:
:

Powered by GetResponse email marketing software

Actually Make Money Online

Your Helpful Resource About "Actually Make Money Online"

Saturday, August 22, 2020

Scanning TLS Server Configurations With Burp Suite

In this post, we present our new Burp Suite extension "TLS-Attacker".
Using this extension penetration testers and security researchers can assess the security of TLS server configurations directly from within Burp Suite.
The extension is based on the TLS-Attacker framework and the TLS-Scanner, both of which are developed by the Chair for Network and Data Security.

You can find the latest release of our extension at: https://github.com/RUB-NDS/TLS-Attacker-BurpExtension/releases

TLS-Scanner

Thanks to the seamless integration of the TLS-Scanner into the BurpSuite, the penetration tester only needs to configure a single parameter: the host to be scanned.  After clicking the Scan button, the extension runs the default checks and responds with a report that allows penetration testers to quickly determine potential issues in the server's TLS configuration.  Basic tests check the supported cipher suites and protocol versions.  In addition, several known attacks on TLS are automatically evaluated, including Bleichenbacher's attack, Padding Oracles, and Invalid Curve attacks.

Furthermore, the extension allows fine-tuning for the configuration of the underlying TLS-Scanner.  The two parameters parallelProbes and overallThreads can be used to improve the scan performance (at the cost of increased network load and resource usage).

It is also possible to configure the granularity of the scan using Scan Detail and Danger Level. The level of detail contained in the returned scan report can also be controlled using the Report Detail setting.

Please refer to the GitHub repositories linked above for further details on configuration and usage of TLS-Scanner.

Scan History 

If several hosts are scanned, the Scan History tab keeps track of the preformed scans and is a useful tool when comparing the results of subsequent scans.

Additional functions will follow in later versions

Currently, we are working on integrating an at-a-glance rating mechanism to allow for easily estimating the security of a scanned host's TLS configuration.

This is a combined work of Nurullah Erinola, Nils Engelbertz, David Herring, Juraj Somorovsky, Vladislav Mladenov, and Robert Merget.  The research was supported by the European Commission through the FutureTrust project (grant 700542-Future-Trust-H2020-DS-2015-1).

If you would like to learn more about TLS, Juraj and Robert will give a TLS Training at Ruhrsec on the 27th of May 2019. There are still a few seats left.

Continue reading


  1. Hacking App
  2. Tools Used For Hacking
  3. Pentest Reporting Tools
  4. Pentest Tools Tcp Port Scanner
  5. Computer Hacker
  6. Hacking Tools For Mac
  7. Hack App
  8. Pentest Tools Subdomain
  9. Hacker
  10. Game Hacking
  11. Growth Hacker Tools
  12. Hacking Tools For Windows 7
  13. Pentest Tools Website Vulnerability
  14. Pentest Box Tools Download
  15. Pentest Tools Nmap
  16. Hacker Tools For Ios
  17. How To Make Hacking Tools
  18. Hacking Tools Online
  19. Pentest Box Tools Download
  20. Pentest Tools Open Source
  21. Hack Tools Download
  22. Termux Hacking Tools 2019
  23. Hacker Tools Mac
  24. Hack Tools For Games
  25. Pentest Tools Kali Linux
  26. Hack Tools Mac
  27. Hacker Techniques Tools And Incident Handling
  28. Pentest Tools Open Source
  29. Hack Tools Download
  30. What Are Hacking Tools
  31. Hacking Tools For Windows
  32. Hacking Tools Software
  33. Hacking Tools 2019
  34. Hacking Tools 2020
  35. Hacker Tools For Windows
  36. Hacker Tools Hardware
  37. Hacker Tools List
  38. World No 1 Hacker Software
  39. Pentest Tools Online
  40. Github Hacking Tools
  41. Beginner Hacker Tools
  42. Pentest Tools List
  43. Pentest Recon Tools
  44. Pentest Tools Github
  45. Hack Tool Apk No Root
  46. Pentest Tools For Windows
  47. Pentest Box Tools Download
  48. How To Install Pentest Tools In Ubuntu
  49. Hack Tools Pc
  50. Hack Tools Mac
  51. Black Hat Hacker Tools
  52. Hacking Tools Mac
  53. Hack Tools Github
  54. Hacking Tools For Pc
  55. New Hacker Tools
  56. Tools For Hacker
  57. Pentest Tools Alternative
  58. Pentest Tools Download
  59. Hackers Toolbox
  60. What Is Hacking Tools
  61. Tools Used For Hacking
  62. Hacker Tools For Ios
  63. Pentest Tools For Android
  64. What Are Hacking Tools
  65. Blackhat Hacker Tools
  66. Pentest Tools Windows
  67. Best Pentesting Tools 2018
  68. Hacking Tools Windows
  69. Hak5 Tools
  70. Pentest Tools Online
  71. Pentest Tools Framework
  72. Pentest Box Tools Download
  73. Hacking Tools Usb
  74. Hacking Tools For Windows 7
  75. Pentest Tools Tcp Port Scanner
  76. Pentest Tools Bluekeep
  77. Hacking Tools For Mac
  78. Hack Apps
  79. Hack Rom Tools
  80. Hacker
  81. Hack Tool Apk No Root
  82. Pentest Tools Port Scanner
  83. Pentest Tools Website Vulnerability
  84. Pentest Tools For Ubuntu
  85. Hacking Tools 2020
  86. Hack Rom Tools
  87. Nsa Hacker Tools
  88. Pentest Tools Apk
  89. Hacker Tools For Pc
  90. Nsa Hack Tools Download
  91. Pentest Tools Review
  92. Hack Tools 2019
  93. Hacking Tools For Windows Free Download
  94. How To Hack
  95. Hacker Techniques Tools And Incident Handling
  96. Hack Website Online Tool
  97. Hack Tools 2019
  98. Hackrf Tools
  99. Hacking Tools And Software
  100. Hacker Tools 2020
  101. Pentest Tools List
  102. Game Hacking
  103. Hack Tools For Mac
  104. Hacker Tools 2019
  105. Game Hacking
  106. Hacking Tools Kit
  107. Hacker Tools Github
  108. Top Pentest Tools
  109. How To Install Pentest Tools In Ubuntu
  110. Hacking Tools For Mac
  111. Pentest Tools Github
  112. Pentest Reporting Tools
  113. Hacker Tools Software
  114. Hacker Search Tools
  115. Termux Hacking Tools 2019
  116. Hacking Tools 2019
  117. Hack Tools Download
  118. Best Hacking Tools 2019
  119. Pentest Tools For Mac
  120. Hack Tools
  121. Hacking Tools And Software
  122. Hack Tools Download
  123. Best Hacking Tools 2020
  124. Hacking Tools
  125. Pentest Tools Online
  126. Pentest Tools
  127. Hack Tools For Ubuntu
  128. Tools 4 Hack
  129. Hack App
  130. Hack Tool Apk No Root
  131. Hacker Tools Software
  132. Pentest Tools Find Subdomains

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home