GSA-TTS/all_sorns

Pen-test Finding: weak ciphers

Opened this issue · 2 comments

The site offers week SEED and 128- and 256-bit CBC ciphers.

I emailed the pen-tester to provide details of which ciphers we currently offer that should be disabled.

Also, tests may be false positives according to this shared by Garret

0

Better screenshot of test results