Tuesday, January 23, 2024

Scanning TLS Server Configurations With Burp Suite

In this post, we present our new Burp Suite extension "TLS-Attacker".
Using this extension penetration testers and security researchers can assess the security of TLS server configurations directly from within Burp Suite.
The extension is based on the TLS-Attacker framework and the TLS-Scanner, both of which are developed by the Chair for Network and Data Security.

You can find the latest release of our extension at: https://github.com/RUB-NDS/TLS-Attacker-BurpExtension/releases

TLS-Scanner

Thanks to the seamless integration of the TLS-Scanner into the BurpSuite, the penetration tester only needs to configure a single parameter: the host to be scanned.  After clicking the Scan button, the extension runs the default checks and responds with a report that allows penetration testers to quickly determine potential issues in the server's TLS configuration.  Basic tests check the supported cipher suites and protocol versions.  In addition, several known attacks on TLS are automatically evaluated, including Bleichenbacher's attack, Padding Oracles, and Invalid Curve attacks.

Furthermore, the extension allows fine-tuning for the configuration of the underlying TLS-Scanner.  The two parameters parallelProbes and overallThreads can be used to improve the scan performance (at the cost of increased network load and resource usage).

It is also possible to configure the granularity of the scan using Scan Detail and Danger Level. The level of detail contained in the returned scan report can also be controlled using the Report Detail setting.

Please refer to the GitHub repositories linked above for further details on configuration and usage of TLS-Scanner.

Scan History 

If several hosts are scanned, the Scan History tab keeps track of the preformed scans and is a useful tool when comparing the results of subsequent scans.

Additional functions will follow in later versions

Currently, we are working on integrating an at-a-glance rating mechanism to allow for easily estimating the security of a scanned host's TLS configuration.

This is a combined work of Nurullah Erinola, Nils Engelbertz, David Herring, Juraj Somorovsky, Vladislav Mladenov, and Robert Merget.  The research was supported by the European Commission through the FutureTrust project (grant 700542-Future-Trust-H2020-DS-2015-1).

If you would like to learn more about TLS, Juraj and Robert will give a TLS Training at Ruhrsec on the 27th of May 2019. There are still a few seats left.

Related articles


  1. Nsa Hack Tools
  2. Hacker Tools Free Download
  3. Hacking Tools Usb
  4. Underground Hacker Sites
  5. Hak5 Tools
  6. Pentest Tools Github
  7. Hacker Techniques Tools And Incident Handling
  8. Pentest Tools Linux
  9. Pentest Tools List
  10. New Hack Tools
  11. Pentest Tools Port Scanner
  12. Pentest Tools Github
  13. Hak5 Tools
  14. Pentest Tools Android
  15. Install Pentest Tools Ubuntu
  16. Hacker
  17. Hacker Tools For Pc
  18. Hacker Tools 2020
  19. Pentest Tools Download
  20. Ethical Hacker Tools
  21. Hacker Tools For Windows
  22. Hacking Tools Windows
  23. Nsa Hack Tools Download
  24. Hak5 Tools
  25. Hacker Tools 2019
  26. Easy Hack Tools
  27. Hack Tool Apk
  28. Best Hacking Tools 2019
  29. Hacker Tools Apk Download
  30. Nsa Hack Tools Download
  31. Hack And Tools
  32. Hacking Tools Github
  33. Physical Pentest Tools
  34. Hack Tool Apk
  35. Pentest Tools Download
  36. Underground Hacker Sites
  37. Hacking Tools Kit
  38. Hacking Tools Pc
  39. How To Make Hacking Tools
  40. Hack Apps
  41. Pentest Tools Github
  42. Pentest Tools Windows
  43. Pentest Tools Online
  44. Game Hacking
  45. Hack Website Online Tool
  46. Kik Hack Tools
  47. Hack Tools For Windows
  48. Hacking Tools Mac
  49. What Are Hacking Tools
  50. Game Hacking
  51. Pentest Box Tools Download
  52. Easy Hack Tools
  53. Hacking Tools Free Download
  54. Hack Apps
  55. Hacking Tools Hardware
  56. Pentest Tools Alternative
  57. Github Hacking Tools
  58. Hacking Tools 2019
  59. Hacks And Tools
  60. Nsa Hack Tools Download
  61. Hacker Tools Apk Download
  62. Hacker Tools Apk Download
  63. Hack Tools For Mac
  64. Hacker Tools For Mac
  65. New Hacker Tools
  66. Hacker Tools For Mac
  67. Hacking Tools Pc
  68. Hacking Tools Name
  69. Hacking Tools Pc
  70. Hacking Tools Mac
  71. Hacking Tools Software
  72. Hacking Tools
  73. Hack And Tools
  74. Hack Tools For Windows
  75. Hak5 Tools
  76. Hacker Tools Apk
  77. Hacking Tools For Windows
  78. Hack And Tools
  79. Hacker
  80. Pentest Box Tools Download
  81. Hacker Techniques Tools And Incident Handling
  82. Pentest Tools Apk
  83. Hacker Tools Github
  84. Pentest Tools Alternative
  85. Hacker Tools 2020
  86. Hacker Tools 2020
  87. Bluetooth Hacking Tools Kali
  88. Hack App
  89. Pentest Tools Framework
  90. Hacker Tools For Pc
  91. Hack Tools For Pc
  92. Wifi Hacker Tools For Windows
  93. Hacker
  94. Hack Tools Pc
  95. Hackrf Tools
  96. Hacker Search Tools

No comments:

Post a Comment