Re: SSL drown vulnerability?
Vincent Fox <[email protected]> Thu, 3 Mar 2016 20:56:28 +0000
| Newsgroups | gmane.mail.perdition.user |
|---|---|
| Message-ID | <BY2PR0801MB1607A26059F36E1AF0391580BABD0@BY2PR0801MB1607.namprd08.prod.outlook.com> |
--===============1157736393== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_BY2PR0801MB1607A26059F36E1AF0391580BABD0BY2PR0801MB1607_" --_000_BY2PR0801MB1607A26059F36E1AF0391580BABD0BY2PR0801MB1607_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable To answer my own question, we will be updating our configs to define a cipher list which disables SSLv2. It seems this should address concerns. ________________________________ From: Perdition-users <[email protected]> on behalf of V= incent Fox <[email protected]> Sent: Thursday, March 3, 2016 11:11 AM To: [email protected] Subject: [PERDITION-USERS] SSL drown vulnerability? Hi, I am just reading up on Drown SSL vulnerability. What is everyone doing with regards to locking down Perdition? Thanks! --_000_BY2PR0801MB1607A26059F36E1AF0391580BABD0BY2PR0801MB1607_ Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-= 1"> <style type=3D"text/css" style=3D"display:none;"><!-- P {margin-top:0;margi= n-bottom:0;} --></style> </head> <body dir=3D"ltr"> <div id=3D"divtagdefaultwrapper" style=3D"font-size:12pt;color:#000000;back= ground-color:#FFFFFF;font-family:Calibri,Arial,Helvetica,sans-serif;"> <p>To answer my own <span> question, we will be updating</span></p> <p><span>our configs to define a cipher list which disables <br> </span></p> <p><span>SSLv2. It seems this should address concerns.<br> </span></p> <p><br> </p> <br> <br> <div style=3D"color: rgb(26, 26, 26);"> <hr tabindex=3D"-1" style=3D"display:inline-block; width:98%"> <div id=3D"divRplyFwdMsg" dir=3D"ltr"><font style=3D"font-size:11pt" face= =3D"Calibri, sans-serif" color=3D"#000000"><b>From:</b> Perdition-users <= ;[email protected]> on behalf of Vincent Fox <vbfo= [email protected]><br> <b>Sent:</b> Thursday, March 3, 2016 11:11 AM<br> <b>To:</b> [email protected]<br> <b>Subject:</b> [PERDITION-USERS] SSL drown vulnerability?</font> <div> </div> </div> <div> <div id=3D"divtagdefaultwrapper" style=3D"font-size:12pt; color:#000000; ba= ckground-color:#FFFFFF; font-family:Calibri,Arial,Helvetica,sans-serif"> <p>Hi,</p> <p><br> </p> <p>I am just reading up on Drown SSL vulnerability. What is</p> <p>everyone doing with regards to locking down Perdition?</p> <p><br> </p> <p>Thanks!</p> <p><br> </p> <p><br> </p> </div> </div> </div> </div> </body> </html> --_000_BY2PR0801MB1607A26059F36E1AF0391580BABD0BY2PR0801MB1607_-- --===============1157736393== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXwpQZXJkaXRpb24t dXNlcnMgbWFpbGluZyBsaXN0ClBlcmRpdGlvbi11c2Vyc0B2ZXJnZW5ldC5uZXQKaHR0cHM6Ly9s aXN0cy52ZXJnZW5ldC5uZXQvbGlzdGluZm8vcGVyZGl0aW9uLXVzZXJzCg== --===============1157736393==--