cnp3 / ebook

Third edition of the Computer Networking: Principles, Protocols and Practice ebook
https://www.computer-networking.info
117 stars 42 forks source link

Security issues with the website #138

Open emanruse opened 1 year ago

emanruse commented 1 year ago

https://www.ssllabs.com/ shows very bad info about https://www.computer-networking.info/

That doesn't speak really well about those who teach others about networking.

obonaventure commented 11 months ago

Thanks for the report. This requires a new version of the SSL library. We'll work on that in January

./testssl.sh https://www.computer-networking.info

########################################################### testssl.sh 3.2rc3 from https://testssl.sh/dev/ (7829821 2023-12-09 18:13:24)

  This program is free software. Distribution and
         modification under GPLv2 permitted.
  USAGE w/o ANY WARRANTY. USE IT AT YOUR OWN RISK!

   Please file bugs @ https://testssl.sh/bugs/

###########################################################

Using "LibreSSL 3.3.6" [~72 ciphers] on mac-SE23-325:/usr/bin/openssl (built: "date not available", platform: "information not available")

Start 2023-12-22 16:44:05 -->> 130.104.228.140:443 (www.computer-networking.info) <<--

Further IP addresses: 2001:6a8:308f:8:0:82ff:fe68:e48c rDNS (130.104.228.140): -- Service detected: HTTP

Testing protocols via sockets except NPN+ALPN

SSLv2 not offered (OK) SSLv3 not offered (OK) TLS 1 offered (deprecated) TLS 1.1 offered (deprecated) TLS 1.2 offered (OK) TLS 1.3 not offered and downgraded to a weaker protocol NPN/SPDY Local problem: /usr/bin/openssl doesn't support NPN/SPDY ALPN/HTTP2 not offered

Testing cipher categories

NULL ciphers (no encryption) not offered (OK) Anonymous NULL Ciphers (no authentication) not offered (OK) Export ciphers (w/o ADH+NULL) not offered (OK) LOW: 64 Bit + DES, RC[2,4], MD5 (w/o export) offered (NOT ok) Triple DES Ciphers / IDEA offered Obsoleted CBC ciphers (AES, ARIA etc.) offered Strong encryption (AEAD ciphers) with no FS offered (OK) Forward Secrecy strong encryption (AEAD ciphers) offered (OK)

Testing server's cipher preferences

Hexcode Cipher Suite Name (OpenSSL) KeyExch. Encryption Bits Cipher Suite Name (IANA/RFC)

SSLv2