|
1 | 1 | "ALPN","","INFO","http/1.1","",""
|
2 | 2 | "BEAST","","OK","not vulnerable, no SSL3 or TLS1","CVE-2011-3389","CWE-20"
|
3 |
| -"BREACH","","OK","not vulnerable, no HTTP compression - only supplied '/' tested","CVE-2013-3587","CWE-310" |
| 3 | +"BREACH","","OK","not vulnerable, no gzip/deflate/compress/br HTTP compression - only supplied '/' tested","CVE-2013-3587","CWE-310" |
4 | 4 | "CCS","","OK","not vulnerable","CVE-2014-0224","CWE-310"
|
5 | 5 | "CRIME_TLS","","OK","not vulnerable","CVE-2012-4929","CWE-310"
|
6 | 6 | "DNS_CAArecord","","LOW","--","",""
|
7 | 7 | "DROWN","","OK","not vulnerable on this host and port","CVE-2016-0800 CVE-2016-0703","CWE-310"
|
8 | 8 | "DROWN_hint","","INFO","no RSA certificate, can't be used with SSLv2 elsewhere","CVE-2016-0800 CVE-2016-0703","CWE-310"
|
9 | 9 | "FREAK","","OK","not vulnerable","CVE-2015-0204","CWE-310"
|
| 10 | +"FS","","OK","offered","","" |
| 11 | +"FS_ECDHE_curves","","OK","prime256v1 secp384r1 secp521r1","","" |
| 12 | +"FS_TLS12_sig_algs","","INFO","ECDSA+SHA256 ECDSA+SHA384 ECDSA+SHA512 ECDSA-BRAINPOOL+SHA256 ECDSA-BRAINPOOL+SHA384 ECDSA-BRAINPOOL+SHA512 ECDSA+SHA224","","" |
| 13 | +"FS_TLS13_sig_algs","","INFO","ECDSA+SHA384","","" |
| 14 | +"FS_ciphers","","INFO","TLS_AES_256_GCM_SHA384 ECDHE-ECDSA-AES256-GCM-SHA384 TLS_AES_128_GCM_SHA256 ECDHE-ECDSA-AES128-GCM-SHA256","","" |
10 | 15 | "HPKP","","INFO","No support for HTTP Public Key Pinning","",""
|
11 | 16 | "HSTS","","LOW","not offered","",""
|
12 | 17 | "HTTP_clock_skew","","INFO","Got no HTTP time, maybe try different URL?","",""
|
|
16 | 21 | "LUCKY13","","OK","not vulnerable","CVE-2013-0169","CWE-310"
|
17 | 22 | "NPN","","INFO","not offered","",""
|
18 | 23 | "OCSP_stapling","","INFO","not offered","",""
|
19 |
| -"PFS","","OK","offered","","" |
20 |
| -"PFS_ECDHE_curves","","OK","prime256v1 secp384r1 secp521r1","","" |
21 |
| -"PFS_ciphers","","INFO","TLS_AES_256_GCM_SHA384 ECDHE-ECDSA-AES256-GCM-SHA384 TLS_AES_128_GCM_SHA256 ECDHE-ECDSA-AES128-GCM-SHA256","","" |
22 | 24 | "POODLE_SSL","","OK","not vulnerable, no SSLv3","CVE-2014-3566","CWE-310"
|
23 | 25 | "RC4","","OK","not vulnerable","CVE-2013-2566 CVE-2015-2808","CWE-310"
|
24 | 26 | "ROBOT","","OK","not vulnerable, no RSA key transport cipher","CVE-2017-17382 CVE-2017-17427 CVE-2017-17428 CVE-2017-13098 CVE-2017-1000385 CVE-2017-13099 CVE-2016-6883 CVE-2012-5081 CVE-2017-6168","CWE-203"
|
|
46 | 48 | "cert_eTLS","","INFO","not present","",""
|
47 | 49 | "cert_expirationStatus","","HIGH","expires < 30 days (0)","",""
|
48 | 50 | "cert_extKeyUsage","","INFO","No server extended key usage information","",""
|
| 51 | +"cert_extlifeSpan","","OK","certificate has no extended life time according to browser forum","","" |
49 | 52 | "cert_fingerprintSHA1","","INFO","","",""
|
50 | 53 | "cert_fingerprintSHA256","","INFO","","",""
|
51 |
| -"cert_keySize","","OK","EC 384 bits","","" |
| 54 | +"cert_keySize","","OK","EC 384 bits (curve P-384)","","" |
52 | 55 | "cert_keyUsage","","INFO","No server key usage information","",""
|
53 | 56 | "cert_mustStapleExtension","","INFO","--","",""
|
54 | 57 | "cert_notAfter","","HIGH","","",""
|
|
61 | 64 | "cert_signatureAlgorithm","","OK","ECDSA with SHA384","",""
|
62 | 65 | "cert_subjectAltName","","INFO","","",""
|
63 | 66 | "cert_trust","","OK","Ok via SAN","",""
|
64 |
| -"cert_validityPeriod","","INFO","No finding","","" |
| 67 | +"certificate_compression","","INFO","none","","" |
65 | 68 | "certificate_transparency","","INFO","--","",""
|
66 | 69 | "certs_countServer","","INFO","1","",""
|
67 | 70 | "certs_list_ordering_problem","","INFO","no","",""
|
68 |
| -"cipher_negotiated","","OK","TLS_AES_256_GCM_SHA384, 256 bit ECDH (P-256)","","" |
| 71 | +"cipher-tls1_2_xc02b","","OK","TLSv1.2 xc02b ECDHE-ECDSA-AES128-GCM-SHA256 ECDH 521 AESGCM 128 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256","","" |
| 72 | +"cipher-tls1_2_xc02c","","OK","TLSv1.2 xc02c ECDHE-ECDSA-AES256-GCM-SHA384 ECDH 521 AESGCM 256 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384","","" |
| 73 | +"cipher-tls1_3_x1301","","OK","TLSv1.3 x1301 TLS_AES_128_GCM_SHA256 ECDH 256 AESGCM 128 TLS_AES_128_GCM_SHA256","","" |
| 74 | +"cipher-tls1_3_x1302","","OK","TLSv1.3 x1302 TLS_AES_256_GCM_SHA384 ECDH 256 AESGCM 256 TLS_AES_256_GCM_SHA384","","" |
69 | 75 | "cipher_order","","OK","server","",""
|
70 |
| -"cipher_x1301","","INFO","x1301 TLS_AES_128_GCM_SHA256 ECDH 256 AESGCM 128 TLS_AES_128_GCM_SHA256","","" |
71 |
| -"cipher_x1302","","INFO","x1302 TLS_AES_256_GCM_SHA384 ECDH 256 AESGCM 256 TLS_AES_256_GCM_SHA384","","" |
72 |
| -"cipher_xc02b","","INFO","xc02b ECDHE-ECDSA-AES128-GCM-SHA256 ECDH 521 AESGCM 128 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256","","" |
73 |
| -"cipher_xc02c","","INFO","xc02c ECDHE-ECDSA-AES256-GCM-SHA384 ECDH 521 AESGCM 256 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384","","" |
| 76 | +"cipher_order-tls1_2","","OK","server","","" |
| 77 | +"cipher_order-tls1_3","","OK","server","","" |
| 78 | +"cipher_strength_score","","INFO","0","","" |
| 79 | +"cipher_strength_score_weighted","","INFO","0","","" |
74 | 80 | "cipherlist_3DES_IDEA","","INFO","not offered","","CWE-310"
|
75 |
| -"cipherlist_AVERAGE","","INFO","not offered","","CWE-310" |
76 | 81 | "cipherlist_EXPORT","","OK","not offered","","CWE-327"
|
77 | 82 | "cipherlist_LOW","","OK","not offered","","CWE-327"
|
78 | 83 | "cipherlist_NULL","","OK","not offered","","CWE-327"
|
79 |
| -"cipherlist_STRONG","","OK","offered","","" |
| 84 | +"cipherlist_OBSOLETED","","INFO","not offered","","CWE-310" |
| 85 | +"cipherlist_STRONG_FS","","OK","offered","","" |
| 86 | +"cipherlist_STRONG_NOFS","","INFO","not offered","","" |
80 | 87 | "cipherlist_aNULL","","OK","not offered","","CWE-327"
|
81 | 88 | "cipherorder_TLSv1_2","","INFO","ECDHE-ECDSA-AES256-GCM-SHA384 ECDHE-ECDSA-AES128-GCM-SHA256","",""
|
82 | 89 | "cipherorder_TLSv1_3","","INFO","TLS_AES_256_GCM_SHA384 TLS_AES_128_GCM_SHA256","",""
|
83 |
| -"clientsimulation-android_442","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","","" |
84 |
| -"clientsimulation-android_500","","INFO","TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256","","" |
| 90 | +"clientAuth","","INFO","optional","","" |
| 91 | +"clientAuth_CA_list","","INFO","empty","","" |
| 92 | +"clientsimulation-android_11","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
| 93 | +"clientsimulation-android_12","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
85 | 94 | "clientsimulation-android_60","","INFO","TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256","",""
|
86 | 95 | "clientsimulation-android_70","","INFO","No connection","",""
|
87 | 96 | "clientsimulation-android_81","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
|
88 | 97 | "clientsimulation-android_90","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
|
89 | 98 | "clientsimulation-android_X","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
|
90 |
| -"clientsimulation-apple_ats_9_ios9","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","","" |
91 |
| -"clientsimulation-chrome_74_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
| 99 | +"clientsimulation-apple_mail_16_0","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","","" |
| 100 | +"clientsimulation-chrome_101_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
92 | 101 | "clientsimulation-chrome_79_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
|
| 102 | +"clientsimulation-edge_101_win10_21h2","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
93 | 103 | "clientsimulation-edge_15_win10","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
|
94 |
| -"clientsimulation-edge_17_win10","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","","" |
| 104 | +"clientsimulation-firefox_100_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
95 | 105 | "clientsimulation-firefox_66_win81","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
|
96 |
| -"clientsimulation-firefox_71_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
| 106 | +"clientsimulation-go_1178","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
97 | 107 | "clientsimulation-ie_11_win10","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
|
98 | 108 | "clientsimulation-ie_11_win7","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
|
99 | 109 | "clientsimulation-ie_11_win81","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
|
|
102 | 112 | "clientsimulation-ie_8_win7","","INFO","No connection","",""
|
103 | 113 | "clientsimulation-ie_8_xp","","INFO","No connection","",""
|
104 | 114 | "clientsimulation-java1102","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
|
105 |
| -"clientsimulation-java1201","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
106 |
| -"clientsimulation-java_6u45","","INFO","No connection","","" |
| 115 | +"clientsimulation-java1703","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
107 | 116 | "clientsimulation-java_7u25","","INFO","No connection","",""
|
108 | 117 | "clientsimulation-java_8u161","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
|
| 118 | +"clientsimulation-libressl_283","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","","" |
109 | 119 | "clientsimulation-openssl_102e","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
|
110 | 120 | "clientsimulation-openssl_110l","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
|
111 | 121 | "clientsimulation-openssl_111d","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
|
112 |
| -"clientsimulation-opera_66_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
113 |
| -"clientsimulation-safari_10_osx1012","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","","" |
| 122 | +"clientsimulation-openssl_303","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
114 | 123 | "clientsimulation-safari_121_ios_122","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
|
115 | 124 | "clientsimulation-safari_130_osx_10146","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
|
116 |
| -"clientsimulation-safari_9_ios9","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","","" |
117 |
| -"clientsimulation-safari_9_osx1011","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","","" |
118 |
| -"clientsimulation-thunderbird_68_3_1","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
| 125 | +"clientsimulation-safari_154_osx_1231","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
| 126 | +"clientsimulation-thunderbird_91_9","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","","" |
119 | 127 | "cookie_count","","INFO","0 at '/' (30x detected, better try target URL of 30x)","",""
|
120 | 128 | "fallback_SCSV","","OK","no protocol below TLS 1.2 offered","",""
|
| 129 | +"final_score","","INFO","0","","" |
| 130 | +"grade_cap_reason_1","","INFO","Grade capped to T. Issues with the chain of trust (chain incomplete)","","" |
| 131 | +"grade_cap_reason_2","","INFO","Grade capped to A. HSTS is not offered","","" |
121 | 132 | "heartbleed","","OK","not vulnerable, no heartbeat extension","CVE-2014-0160","CWE-119"
|
122 | 133 | "id","fqdn/ip","port","severity","finding","cve","cwe"
|
| 134 | +"intermediate_cert_badOCSP","","OK","intermediate certificate(s) is/are ok","","" |
| 135 | +"key_exchange_score","","INFO","0","","" |
| 136 | +"key_exchange_score_weighted","","INFO","0","","" |
| 137 | +"overall_grade","","CRITICAL","T","","" |
123 | 138 | "pre_128cipher","","INFO","No 128 cipher limit bug","",""
|
124 |
| -"protocol_negotiated","","OK","Default protocol TLS1.3","","" |
| 139 | +"protocol_support_score","","INFO","0","","" |
| 140 | +"protocol_support_score_weighted","","INFO","0","","" |
| 141 | +"rating_doc","","INFO","https://github.com/ssllabs/research/wiki/SSL-Server-Rating-Guide","","" |
| 142 | +"rating_spec","","INFO","SSL Labs's 'SSL Server Rating Guide' (version 2009q from 2020-01-30)","","" |
125 | 143 | "secure_client_renego","","OK","not vulnerable","CVE-2011-1473","CWE-310"
|
126 | 144 | "secure_renego","","OK","supported","","CWE-310"
|
127 | 145 | "security_headers","","MEDIUM","--","",""
|
128 | 146 | "service","","INFO","HTTP","",""
|
129 | 147 | "sessionresumption_ID","","INFO","not supported","",""
|
130 | 148 | "sessionresumption_ticket","","INFO","not supported","",""
|
131 | 149 | "ticketbleed","","OK","not vulnerable","CVE-2016-9244","CWE-200"
|
| 150 | +"winshock","","OK","not vulnerable","CVE-2014-6321","CWE-94" |
0 commit comments