Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-04-27, 13:53:00

Author Topic: Vulnerability Protokol SSL  (Read 8706 times)

0 Members and 1 Guest are viewing this topic.

Offline Wibowo

  • Master
  • **
  • Posts: 391
  • Karma: +0/-0
  • Gender: Male
    • View Profile
Vulnerability Protokol SSL
« on: 2016-03-17, 10:55:49 »
barusan iseng-iseng cek SSL pake SSLabs Qualys
ssllabs[dot]com/ssltest

pake nginxproxy hasilnya lumayan mengagetkan juga
vulnerable ke Drown Attack dan penggunaan cipher Diffie-Hellman


coba baca di sini https://weakdh.org/sysadmin.html dan di sini https://blog.qualys.com/securitylabs/2016/03/04/ssl-labs-drown-test-implementation-details ada panduan untuk memperbaiki config

saya coba cek /opt/configs/nginx/tpl/domains.conf.tpl kok gak nemu bagian ssl cipher ya?
apa memang harus ditambahkan sendiri?

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Vulnerability Protokol SSL
« Reply #1 on: 2016-03-17, 16:11:16 »
Lihat di /opt/configs/nginx/conf/globals/ssl_base.conf.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline Wibowo

  • Master
  • **
  • Posts: 391
  • Karma: +0/-0
  • Gender: Male
    • View Profile
Re: Vulnerability Protokol SSL
« Reply #2 on: 2016-03-17, 18:11:08 »
Lihat di /opt/configs/nginx/conf/globals/ssl_base.conf.

ya pak
sudah saya edit, warning diffie-hellman hilang tapi warning drown masih ada
mungkin dari key ssl-nya (masih nebak2)

Offline masnggakdiajak

  • Valuable Member
  • *
  • Posts: 126
  • Karma: +0/-0
    • View Profile
Re: Vulnerability Protokol SSL
« Reply #3 on: 2016-04-02, 03:41:30 »
bang wibowo pernah tes di https securityheaders[dot]io dapat nilai apa?

mau tanya untuk nambah kode ini untuk per domain

Code: [Select]
#Strict-Transport-Security
add_header Strict-Transport-Security "max-age=31536000;" always;
#X-Frame-Options
add_header X-Frame-Options "SAMEORIGIN" always;
#X-Content-Type-Options
add_header X-Content-Type-Options "nosniff" always;
#X-XSS-Protection
add_header X-Xss-Protection "1; mode=block" always;
#Content-Security-Policy
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://domain.disqus.com https://www.google-analytics.com; style-src 'self' 'unsafe-inline'; img-src 'self' https://www.google-analytics.com";
#Public-Key-Pins
add_header Public-Key-Pins 'pin-sha256="X3pGTSOuJeEVw989IJ/cEtXUEmy52zs1TZQrU06KUKg="; pin-sha256="MHJYVThihUrJcxW6wcqyOISTXIsInsdj3xK8QrZbHec="; pin-sha256="isi41AizREkLvvft0IRW4u3XMFR2Yg7bvrF7padyCJg="; max-age=10';

diamana? apakah sama di

Code: [Select]
/opt/configs/nginx/conf/globals/ssl_base.conf.

terimakasih,

Offline NginxHolic

  • Valuable Member
  • *
  • Posts: 84
  • Karma: +1/-0
    • View Profile
Re: Vulnerability Protokol SSL
« Reply #4 on: 2016-04-29, 17:17:13 »
Sorry bump old thread.

Ada yang sudah solve untuk DROWN attack di Kloxo MR?
LogJam sudah clear di saya.

Offline masnggakdiajak

  • Valuable Member
  • *
  • Posts: 126
  • Karma: +0/-0
    • View Profile
Re: Vulnerability Protokol SSL
« Reply #5 on: 2016-06-03, 04:27:30 »
saya juga masih belum menemukan bang masalah DROWN attack di Kloxo MR, semoga mimin bisa membantu,

btw LogJam apa yah bang?

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Vulnerability Protokol SSL
« Reply #6 on: 2016-06-03, 05:16:04 »
Jika dicoba webserver satu-per-satu (nginx, lighttpd, httpd, apache). Hasilnya akan berbeda.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline masnggakdiajak

  • Valuable Member
  • *
  • Posts: 126
  • Karma: +0/-0
    • View Profile
Re: Vulnerability Protokol SSL
« Reply #7 on: 2016-06-03, 05:22:19 »
saya menggunakan nginxproxy DROWN attack masih muncul, agara warning DROWN attack hilang menggunakan webserver apa mas?

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Vulnerability Protokol SSL
« Reply #8 on: 2016-06-03, 06:07:12 »
Ujinya pakai SSLLabs ya?. Saya agak ragu ujinya.

Drown itu 'menyerang' ssl yang masih SSLv2. Bagaimana mungkin jika pakai hiawatha katanya masih ada drown attack. Hiawatha tidak pakai lagi SSLv2 bahkan SSLv3 pun ditiadakan. Hiawatha hanya pakai TLS1.0 keatas.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline masnggakdiajak

  • Valuable Member
  • *
  • Posts: 126
  • Karma: +0/-0
    • View Profile
Re: Vulnerability Protokol SSL
« Reply #9 on: 2016-06-03, 07:33:59 »
iya di SSLLabs, kalau nginxproxy kloxoMR menggunakan ssl atau tls?

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Vulnerability Protokol SSL
« Reply #10 on: 2016-06-03, 08:01:59 »
iya di SSLLabs, kalau nginxproxy kloxoMR menggunakan ssl atau tls?
Semua webserver di Kloxo-MR 7.0 sudah disable SSLv2 dan SSLv3 sehingga hanya pakai TLS1.0, TLS1.1 dan TLS1.2.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline masnggakdiajak

  • Valuable Member
  • *
  • Posts: 126
  • Karma: +0/-0
    • View Profile
Re: Vulnerability Protokol SSL
« Reply #11 on: 2016-06-03, 08:11:14 »
oke siap mas makasih,

Offline hostrator

  • Valuable Member
  • *
  • Posts: 66
  • Karma: +0/-0
    • View Profile
Re: Vulnerability Protokol SSL
« Reply #12 on: 2016-06-09, 06:19:45 »
kalau ubah sslkey bit dari 2048 ke 4096 gimanaya caranya, apakah dihapus dulu ssl nya terus di add lagi ?

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Vulnerability Protokol SSL
« Reply #13 on: 2016-06-09, 06:36:02 »
kalau ubah sslkey bit dari 2048 ke 4096 gimanaya caranya, apakah dihapus dulu ssl nya terus di add lagi ?
Ya.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

 


Top 10 Social Networking:    Facebook    Twitter    LinkedIn    Pinterest    Google Plus    Tumblr    Instagram    VK    Flickr    Vine
Click Here

Page created in 0.033 seconds with 18 queries.

web stats analysis