Saturday, August 22, 2020

Scanning TLS Server Configurations With Burp Suite

In this post, we present our new Burp Suite extension "TLS-Attacker".
Using this extension penetration testers and security researchers can assess the security of TLS server configurations directly from within Burp Suite.
The extension is based on the TLS-Attacker framework and the TLS-Scanner, both of which are developed by the Chair for Network and Data Security.

You can find the latest release of our extension at: https://github.com/RUB-NDS/TLS-Attacker-BurpExtension/releases

TLS-Scanner

Thanks to the seamless integration of the TLS-Scanner into the BurpSuite, the penetration tester only needs to configure a single parameter: the host to be scanned.  After clicking the Scan button, the extension runs the default checks and responds with a report that allows penetration testers to quickly determine potential issues in the server's TLS configuration.  Basic tests check the supported cipher suites and protocol versions.  In addition, several known attacks on TLS are automatically evaluated, including Bleichenbacher's attack, Padding Oracles, and Invalid Curve attacks.

Furthermore, the extension allows fine-tuning for the configuration of the underlying TLS-Scanner.  The two parameters parallelProbes and overallThreads can be used to improve the scan performance (at the cost of increased network load and resource usage).

It is also possible to configure the granularity of the scan using Scan Detail and Danger Level. The level of detail contained in the returned scan report can also be controlled using the Report Detail setting.

Please refer to the GitHub repositories linked above for further details on configuration and usage of TLS-Scanner.

Scan History 

If several hosts are scanned, the Scan History tab keeps track of the preformed scans and is a useful tool when comparing the results of subsequent scans.

Additional functions will follow in later versions

Currently, we are working on integrating an at-a-glance rating mechanism to allow for easily estimating the security of a scanned host's TLS configuration.

This is a combined work of Nurullah Erinola, Nils Engelbertz, David Herring, Juraj Somorovsky, Vladislav Mladenov, and Robert Merget.  The research was supported by the European Commission through the FutureTrust project (grant 700542-Future-Trust-H2020-DS-2015-1).

If you would like to learn more about TLS, Juraj and Robert will give a TLS Training at Ruhrsec on the 27th of May 2019. There are still a few seats left.
Related posts

  1. Hacker Tools Software
  2. Hacking Tools For Pc
  3. Hacking Tools Online
  4. Github Hacking Tools
  5. Hacking Tools For Windows 7
  6. Pentest Tools For Android
  7. Hak5 Tools
  8. Hacking Tools Windows
  9. Termux Hacking Tools 2019
  10. Hacker Tools Windows
  11. Nsa Hacker Tools
  12. Easy Hack Tools
  13. Hack Tools For Games
  14. Best Hacking Tools 2019
  15. How To Hack
  16. Hacking Tools Windows 10
  17. How To Install Pentest Tools In Ubuntu
  18. Pentest Tools Apk
  19. Hack Tools For Ubuntu
  20. How To Hack
  21. Hack Tools Mac
  22. Computer Hacker
  23. Nsa Hack Tools Download
  24. Beginner Hacker Tools
  25. Pentest Tools Website
  26. Tools Used For Hacking
  27. Growth Hacker Tools
  28. Pentest Tools Android
  29. Hacker Tools For Ios
  30. Pentest Reporting Tools
  31. Hacking Tools Usb
  32. Pentest Tools For Mac
  33. Pentest Tools Website Vulnerability
  34. Pentest Tools Online
  35. Nsa Hack Tools
  36. Beginner Hacker Tools
  37. Hacking Tools For Windows
  38. Best Hacking Tools 2019
  39. Tools For Hacker
  40. Hacking Tools Windows 10
  41. Pentest Tools Url Fuzzer
  42. Hack Apps
  43. Usb Pentest Tools
  44. Hack Tools For Mac
  45. Hack Apps
  46. Hackrf Tools
  47. Hacker Tools Online
  48. Nsa Hack Tools
  49. Hacking Tools
  50. Tools 4 Hack
  51. Hacker Tools For Pc
  52. Hack Tools Pc
  53. Growth Hacker Tools
  54. Hack Tool Apk No Root
  55. Hacks And Tools
  56. New Hack Tools
  57. Hack Tools Github
  58. Hacking Tools Online
  59. Pentest Automation Tools
  60. Hacking Tools Windows
  61. Pentest Tools Review
  62. Hacking Tools For Games
  63. Hacking Tools 2020
  64. Pentest Tools For Android
  65. Hack Apps
  66. New Hack Tools
  67. Hack Tools Download
  68. Pentest Tools
  69. Hacking Tools Free Download
  70. Wifi Hacker Tools For Windows
  71. Wifi Hacker Tools For Windows
  72. Hacker Techniques Tools And Incident Handling
  73. Hacking Tools For Games
  74. Hacker Tools Linux
  75. Pentest Tools For Android
  76. Hacker Tools For Ios
  77. Hacker Tools Github
  78. Hacking Tools 2019
  79. Top Pentest Tools
  80. What Is Hacking Tools
  81. Free Pentest Tools For Windows
  82. Growth Hacker Tools
  83. Hacking Tools For Windows Free Download
  84. Hacking Tools Software
  85. Pentest Tools Bluekeep
  86. Hack Tools For Ubuntu
  87. Hacking Tools For Windows Free Download
  88. Pentest Tools For Windows
  89. Pentest Automation Tools
  90. Hack Tool Apk
  91. Black Hat Hacker Tools
  92. Hack Tools For Pc
  93. Pentest Tools Framework
  94. Hack Tools For Games
  95. Hacker Tools 2020
  96. Hacker Tools Windows
  97. Hacker Tools Free Download
  98. Pentest Tools Subdomain
  99. Best Hacking Tools 2019
  100. Hacks And Tools
  101. Tools 4 Hack
  102. Growth Hacker Tools
  103. Github Hacking Tools
  104. Hackrf Tools
  105. New Hacker Tools
  106. Hacker Tools 2019
  107. Hacker Search Tools
  108. Hacker Tools Hardware
  109. How To Make Hacking Tools
  110. Top Pentest Tools
  111. Hacker Tools Apk
  112. Hacker Tools
  113. Hacking Tools For Windows
  114. Hacking Tools Github
  115. Pentest Tools Subdomain
  116. Pentest Tools Port Scanner
  117. Pentest Recon Tools
  118. Hacking Tools For Games
  119. Pentest Tools Open Source
  120. Hack Rom Tools
  121. Nsa Hack Tools Download
  122. Hacking Tools And Software
  123. Github Hacking Tools
  124. Hackrf Tools
  125. Pentest Tools Tcp Port Scanner
  126. How To Install Pentest Tools In Ubuntu
  127. Hack Rom Tools
  128. Hacker Tools For Mac
  129. New Hacker Tools
  130. Hack And Tools
  131. Hacker Tools Free
  132. Hacking Tools Online
  133. Hack Tools Download
  134. Pentest Tools List
  135. Hacking Tools Windows 10
  136. Hack Rom Tools
  137. Hacking Tools For Windows
  138. Hack App
  139. Pentest Automation Tools
  140. Hacking Tools Hardware
  141. Pentest Tools Url Fuzzer
  142. Pentest Tools Alternative
  143. Hack Tools For Windows
  144. Hacking Tools Pc
  145. Hacker Tools Online
  146. What Are Hacking Tools
  147. Hack Rom Tools
  148. Hacking Tools For Mac
  149. Pentest Tools Open Source
  150. How To Hack
  151. Android Hack Tools Github
  152. Hack Tools 2019
  153. What Is Hacking Tools
  154. Hacking Tools Software

No comments:

Post a Comment