Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: verify HTTPS 'vulnerabilities' |
|---|---|
| Date: | Tue, 26 Jul 2005 16:02:41 -0500 |
Would SSLDigger from Foundstone not work? For at least part of the testing?
-----Original Message----- From: Thomas Springer [mailto:tuevsec@gmx.net] Sent: Tuesday, July 26, 2005 10:28 AM To: pen-test@securityfocus.com Cc: Dan Rogers Subject: Re: verify HTTPS 'vulnerabilities' Dan Rogers wrote:List, Simple question: I have a report from Nessus telling me that a web server isoffering'export class' cyphers for it's SSL/TLS service. Nessusalso managedto obtain an internal IP address from the host (which is correct). Only HTTPS is open.i put an https-check based on openssl online at http://serversniff.net that tells you about certs and allowed ciphers on your https-server. tom
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RES: IPS comparison, Charbel Chalala Issa |
|---|---|
| Next by Date: | Re: verify HTTPS 'vulnerabilities', Michael Sierchio |
| Previous by Thread: | RE: verify HTTPS 'vulnerabilities', Carl |
| Next by Thread: | re: DECODING EMAILS BETWEEN MS EXCHANGE AND A CLIENT, Dan Berberich |
| Indexes: | [Date] [Thread] [Top] [All Lists] |