SSL Checklist for Pentesters - NCC Group [PDF]

27 Jun 2014 - PoC and first-gen tools raced out. – Testing could lead to compromise of sensitive data and/or potential

26 downloads 27 Views 984KB Size

Recommend Stories


NCC
Goodbyes are only for those who love with their eyes. Because for those who love with heart and soul

ssl
I tried to make sense of the Four Books, until love arrived, and it all became a single syllable. Yunus

PDF Download SSL TLS Essentials
And you? When will you begin that long journey into yourself? Rumi

Group Hotel or Conference Checklist
Don't ruin a good today by thinking about a bad yesterday. Let it go. Anonymous

Checklist (PDF)
And you? When will you begin that long journey into yourself? Rumi

MFA School Group Visit Checklist
Ask yourself: What is one thing I love the most about myself? Next

NCC Recycling
Kindness, like a boomerang, always returns. Unknown

Career (NCC)
Open your mouth only if what you are going to say is more beautiful than the silience. BUDDHA

F5 Solutions for SSL Visibility
This being human is a guest house. Every morning is a new arrival. A joy, a depression, a meanness,

SSL Performance
Don't ruin a good today by thinking about a bad yesterday. Let it go. Anonymous

Idea Transcript


SSL Checklist for Pentesters Jerome Smith BSides MCR, 27th June 2014

whoami

# whoami jerome

• Pentester • Author/trainer – Hands-on technical – Web application, infrastructure, wireless security

• Security projects – Log correlation – Dirty data – Incident response exercises

• Sysadmin • MSc Computing Science (Dist) • www.exploresecurity.com | @exploresecurity

Introduction • Broad review of SSL/TLS checks – Viewpoint of pentester – Pitfalls – Manually replicating what tools do (unless you told the client that SSL Labs would be testing them ) – Issues to consider reporting (but views are my own)

• While SSL issues are generally low in priority, it’s nice to get them right! • I’m not a cryptographer: this is all best efforts

SSLv2 • Flawed, e.g. no handshake protection → MITM downgrade • Modern browsers do not support SSLv2 anyway – Except for IE but it’s disabled by default from IE7 – That mitigates the risk these days – http://en.wikipedia.org/wiki/Transport_Layer_Security#W eb_browsers

• OpenSSL 1.0.0+ doesn’t support it – Which means SSLscan won’t find it – General point: tools that dynamically link to an underlying SSL library in the OS can be limited by what that library supports

SSLv2 • Same scan on different OpenSSL versions:

SSLv2 •

testssl.sh warns you

– It can work with any installed OpenSSL version

• OpenSSL

Smile Life

When life gives you a hundred reasons to cry, show life that you have a thousand reasons to smile

Get in touch

© Copyright 2015 - 2024 PDFFOX.COM - All rights reserved.