isvsecwatch / httpstracker

Our main issue tracker for ISV security issues, such as the SSL/TLS configuration of their online stores.
3 stars 0 forks source link

chatvc9.contactcenterlive.nl - outsourced customer support chat #81

Closed isvsecwatch-report closed 8 years ago

isvsecwatch-report commented 9 years ago

SSL Server Test Results https://www.ssllabs.com/ssltest/analyze.html?d=chatvc9.contactcenterlive.nl (F)

isvsecwatch-report commented 8 years ago

Cipherscan Results

Target: chatvc9.contactcenterlive.nl:443

prio  ciphersuite           protocols  pubkey_size  signature_algoritm     trusted  ticket_hint  ocsp_staple  pfs                 curves  curves_ordering
1     AES256-SHA            TLSv1      2048         sha1WithRSAEncryption  True     None         True         None                None
2     ECDHE-RSA-AES128-SHA  TLSv1      2048         sha1WithRSAEncryption  True     None         True         ECDH,P-256,256bits  server
3     ECDHE-RSA-AES256-SHA  TLSv1      2048         sha1WithRSAEncryption  True     None         True         ECDH,P-256,256bits  server
4     RC4-MD5               SSLv2      2048         sha1WithRSAEncryption  False    None         False        None                None    server
5     DES-CBC3-MD5          SSLv2      2048         sha1WithRSAEncryption  False    None         False        None                None    server

OCSP stapling: supported
Cipher ordering: server
Curves ordering: server - fallback: no
Server DOESN'T support secure renegotiation
Server supported compression methods: NONE

TLS Tolerance: no
Fallbacks required:
big-SSLv3 config not supported, connection failed
big-TLSv1.0 no fallback req, connected: TLSv1 AES256-SHA
big-TLSv1.1 no fallback req, connected: TLSv1 AES256-SHA
big-TLSv1.2 config not supported, connection failed
small-SSLv3 no fallback req, connected: SSLv3 RC4-SHA
small-TLSv1.0 no fallback req, connected: TLSv1 AES128-SHA
small-TLSv1.1 no fallback req, connected: TLSv1 AES128-SHA
small-TLSv1.2 no fallback req, connected: TLSv1 AES128-SHA
v2-big-TLSv1.2 no fallback req, connected: TLSv1 AES128-SHA
v2-small-SSLv3 no fallback req, connected: SSLv3 RC4-SHA
v2-small-TLSv1.0 no fallback req, connected: TLSv1 AES128-SHA
v2-small-TLSv1.1 no fallback req, connected: TLSv1 AES128-SHA
v2-small-TLSv1.2 no fallback req, connected: TLSv1 AES128-SHA
isvsecwatch-report commented 8 years ago

Notified via email; info@contactcenterlive.nl

isvsecwatch-report commented 8 years ago

No change, vulnerable to DROWN.

isvsecwatch-report commented 8 years ago

No change.

isvsecwatch-report commented 8 years ago

No change. Closing as unresolved.