Nmap-scripts-ssl: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
 
Zeile 22: Zeile 22:
 
Nmap done: 1 IP address (1 host up) scanned in 0.80 seconds
 
Nmap done: 1 IP address (1 host up) scanned in 0.80 seconds
 
</pre>
 
</pre>
 
 
 
 
 
=Welche Cipher Suits werden angeboten=
 
=Welche Cipher Suits werden angeboten=
 
*nmap -sV --script ssl-enum-ciphers 192.168.34.1 -p 993
 
*nmap -sV --script ssl-enum-ciphers 192.168.34.1 -p 993

Aktuelle Version vom 26. Februar 2023, 13:29 Uhr

Welche Certs werden angeboten

  • nmap --script ssl-cert.nse 192.168.34.1 -p 993
Starting Nmap 7.93 ( https://nmap.org ) at 2023-02-26 14:26 CET
Nmap scan report for ns1.vulkan.int (192.168.34.1)
Host is up (0.0011s latency).

PORT    STATE SERVICE
993/tcp open  imaps
| ssl-cert: Subject: commonName=debian.secure.lab
| Subject Alternative Name: DNS:debian.secure.lab
| Issuer: commonName=debian.secure.lab
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2023-02-26T07:29:41
| Not valid after:  2033-02-23T07:29:41
| MD5:   889faefa703e991ae039b481b47e788b
|_SHA-1: 72b4345cf9707406608c2bc0f594b9144d2f48c8
MAC Address: 08:00:27:1B:67:A0 (Oracle VirtualBox virtual NIC)

Nmap done: 1 IP address (1 host up) scanned in 0.80 seconds

Welche Cipher Suits werden angeboten

  • nmap -sV --script ssl-enum-ciphers 192.168.34.1 -p 993
Starting Nmap 7.93 ( https://nmap.org ) at 2023-02-26 14:27 CET
Nmap scan report for ns1.vulkan.int (192.168.34.1)
Host is up (0.0011s latency).

PORT    STATE SERVICE  VERSION
993/tcp open  ssl/imap Dovecot imapd
| ssl-enum-ciphers: 
|   TLSv1.0: 
|     ciphers: 
|       TLS_DHE_RSA_WITH_AES_128_CBC_SHA (dh 4096) - A
|       TLS_DHE_RSA_WITH_AES_256_CBC_SHA (dh 4096) - A
|       TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA (dh 4096) - A
|       TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA (dh 4096) - A
|       TLS_DHE_RSA_WITH_SEED_CBC_SHA (dh 4096) - A
|       TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (secp256r1) - A
|     compressors: 
|       NULL
|     cipher preference: client
|   TLSv1.1: 
|     ciphers: 
|       TLS_DHE_RSA_WITH_AES_128_CBC_SHA (dh 4096) - A
|       TLS_DHE_RSA_WITH_AES_256_CBC_SHA (dh 4096) - A
|       TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA (dh 4096) - A
|       TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA (dh 4096) - A
|       TLS_DHE_RSA_WITH_SEED_CBC_SHA (dh 4096) - A
|       TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (secp256r1) - A
|     compressors: 
|       NULL
|     cipher preference: client