Nmap Development mailing list archives

Re: [NSE] Extended ssl-enum-ciphers script


From: Daniel Miller <bonsaiviking () gmail com>
Date: Tue, 12 Aug 2014 07:17:03 -0500

On Tue, Aug 12, 2014 at 4:15 AM, Bojan Zdrnja (SANS ISC) <
bojan.isc () gmail com> wrote:

Btw, according to this article that I later found:
http://msdn.microsoft.com/en-us/library/windows/desktop/aa374757(v=vs.85).aspx
Schannel on Windows supports a total of 55 ciphers (30 by default and 25
that have to be added), so with a normal setup on Windows there should
never be a case when more than 64 ciphers are supported.


That's good to know. However, the script will only attempt 64 ciphers at a
time, regardless of server capability. So Windows is the limiting factor,
but it affects every server we scan, so this is still a relevant issue.

Dan
_______________________________________________
Sent through the dev mailing list
http://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/


Current thread: