Author Topic: DROWn vulnerable website  (Read 1846 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: DROWn vulnerable website
« Reply #1 on: March 10, 2016, 11:02:44 PM »
Seems IP has been blacklisted for spamming, see: http://www.ip-finder.me/193.105.104.51/
Re: -http://www.ip-finder.me/193.105.104.51/#collapseOne  (do not open has names of spammer links!).
Hackers, Spyware, Botnets etc.   listed: http://www.tcpiputils.com/browse/ip-address/193.105.104.51
Comical observation - hackers that are vulnerable to the DROWn attack.
The real world is weirder than your weirdest imagination, folks.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: DROWn vulnerable website
« Reply #3 on: March 10, 2016, 11:45:06 PM »
Just another one that bites the dust: https://test.drownattack.com/?site=ipo.gov.uk
IP Address   Port   Export   Special   Status
212.100.1.70   443   Yes   Yes   DROWn Vulnerable (same hostname with SSL v2)
https://www.eff.org/https-everywhere/atlas/domains/ipo.gov.uk.html
http://toolbar.netcraft.com/site_report?url=https://www.gov.uk
This website is insecure.
100% of the trackers on this site could be protecting you from NSA snooping. Tell ipo.gov.uk to fix it.

 All trackers
At least 2 third parties know you are on this webpage.

 -assets.digital.cabinet--office.gov.uk
-shaaaaaaaaaaaaa.com -shaaaaaaaaaaaaa.com (not vulnerable SHA2)

polonus (volunteer website security analyst and website error-hunter)

P.S. -assets.digital.cabinet-office.gov.uk on there does not seem vulnerable.
« Last Edit: March 10, 2016, 11:49:46 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: DROWn vulnerable website
« Reply #4 on: March 11, 2016, 12:05:14 AM »
Aargh mozilla dot org is vulnerable: - https://test.drownattack.com/?site=mozilla.org
Re: https://www.eff.org/https-everywhere/atlas/domains/mozilla.org.html
Moreover it is SSL3 insecure.
Another SSL test gives it as not DROWn insecure, but vulnerable to POODLE.
OpenSSL CCS vuln. (CVE-2014-0224)   Probably, but not exploitable
Weak key exchange detected.
100% of the trackers on this site could be protecting you from NSA snooping. Tell mozilla.org to fix it.
But cannot get anything else as the Apache test page. Apache HTTP Server Test Page powered by CentOS.
And a series of 404 Not Found

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!