{"id":3363,"date":"2015-10-08T21:30:27","date_gmt":"2015-10-08T13:30:27","guid":{"rendered":"http:\/\/www.alfredivy.per.sg\/blogger\/?p=3363"},"modified":"2016-01-04T15:11:35","modified_gmt":"2016-01-04T07:11:35","slug":"exploring-https-encryption","status":"publish","type":"post","link":"https:\/\/www.alfredivy.sg\/blogger\/2015\/10\/exploring-https-encryption\/","title":{"rendered":"Exploring HTTPS encryption"},"content":{"rendered":"<p>This is a post on HTTPS encryption long time coming. \u00a0I have been patching SSL\/TLS vulnerabilities in various systems, so I thought I should put all my notes in one place.<\/p>\n<p>HTTPS encryption uses SSL and later TLS to protect your HTTP traffic.<\/p>\n<ul>\n<li>SSLv2 &#8211; not used any more.<\/li>\n<li>SSLv3 &#8211; vulnerable to BEAST attack <a href=\"https:\/\/www.imperialviolet.org\/2011\/09\/23\/chromeandbeast.html\" target=\"_blank\">link<br \/>\n<\/a>From Nessus scanner<\/li>\n<\/ul>\n<blockquote><p>A vulnerability exists in SSL 3.0 and TLS 1.0 that could allow<br \/>\ninformation disclosure if an attacker intercepts encrypted traffic<br \/>\nserved from an affected system.<\/p>\n<p>TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are<br \/>\nnot affected.<\/p><\/blockquote>\n<ul>\n<li>TLS1.0- vulnerable to BEAST attack<br \/>\nSee above.<\/li>\n<li>TLS1.1<\/li>\n<li>TLS1.2<\/li>\n<\/ul>\n<p>cURL is a popular tool to standin as a web browser in scripts. \u00a0<a href=\"http:\/\/curl.haxx.se\/docs\/manpage.html\" target=\"_blank\">manpage<\/a>\u00a0 Here are some scripts to test HTTPS.<\/p>\n<blockquote><p>curl -v &#8220;https:\/\/www.myorg.org&#8221;<br \/>\ncurl -v &#8211;tlsv1\u00a0&#8220;https:\/\/www.myorg.org&#8221;<br \/>\ncurl -v &#8211;tlsv1.2 &#8220;https:\/\/www.myorg.org&#8221; \u00a0for cURL 7.34 or later.<br \/>\ncurl -v &#8211;sslv2\u00a0&#8220;https:\/\/www.myorg.org&#8221;<br \/>\ncurl -v &#8211;sslv3\u00a0&#8220;https:\/\/www.myorg.org&#8221;<\/p><\/blockquote>\n<p>List of SSL and TLS error codes from cURL <a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Mozilla\/Projects\/NSS\/SSL_functions\/sslerr.html\" target=\"_blank\">mozilla<\/a><\/p>\n<p>JavaSE 7 SSL overview <a href=\"http:\/\/docs.oracle.com\/javase\/7\/docs\/technotes\/guides\/security\/jsse\/JSSERefGuide.html#SSLOverview\" target=\"_blank\">link<\/a>\u00a0 These are the clients initiating the requests.<\/p>\n<p>You can verify the certificate of a website by hand. \u00a0You will need OpenSSL and a CA certificate. \u00a0<a href=\"http:\/\/t.co\/0F8hZ3zAtt\" target=\"_blank\">nixCraft<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is a post on HTTPS encryption long time coming. \u00a0I have been patching SSL\/TLS vulnerabilities in various systems, so I thought I should put all my notes in one place. HTTPS encryption uses SSL and later TLS to protect&hellip; <\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[249,237],"tags":[245,385],"class_list":["post-3363","post","type-post","status-publish","format-standard","hentry","category-internet","category-security","tag-ssl","tag-tls"],"_links":{"self":[{"href":"https:\/\/www.alfredivy.sg\/blogger\/wp-json\/wp\/v2\/posts\/3363","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.alfredivy.sg\/blogger\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.alfredivy.sg\/blogger\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.alfredivy.sg\/blogger\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.alfredivy.sg\/blogger\/wp-json\/wp\/v2\/comments?post=3363"}],"version-history":[{"count":9,"href":"https:\/\/www.alfredivy.sg\/blogger\/wp-json\/wp\/v2\/posts\/3363\/revisions"}],"predecessor-version":[{"id":3398,"href":"https:\/\/www.alfredivy.sg\/blogger\/wp-json\/wp\/v2\/posts\/3363\/revisions\/3398"}],"wp:attachment":[{"href":"https:\/\/www.alfredivy.sg\/blogger\/wp-json\/wp\/v2\/media?parent=3363"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.alfredivy.sg\/blogger\/wp-json\/wp\/v2\/categories?post=3363"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.alfredivy.sg\/blogger\/wp-json\/wp\/v2\/tags?post=3363"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}