Author Topic: Many SSL sites remain insecure and vulnerable!  (Read 3425 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34048
  • malware fighter
Many SSL sites remain insecure and vulnerable!
« on: January 31, 2015, 05:35:52 PM »
Read: http://www.biztechmagazine.com/article/2013/09/most-ssl-sites-remain-insecure-and-vulnerable  (Alexander Slagg = article author)
This information to a large extent still holds out for the 2015 situation. Why I stiil come accross so many https (SSL) stes which do not get a green padlock in the Google Chrome browser.
Here it is OK: https://shaaaaaaaaaaaaa.com/check/webmail.online.nl/
Still I do not get the Google Chrome green padlock. Intermediate certificate has a weak signature. -> https://www.ssllabs.com/ssltest/analyze.html?d=webmail.online.nl
Security Header Implementation Situation: https://www.uploady.com/#!/download/w~FwQhr0Ysa/haY1QZdsfzfE9olG
Minor warnings here: http://www.dnsinspect.com/online.nl/1422721624
ISP tracks with fonts.googleapis.com
Quote
  just a font service, but one that could, conceivably, be used for tracking.
Read on quote: http://www.telecomasia.net/blog/content/tangled-web-internet-tracking
link article author = Don Sambandaraksa

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34048
  • malware fighter
Re: Many SSL sites remain insecure and vulnerable!
« Reply #1 on: January 31, 2015, 10:16:49 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34048
  • malware fighter
Re: Many SSL sites remain insecure and vulnerable!
« Reply #2 on: January 31, 2015, 10:33:14 PM »
Another test tool result: http://foundeo.com/products/iis-weak-ssl-ciphers/test.cfm?test_domain=www.mozilla.org
Result page view: https://www.uploady.com/#!/download/jlskjnLGKKg/yla7bNUDe6k~uTdf
Issues: http://www.dnsinspect.com/mozilla.org/1422739211
Cert Logik alerts to: Signature Algorithm   sha1WithRSAEncryption (SHA-1 is being phased out)
See: https://ssl.trustwave.com/support/support-certificate-analyzer.php?address=www.mozilla.org&port=443
Vulnerable to POODLE attack: https://www.ssllabs.com/ssltest/analyze.html?d=www.mozilla.org
POODLE Scan: Scan results
WWW.MOZILLA.ORG:443 (63.245.215.20) - VULNERABLE
Security Header Check results page: https://www.uploady.com/#!/download/pbOUFnFNYx8/XXX5fzGT6DslWY9O
Confirmed: http://toolbar.netcraft.com/site_report/?url=https%3A%2F%2Fwww.mozilla.org

Tracking: The following sites know that you visited this page. Click on a site to find out what more it knows about you.
-mozilla.net
-optimizely.com
-mozorg.cdn.mozilla.net is tracking with some safety measures taken.

Mozilla SSL  ::)

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34048
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline ehmen

  • Poster
  • *
  • Posts: 498

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34048
  • malware fighter
Re: Many SSL sites remain insecure and vulnerable!
« Reply #5 on: February 02, 2015, 03:08:02 PM »
Hi ehmen,

That is a good sign, but also webmasters and website hosters should get their configurations like it shopuld.
Alas I haven't seen any without errors, flaws or not using best policy.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: Many SSL sites remain insecure and vulnerable!
« Reply #6 on: February 03, 2015, 02:31:44 AM »
but also webmasters and website hosters should get their configurations like it shopuld.
Agreed 100%.
But at least those using Chrome v40 will be immune and won't suffer due to a webmasters negligence.
Alas, many a webmaster and hoster isn't as concerned with cyber-security as need be.