Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

RE: verify HTTPS 'vulnerabilities'

Subject: RE: verify HTTPS 'vulnerabilities'
Date: Tue, 26 Jul 2005 16:02:41 -0500
Would SSLDigger from Foundstone not work? For at least part of the
testing? 

-----Original Message-----
From: Thomas Springer [mailto:tuevsec@gmx.net] 
Sent: Tuesday, July 26, 2005 10:28 AM
To: pen-test@securityfocus.com
Cc: Dan Rogers
Subject: Re: verify HTTPS 'vulnerabilities'

Dan Rogers wrote:
List,

Simple question:

I have a report from Nessus telling me that a web server is 
offering 
'export class' cyphers for it's SSL/TLS service. Nessus 
also managed 
to obtain an internal IP address from the host (which is correct).
Only HTTPS is open.

i put an https-check based on openssl online at 
http://serversniff.net that tells you about certs and allowed 
ciphers on your https-server.

tom


<Prev in Thread] Current Thread [Next in Thread>