You are viewing 'SSLScan'


Outdated SSL: Common Vulnerability

 Jose Hernandez

Jose Hernandez    |    June 06, 2012

When conducting external vulnerability assessments I have been seeing a specific finding as “very common”; the finding that the server supports outdated Secure Socket Layer (SSL) version 2 protocols.

The problem is simple enough. You didn’t update your server support and you are now not running the more recent versions. But, as is usually the case, the newer SSL standards are more secure.

Every modern vulnerability scanner will pick up on this issue and report on it. I always like to double check findings using manual testing techniques or running separate tools to verify findings are legitimate. The tool SSLScan, part of the backtrac testing suite, is very useful when verifying this finding. SSLScan is very easy to use and will give you a clear picture of what ciphers your server supports, what are the servers preferred ciphers and which SSL protocols are supported. The following is a screenshot of SSLScan running against... read more >



Tags: Solutionary, vulnerability management, Secure Socket Layer (SSL), SSLScan, vulnerability scanner

Solutionary is a leading managed security service provider. The company reduces the information security and compliance burden, providing flexible security services that work the way clients want; enhancing existing initiatives, infrastructure and personnel. This blog is a place to learn about, and discuss, a wide variety of security and compliance topics.

Subscribe Now!  RSS Feed

LATEST TWEETS