Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




webappsec logo WebApp Sec mailing list archives

SSL version selection query
From: "Abhishek Kumar" <abhishek.kumar () paladion net>
Date: Tue, 23 Mar 2004 19:00:45 +0530

Hello,

I have a query regarding SSL. There is a web server on which both SSLv2
and SSLv3 are enabled. Along with this all the Cipher suites (including
low strength) are also enabled on this server.

A client is using a browser which supports both SSLv2 and SSLv3, with
high strength encryption. 

My question is:

What version of SSL and Cipher suite will be chosen by default? Will it
always be SSLv3 with maximum strength encryption ? Or is there a
situation where SSLv2 can also be selected with some low strength Cipher
suite.

Thanks

-Abhishek



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]