nullcon 2011 - sslsmart – smart ssl cipher enumeration

12
SSLSmart Smart SSL Cipher Enumeration Gursev Singh Kalra nullcon | Feb26, 2011

Upload: nu-the-open-security-community

Post on 29-Nov-2014

1.417 views

Category:

Technology


2 download

DESCRIPTION

SSLSmart – Smart SSL Cipher Enumeration by Gursev Singh Kalra

TRANSCRIPT

Page 1: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

SSLSmart – Smart SSL

Cipher Enumeration

Gursev Singh Kalra

nullcon | Feb26, 2011

Page 2: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

www.foundstone.com

© 2010, McAfee, Inc.

Agenda

►Introduction

►Why Enumerate SSL Ciphers?

►Why SSLSmart?

►SSLSmart Demonstrations

►Q&A

Page 3: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

www.foundstone.com

© 2010, McAfee, Inc.

Introduction

►Who am I?

■ Managing Consultant – Foundstone Professional

Services

■ Web Applications, Networks, Mobile Applications,

Research, Tools…

Page 4: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

www.foundstone.com

© 2010, McAfee, Inc.

Why Enumerate SSL Ciphers?

►PCI Compliance

►Web Application Penetration Testing

►Network Assessments

►Insecure Crypto Implementation

Page 5: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

www.foundstone.com

© 2010, McAfee, Inc.

Why SSLSmart?

Flexible WYSIWYG

Open Source and Cross Platform

Rich Reporting

SSLSmart

Page 6: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

www.foundstone.com

© 2010, McAfee, Inc.

Flexibility

• Granular Cipher Control

• Certificate Verification

• Proxy Support

• Content and CONNECT Tests

Page 7: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

www.foundstone.com

© 2010, McAfee, Inc.

What You See Is What You Get

Page 8: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

www.foundstone.com

© 2010, McAfee, Inc.

Open Source and Cross Platform

• Works with Ruby 1.8.6, 1.8.7, 1.9.1 & 1.9.2

• Tested on Windows, Linux

Page 9: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

www.foundstone.com

© 2010, McAfee, Inc.

Rich Reporting

• Text

• HTML

• XML

Page 10: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

www.foundstone.com

© 2010, McAfee, Inc.

SSLSmart Demonstrations

►SSLSmart GUI

►Custom scripts using SSLSmart API’s

Page 11: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

www.foundstone.com

© 2010, McAfee, Inc.

Queries

Page 12: nullcon 2011 - SSLSmart – Smart SSL Cipher Enumeration

www.foundstone.com

© 2010, McAfee, Inc.

Thank You

Gursev Kalra

[email protected]