Nmap Development mailing list archives

Re: sslv2 script bug


From: Matt Selsky <selsky () columbia edu>
Date: Fri, 9 Jul 2010 23:53:43 -0400 (EDT)

Is there any way you can get a capture of the server traffic? We can see
what the script is detecting and what else it should look for.

Packet capture of the SSLv2 probe itself is attached.

When I turned on debugging, the script prints:

PORT    STATE SERVICE  REASON  VERSION
465/tcp open  ssl/smtp syn-ack Sendmail 8.14.4/8.14.3/CUIT
| sslv2: server still supports SSLv2
|_      the server didn't offer any cyphers
Service Info: Host: serrano.cc.columbia.edu; OS: Unix

It seems like if no ciphers are offered for SSLv2, then it should be considered off. Maybe in verbose mode, if would report "supports SSLv2, but no ciphers".

Cheers,


--
Matt

Attachment: smtp-sslv2-check.pcap
Description:

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/

Current thread: