Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Online "Passive" Info Gathering Tools

Online "Passive" Info Gathering Tools

From: <appsec_at_technicalinfo.net>
Date: Fri, 17 Oct 2003 23:40:42 +0100

Hey there,

I have been working to bring together a number of links/forms together to make it simpler to carryout "passive" information gathering phases during an assessment. While there is a vast number of online tools - I have gatherd togther some of my favourites - but I can't appear to find one specific online tool that would be quite useful in alot of cases... specially in the precursor to web application assessments.

Does anyone know of, or have, a link to a site that does the following:
1. given an website running HTTPS - can display (and perferably analyse) the SSL certificate in a nice way.
2. connect to website running HTTPS - and chck what versions and encryption levels the server handles (e.g. SSL v.2, SSL v.3, TLS, 40 bit, 56 bit....)
3. (or more flexibly) given a DNS name and specific port - identify the version of SSL/certificate.

While there are a number of tools that can do this (such as Nessus) - are there any sites around that provide this level of SSL/HTTPS analysis. Perferably, the hosting site should be reliable and be around for more than a couple of months (trustworthy would be nice too). :-)

For those interested, the current collection of tools (and their righful owners links) can be found at: http://www.technicalinfo.net/tools/index.html

Cheers,

Gunter
Received on Oct 17 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]