Loading HuntDB...

bring grtp.co up to A grade on SSLLabs

Low
G
Gratipay
Submitted None
Reported by mmyamin

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
Issues at https://grtp.co/ reference for Weak SSL Ciphers:https://www.owasp.org/index.php/Testing_for_Weak_SSL/TLS_Ciphers,_Insufficient_Transport_Layer_Protection_(OTG-CRYPST-001) Weak SSL Ciphers supported at port 443: TLS 1.0: TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA (ec 256) - C TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA (dh 1024) - D TLS_RSA_WITH_3DES_EDE_CBC_SHA (rsa 4096) - C TLSv1.2: TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA (ec 256) - C TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA (dh 1024) - D TLS_RSA_WITH_3DES_EDE_CBC_SHA (rsa 4096) - C Evidence of Weak SSL ciphers is attached in figure 1 Weak SSH Ciphers supported at port 22: Reference :https://www.tenable.com/plugins/index.php?view=single&id=70658 Supported CBC ciphers aes128-cbc 3des-cbc blowfish-cbc cast128-cbc aes192-cbc aes256-cbc Evidence related to supported CBC ciphers is attached in figure 2

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$1.00

Submitted

Weakness

Violation of Secure Design Principles