2023-10-14 11:27:55 +00:00
|
|
|
id: insecure-cipher-suite-detect
|
|
|
|
|
2023-06-03 18:56:35 +00:00
|
|
|
info:
|
|
|
|
name: Insecure Cipher Suite Detection
|
|
|
|
author: pussycat0x
|
|
|
|
severity: info
|
|
|
|
description: |
|
|
|
|
Weak ciphers are those encryption algorithms vulnerable to attack, often as a result of an insufficient key length.
|
|
|
|
reference:
|
|
|
|
- https://www.acunetix.com/vulnerabilities/web/tls-ssl-weak-cipher-suites/
|
|
|
|
metadata:
|
|
|
|
max-request: 4
|
|
|
|
tags: ssl
|
2023-10-14 11:27:55 +00:00
|
|
|
ssl:
|
|
|
|
- address: "{{Host}}:{{Port}}"
|
|
|
|
min_version: tls10
|
|
|
|
max_version: tls10
|
|
|
|
|
|
|
|
extractors:
|
|
|
|
- type: dsl
|
|
|
|
dsl:
|
|
|
|
- "tls_version, cipher"
|
|
|
|
matchers:
|
|
|
|
- type: word
|
|
|
|
part: cipher
|
|
|
|
words:
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_GCM_SHA256"
|
|
|
|
- "TLS_NULL_WITH_NULL_NULL"
|
|
|
|
- "TLS_DH_DSS_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_ECDH_RSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_128_CBC_SHA256"
|
|
|
|
- "TLS_RSA_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_SM4_CCM_SM3"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_GCM_SHA384"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_ECDH_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5"
|
|
|
|
- "TLS_RSA_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_MAGMA_CTR_OMAC"
|
|
|
|
- "TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_256_GCM_SHA384"
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_DHE_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA256"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_ECDHE_ECDSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA256"
|
|
|
|
- "TLS_RSA_WITH_NULL_MD5"
|
|
|
|
- "TLS_SHA384_SHA384"
|
|
|
|
- "TLS_SHA256_SHA256"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_GCM_SHA384"
|
|
|
|
- "TLS_RSA_WITH_NULL_SHA256"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA"
|
|
|
|
- "TLS_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_DH_DSS_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_CBC_SHA"
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_256_CBC_SHA384"
|
|
|
|
- "TLS_DH_anon_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_SEED_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_CBC_SHA256"
|
|
|
|
- "TLS_DHE_DSS_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDH_ECDSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_AES_128_CBC_SHA"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_NULL_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_AES_256_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_IDEA_CBC_MD5"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_KUZNYECHIK_CTR_OMAC"
|
|
|
|
- "TLS_ECDHE_RSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_28147_CNT_IMIT"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_DES_CBC_MD5"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC4_40_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_128_GCM_SHA256"
|
|
|
|
- "TLS_SM4_GCM_SM3"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_ECDHE_ECDSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_3DES_EDE_CBC_SHA"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5"
|
|
|
|
- "TLS_DH_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_ECDHE_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DHE_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_CBC_SHA256"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_GCM_SHA256"
|
|
|
|
- "TLS_ECDH_ECDSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_KRB5_WITH_3DES_EDE_CBC_MD5"
|
|
|
|
- "TLS_KRB5_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_RSA_WITH_NULL_SHA"
|
|
|
|
condition: or
|
|
|
|
|
|
|
|
- address: "{{Host}}:{{Port}}"
|
|
|
|
min_version: tls11
|
|
|
|
max_version: tls11
|
|
|
|
|
|
|
|
extractors:
|
|
|
|
- type: dsl
|
|
|
|
dsl:
|
|
|
|
- "tls_version, cipher"
|
|
|
|
matchers:
|
|
|
|
- type: word
|
|
|
|
part: cipher
|
|
|
|
words:
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_GCM_SHA256"
|
|
|
|
- "TLS_NULL_WITH_NULL_NULL"
|
|
|
|
- "TLS_DH_DSS_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_ECDH_RSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_128_CBC_SHA256"
|
|
|
|
- "TLS_RSA_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_SM4_CCM_SM3"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_GCM_SHA384"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_ECDH_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5"
|
|
|
|
- "TLS_RSA_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_MAGMA_CTR_OMAC"
|
|
|
|
- "TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_256_GCM_SHA384"
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_DHE_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA256"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_ECDHE_ECDSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA256"
|
|
|
|
- "TLS_RSA_WITH_NULL_MD5"
|
|
|
|
- "TLS_SHA384_SHA384"
|
|
|
|
- "TLS_SHA256_SHA256"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_GCM_SHA384"
|
|
|
|
- "TLS_RSA_WITH_NULL_SHA256"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA"
|
|
|
|
- "TLS_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_DH_DSS_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_CBC_SHA"
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_256_CBC_SHA384"
|
|
|
|
- "TLS_DH_anon_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_SEED_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_CBC_SHA256"
|
|
|
|
- "TLS_DHE_DSS_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDH_ECDSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_AES_128_CBC_SHA"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_NULL_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_AES_256_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_IDEA_CBC_MD5"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_KUZNYECHIK_CTR_OMAC"
|
|
|
|
- "TLS_ECDHE_RSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_28147_CNT_IMIT"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_DES_CBC_MD5"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC4_40_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_128_GCM_SHA256"
|
|
|
|
- "TLS_SM4_GCM_SM3"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_ECDHE_ECDSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_3DES_EDE_CBC_SHA"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5"
|
|
|
|
- "TLS_DH_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_ECDHE_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DHE_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_CBC_SHA256"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_GCM_SHA256"
|
|
|
|
- "TLS_ECDH_ECDSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_KRB5_WITH_3DES_EDE_CBC_MD5"
|
|
|
|
- "TLS_KRB5_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_RSA_WITH_NULL_SHA"
|
|
|
|
condition: or
|
|
|
|
|
|
|
|
- address: "{{Host}}:{{Port}}"
|
|
|
|
min_version: tls12
|
|
|
|
max_version: tls12
|
|
|
|
|
|
|
|
extractors:
|
|
|
|
- type: dsl
|
|
|
|
dsl:
|
|
|
|
- "tls_version, cipher"
|
|
|
|
matchers:
|
|
|
|
- type: word
|
|
|
|
part: cipher
|
|
|
|
words:
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_GCM_SHA256"
|
|
|
|
- "TLS_NULL_WITH_NULL_NULL"
|
|
|
|
- "TLS_DH_DSS_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_ECDH_RSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_128_CBC_SHA256"
|
|
|
|
- "TLS_RSA_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_SM4_CCM_SM3"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_GCM_SHA384"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_ECDH_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5"
|
|
|
|
- "TLS_RSA_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_MAGMA_CTR_OMAC"
|
|
|
|
- "TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_256_GCM_SHA384"
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_DHE_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA256"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_ECDHE_ECDSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA256"
|
|
|
|
- "TLS_RSA_WITH_NULL_MD5"
|
|
|
|
- "TLS_SHA384_SHA384"
|
|
|
|
- "TLS_SHA256_SHA256"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_GCM_SHA384"
|
|
|
|
- "TLS_RSA_WITH_NULL_SHA256"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA"
|
|
|
|
- "TLS_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_DH_DSS_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_CBC_SHA"
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_256_CBC_SHA384"
|
|
|
|
- "TLS_DH_anon_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_SEED_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_CBC_SHA256"
|
|
|
|
- "TLS_DHE_DSS_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDH_ECDSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_AES_128_CBC_SHA"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_NULL_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_AES_256_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_IDEA_CBC_MD5"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_KUZNYECHIK_CTR_OMAC"
|
|
|
|
- "TLS_ECDHE_RSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_28147_CNT_IMIT"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_DES_CBC_MD5"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC4_40_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_128_GCM_SHA256"
|
|
|
|
- "TLS_SM4_GCM_SM3"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_ECDHE_ECDSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_3DES_EDE_CBC_SHA"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5"
|
|
|
|
- "TLS_DH_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_ECDHE_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DHE_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_CBC_SHA256"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_GCM_SHA256"
|
|
|
|
- "TLS_ECDH_ECDSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_KRB5_WITH_3DES_EDE_CBC_MD5"
|
|
|
|
- "TLS_KRB5_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_RSA_WITH_NULL_SHA"
|
|
|
|
condition: or
|
|
|
|
|
|
|
|
- address: "{{Host}}:{{Port}}"
|
|
|
|
min_version: tls13
|
|
|
|
max_version: tls13
|
|
|
|
|
|
|
|
extractors:
|
|
|
|
- type: dsl
|
|
|
|
dsl:
|
|
|
|
- "tls_version, cipher"
|
|
|
|
matchers:
|
|
|
|
- type: word
|
|
|
|
part: cipher
|
|
|
|
words:
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_GCM_SHA256"
|
|
|
|
- "TLS_NULL_WITH_NULL_NULL"
|
|
|
|
- "TLS_DH_DSS_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_ECDH_RSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_128_CBC_SHA256"
|
|
|
|
- "TLS_RSA_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_SM4_CCM_SM3"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_GCM_SHA384"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_ECDH_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5"
|
|
|
|
- "TLS_RSA_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_MAGMA_CTR_OMAC"
|
|
|
|
- "TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_256_GCM_SHA384"
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_DHE_PSK_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA256"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_ECDHE_ECDSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA256"
|
|
|
|
- "TLS_RSA_WITH_NULL_MD5"
|
|
|
|
- "TLS_SHA384_SHA384"
|
|
|
|
- "TLS_SHA256_SHA256"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_GCM_SHA384"
|
|
|
|
- "TLS_RSA_WITH_NULL_SHA256"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_DES_CBC_40_SHA"
|
|
|
|
- "TLS_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC2_CBC_40_SHA"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_DH_DSS_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_RC4_128_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_CBC_SHA"
|
|
|
|
- "TLS_DHE_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_256_CBC_SHA384"
|
|
|
|
- "TLS_DH_anon_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_SEED_CBC_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_AES_256_CBC_SHA256"
|
|
|
|
- "TLS_DHE_DSS_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDH_ECDSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_AES_128_CBC_SHA"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_NULL_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_AES_256_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_IDEA_CBC_MD5"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_KUZNYECHIK_CTR_OMAC"
|
|
|
|
- "TLS_ECDHE_RSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_GOSTR341112_256_WITH_28147_CNT_IMIT"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA"
|
|
|
|
- "TLS_DH_RSA_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_KRB5_WITH_DES_CBC_MD5"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC4_40_SHA"
|
|
|
|
- "TLS_DH_anon_WITH_ARIA_128_GCM_SHA256"
|
|
|
|
- "TLS_SM4_GCM_SM3"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_ECDHE_ECDSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC4_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_3DES_EDE_CBC_SHA"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_ECDHE_PSK_WITH_NULL_SHA256"
|
|
|
|
- "TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5"
|
|
|
|
- "TLS_DH_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_ECDHE_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_ECDH_anon_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA"
|
|
|
|
- "TLS_DHE_RSA_WITH_DES_CBC_SHA"
|
|
|
|
- "TLS_RSA_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5"
|
|
|
|
- "TLS_DH_anon_WITH_AES_128_CBC_SHA256"
|
|
|
|
- "TLS_DH_anon_WITH_CAMELLIA_128_GCM_SHA256"
|
|
|
|
- "TLS_ECDH_ECDSA_WITH_NULL_SHA"
|
|
|
|
- "TLS_RSA_PSK_WITH_NULL_SHA384"
|
|
|
|
- "TLS_KRB5_WITH_3DES_EDE_CBC_MD5"
|
|
|
|
- "TLS_KRB5_WITH_RC4_128_SHA"
|
|
|
|
- "TLS_RSA_WITH_NULL_SHA"
|
|
|
|
condition: or
|
2023-10-20 11:41:13 +00:00
|
|
|
|
|
|
|
# digest: 490a00463044022032467f79ddf4aebd26984f76bb38318bab6b3d3a48334d54813ba4fec9273cee02203af1271cc84d825ea6918003f8fe30f689cf01149b02a364d468152128fe840f:922c64590222798bb761d5b6d8e72950
|