SSL 問題整理

SSL 問題整理

這一兩年 爆發了很多的SSL漏洞問題,整理一下最近遇到的一些問題

1. 驗證SSL版本是否有關閉方式
2. Google Chrome 移除SHA-1
3. Google Chrome 判定網頁內容有不安全資源

1. 驗證SSL版本是否有關閉方式
Web Server

#openssl s_client -connect hostname:443 -ssl2

 

#openssl s_client -connect hostname:443 -ssl3

 

#openssl s_client -connect hostname:443 -tls1

 

#openssl s_client -connect hostname:443 -tls1_1

 

#openssl s_client -connect hostname:443 -tls1_1

 

#openssl s_client -connect hostname:443 -tls1_2

SMTP Server

#openssl s_client -connect hostname:25 -starttls smtp -ssl2

 

#openssl s_client -connect hostname:25 -starttls smtp -ssl3

 

#openssl s_client -connect hostname:25 -starttls smtp -tls1

 

#openssl s_client -connect hostname:25 -starttls smtp -tls1_1

 

#openssl s_client -connect hostname:25 -starttls smtp -tls1_2
CONNECTED(00000003)
139965340723016:error:1407F0E5:SSL routines:SSL2_WRITE:ssl handshake failure:s2_pkt.c:430:
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 0 bytes and written 45 bytes
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
SSL-Session:
    Protocol  : SSLv2
    Cipher    : 0000
    Session-ID: 
    Session-ID-ctx: 
    Master-Key: 
    Key-Arg   : None
    Krb5 Principal: None
    PSK identity: None
    PSK identity hint: None
    Start Time: 1420609805
    Timeout   : 300 (sec)
    Verify return code: 0 (ok)
此狀況是關閉---

2. Google Chrome 移除SHA-1
最近在2014/9  Google 發出消息準備要全面移除雜湊函數 SHA-1
可以在以下URL確認自己的憑證是否會被chrome列入不安全
http://sha1affected.com/

Chrome Version
SHA-1  Expire date
Chrome 提示訊息
39 (current)
2017/1/1

40
2016/6/1~2016/12/31
2017/1/1
41
2016/1/1~2016/12/31
2017/1/1

3. Google Chrome 判定網頁內容有不安全資源

通常是網頁的Link 或者是 Java Script 載入了http,會被判定網頁內容有不安全的資源

搜尋 http://
將所有找到的 http:// 都換成 //。
儲存對網頁伺服器所做的修改,然後再測試一次

Refer:
https://major.io/2007/01/24/verify-that-sslv2-is-disabled/
http://sha1affected.com/
http://www.symantec.com/connect/blogs/sha1-certificate-shown-insecure-or-mix-content-warning-
google-chrome-39
http://googleonlinesecurity.blogspot.tw/2014/09/gradually-sunsetting-sha-1.html
https://support.google.com/adwords/answer/2580401?hl=zh-Hant

Facebook Comments
machine rape hentai hentaihug.com read hentai magna
ladki chodna pornude.mobi bluefilm com video
hindi video new pornozavr.me gora aur kala
نيك عنيف مترجم 24h-porn.net ينيكها وهي نايمه
يشبفسثء freebigassporn.org فيلم اجنبى قليل الادب
elizabeth olsen bf blondeporntrends.com malayalam sexi
chudai karwai indiandesiclips.com bhabisex.com
haryana village sex video ganstagirls.net wwwxnxcom
bf sexy vidio indiantubetv.com bhaagamathie songs naa songs
open sex free brownporntube.info open dance
bp hd sexy palimas.mobi xexi movie
malayalifuck dunato.mobi sex vedios malayalam
sexy film video hindi mai collegeporntrends.com tamilplay.com 2015 movies download
hot romantic sex porn alohaporn.net xnxx japnese
دانا فسبولى arabicaporn.com مصريه متناكه