aeris / cryptcheck

Verify some SSL/TLS website or XMPP implementation
GNU Affero General Public License v3.0
185 stars 20 forks source link

Testing against unsafe renegotiation CVE-2009-3555 #27

Open lanodan opened 7 years ago

lanodan commented 7 years ago

As of 2016 few servers still seems to be vulnerable to CVE-2009-3555. I currently test it with (Mozilla Firefox)[https://wiki.mozilla.org/Security:Renegotiation] with security.ssl.require_safe_negotiation = true & security.ssl.treat_unsafe_negotiation_as_broken = true. Latest example is akamaihd.