policytestssl.sh/81.169.166.184443INFOsame-site
87banner_reverseproxytestssl.sh/81.169.166.184443INFO--CWE-200
88heartbleedtestssl.sh/81.169.166.184443OKnot vulnerable, no heartbeat extensionCVE-2014-0160CWE-119
89CCStestssl.sh/81.169.166.184443OKnot vulnerableCVE-2014-0224CWE-310
90ticketbleedtestssl.sh/81.169.166.184443OKno session ticket extensionCVE-2016-9244CWE-200
91ROBOTtestssl.sh/81.169.166.184443OKnot vulnerableCVE-2017-17382 CVE-2017-17427 CVE-2017-17428 CVE-2017-13098 CVE-2017-1000385 CVE-2017-13099 CVE-2016-6883 CVE-2012-5081 CVE-2017-6168CWE-203
92secure_renegotestssl.sh/81.169.166.184443OKsupportedCWE-310
93secure_client_renegotestssl.sh/81.169.166.184443OKnot vulnerableCVE-2011-1473CWE-310
94CRIME_TLStestssl.sh/81.169.166.184443OKnot vulnerableCVE-2012-4929CWE-310
95BREACHtestssl.sh/81.169.166.184443OKnot vulnerable, no gzip/deflate/compress/br HTTP compression - only supplied '/' testedCVE-2013-3587CWE-310
96POODLE_SSLtestssl.sh/81.169.166.184443OKnot vulnerable, no SSLv3CVE-2014-3566CWE-310
97fallback_SCSVtestssl.sh/81.169.166.184443OKsupported
98SWEET32testssl.sh/81.169.166.184443OKnot vulnerableCVE-2016-2183 CVE-2016-6329CWE-327
99FREAKtestssl.sh/81.169.166.184443OKnot vulnerableCVE-2015-0204CWE-310
100DROWNtestssl.sh/81.169.166.184443OKnot vulnerable on this host and portCVE-2016-0800 CVE-2016-0703CWE-310
101DROWN_hinttestssl.sh/81.169.166.184443INFOMake sure you don't use this certificate elsewhere with SSLv2 enabled services, see https://search.censys.io/search?resource=hosts&virtual_hosts=INCLUDE&q=5B4BC205947AED96ECB1879F2668F7F69D696C143BA8D1C69DBB4DC873C92AE9CVE-2016-0800 CVE-2016-0703CWE-310
102LOGJAMtestssl.sh/81.169.166.184443OKnot vulnerable, no DH EXPORT ciphers,CVE-2015-4000CWE-310
103LOGJAM-common_primestestssl.sh/81.169.166.184443OK--CVE-2015-4000CWE-310
104BEAST_CBC_TLS1testssl.sh/81.169.166.184443MEDIUMECDHE-RSA-AES256-SHA ECDHE-RSA-AES128-SHA DHE-RSA-CAMELLIA256-SHA DHE-RSA-CAMELLIA128-SHA DHE-RSA-AES256-SHA DHE-RSA-AES128-SHA AES256-SHACVE-2011-3389CWE-20
105BEASTtestssl.sh/81.169.166.184443LOWVULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated)CVE-2011-3389CWE-20
106LUCKY13testssl.sh/81.169.166.184443LOWpotentially vulnerable, uses TLS CBC ciphersCVE-2013-0169CWE-310
107winshocktestssl.sh/81.169.166.184443OKnot vulnerableCVE-2014-6321CWE-94
108RC4testssl.sh/81.169.166.184443OKnot vulnerableCVE-2013-2566 CVE-2015-2808CWE-310
109clientsimulation-android_60testssl.sh/81.169.166.184443INFOTLSv1.2 ECDHE-RSA-AES128-GCM-SHA256
110clientsimulation-android_70testssl.sh/81.169.166.184443INFOTLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
111clientsimulation-android_81testssl.sh/81.169.166.184443INFOTLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
112clientsimulation-android_90testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
113clientsimulation-android_Xtestssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
114clientsimulation-android_11testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
115clientsimulation-android_12testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
116clientsimulation-chrome_79_win10testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
117clientsimulation-chrome_101_win10testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
118clientsimulation-firefox_66_win81testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
119clientsimulation-firefox_100_win10testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
120clientsimulation-ie_6_xptestssl.sh/81.169.166.184443INFONo connection
121clientsimulation-ie_8_win7testssl.sh/81.169.166.184443INFOTLSv1.0 ECDHE-RSA-AES256-SHA
122clientsimulation-ie_8_xptestssl.sh/81.169.166.184443INFONo connection
123clientsimulation-ie_11_win7testssl.sh/81.169.166.184443INFOTLSv1.2 DHE-RSA-AES256-GCM-SHA384
124clientsimulation-ie_11_win81testssl.sh/81.169.166.184443INFOTLSv1.2 DHE-RSA-AES256-GCM-SHA384
125clientsimulation-ie_11_winphone81testssl.sh/81.169.166.184443INFOTLSv1.2 ECDHE-RSA-AES256-SHA
126clientsimulation-ie_11_win10testssl.sh/81.169.166.184443INFOTLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
127clientsimulation-edge_15_win10testssl.sh/81.169.166.184443INFOTLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
128clientsimulation-edge_101_win10_21h2testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
129clientsimulation-safari_121_ios_122testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
130clientsimulation-safari_130_osx_10146testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
131clientsimulation-safari_154_osx_1231testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
132clientsimulation-java_7u25testssl.sh/81.169.166.184443INFOTLSv1.0 ECDHE-RSA-AES128-SHA
133clientsimulation-java_8u161testssl.sh/81.169.166.184443INFOTLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
134clientsimulation-java1102testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
135clientsimulation-java1703testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
136clientsimulation-go_1178testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
137clientsimulation-libressl_283testssl.sh/81.169.166.184443INFOTLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
138clientsimulation-openssl_102etestssl.sh/81.169.166.184443INFOTLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
139clientsimulation-openssl_110ltestssl.sh/81.169.166.184443INFOTLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
140clientsimulation-openssl_111dtestssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
141clientsimulation-openssl_303testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384
142clientsimulation-apple_mail_16_0testssl.sh/81.169.166.184443INFOTLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
143clientsimulation-thunderbird_91_9testssl.sh/81.169.166.184443INFOTLSv1.3 TLS_AES_256_GCM_SHA384