.

.

Scanning TLS Server Configurations With Burp Suite

By on 16:52
In this post, we present our new Burp Suite extension "TLS-Attacker".
Using this extension penetration testers and security researchers can assess the security of TLS server configurations directly from within Burp Suite.
The extension is based on the TLS-Attacker framework and the TLS-Scanner, both of which are developed by the Chair for Network and Data Security.

You can find the latest release of our extension at: https://github.com/RUB-NDS/TLS-Attacker-BurpExtension/releases

TLS-Scanner

Thanks to the seamless integration of the TLS-Scanner into the BurpSuite, the penetration tester only needs to configure a single parameter: the host to be scanned.  After clicking the Scan button, the extension runs the default checks and responds with a report that allows penetration testers to quickly determine potential issues in the server's TLS configuration.  Basic tests check the supported cipher suites and protocol versions.  In addition, several known attacks on TLS are automatically evaluated, including Bleichenbacher's attack, Padding Oracles, and Invalid Curve attacks.

Furthermore, the extension allows fine-tuning for the configuration of the underlying TLS-Scanner.  The two parameters parallelProbes and overallThreads can be used to improve the scan performance (at the cost of increased network load and resource usage).

It is also possible to configure the granularity of the scan using Scan Detail and Danger Level. The level of detail contained in the returned scan report can also be controlled using the Report Detail setting.

Please refer to the GitHub repositories linked above for further details on configuration and usage of TLS-Scanner.

Scan History 

If several hosts are scanned, the Scan History tab keeps track of the preformed scans and is a useful tool when comparing the results of subsequent scans.

Additional functions will follow in later versions

Currently, we are working on integrating an at-a-glance rating mechanism to allow for easily estimating the security of a scanned host's TLS configuration.

This is a combined work of Nurullah Erinola, Nils Engelbertz, David Herring, Juraj Somorovsky, Vladislav Mladenov, and Robert Merget.  The research was supported by the European Commission through the FutureTrust project (grant 700542-Future-Trust-H2020-DS-2015-1).

If you would like to learn more about TLS, Juraj and Robert will give a TLS Training at Ruhrsec on the 27th of May 2019. There are still a few seats left.
More info
  1. Hacker Tools Free Download
  2. Hacker Tools Free Download
  3. Hacking Tools Mac
  4. Pentest Tools Find Subdomains
  5. Install Pentest Tools Ubuntu
  6. Black Hat Hacker Tools
  7. Hacking Tools For Windows Free Download
  8. Hacking Tools 2020
  9. Pentest Tools Github
  10. Termux Hacking Tools 2019
  11. Pentest Tools List
  12. Top Pentest Tools
  13. Hacking Tools Software
  14. Hacking Apps
  15. Pentest Tools Online
  16. Hacking Tools Windows
  17. Beginner Hacker Tools
  18. Termux Hacking Tools 2019
  19. Hacking Tools Hardware
  20. Pentest Tools Online
  21. Pentest Tools Subdomain
  22. Hack Tools For Ubuntu
  23. Hack Tool Apk No Root
  24. Hack Tools Download
  25. Tools 4 Hack
  26. Hacker Search Tools
  27. Pentest Tools Review
  28. Nsa Hack Tools Download
  29. Pentest Tools Port Scanner
  30. Hackers Toolbox
  31. Hacker Tools Mac
  32. How To Hack
  33. Hacking Tools For Mac
  34. Hacking Tools Mac
  35. Pentest Tools For Windows
  36. Android Hack Tools Github
  37. Hacking Tools For Windows Free Download
  38. How To Install Pentest Tools In Ubuntu
  39. Pentest Tools Download
  40. Hack Tools Download
  41. Hack Tools Online
  42. Hacking Tools 2019
  43. Hacking Tools Windows
  44. Hacker Tools List
  45. Android Hack Tools Github
  46. Hack Tools Pc
  47. How To Install Pentest Tools In Ubuntu
  48. Nsa Hack Tools Download
  49. Hacking Tools Kit
  50. Blackhat Hacker Tools
  51. Hack Tools For Mac
  52. Android Hack Tools Github
  53. Hack Tools Github
  54. Hacking Tools For Windows Free Download
  55. Hacker Tools Mac
  56. Pentest Automation Tools
  57. Hacking Tools Hardware
  58. Hacker Tools Free Download
  59. Hacking Tools Windows 10
  60. Game Hacking
  61. Hacker Tools Linux
  62. Hacker Tools Linux
  63. Hack Tools For Mac
  64. Pentest Automation Tools
  65. Pentest Tools Android
  66. Hack Tools For Windows
  67. Hacker Tools Windows
  68. Pentest Tools Free
  69. Hack Tool Apk
  70. Hacker Security Tools

0 comentarios:

Publicar un comentario