← All cheat sheets

SSLSCAN

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

sslscan queries SSL/TLS services to determine supported ciphers,
protocols, and certificate details. It identifies weak configurations
like SSLv2/v3 support, weak ciphers, and certificate issues.

BASIC USAGE#

sslscan <target>                 # Scan default port 443
sslscan <target>:8443            # Scan custom port
sslscan --targets=hosts.txt      # Scan multiple targets

PROTOCOL OPTIONS#

sslscan --ssl2 <target>          # Check SSLv2 support
sslscan --ssl3 <target>          # Check SSLv3 support
sslscan --tls10 <target>         # Check TLS 1.0 support
sslscan --tls11 <target>         # Check TLS 1.1 support
sslscan --tls12 <target>         # Check TLS 1.2 support
sslscan --tls13 <target>         # Check TLS 1.3 support
sslscan --no-ssl2 <target>       # Skip SSLv2 check
sslscan --no-ssl3 <target>       # Skip SSLv3 check
sslscan --no-tls10 <target>      # Skip TLS 1.0 check
sslscan --no-tls11 <target>      # Skip TLS 1.1 check
sslscan --no-tls12 <target>      # Skip TLS 1.2 check
sslscan --no-tls13 <target>      # Skip TLS 1.3 check

CIPHER OPTIONS#

sslscan --show-ciphers <target>  # Show all supported ciphers
sslscan --no-ciphersuites <target>
                                 # Skip cipher enumeration

CERTIFICATE OPTIONS#

sslscan --show-certificate <target>
                                 # Show full certificate
sslscan --no-certinfo <target>   # Skip certificate info
sslscan --ocsp <target>          # Check OCSP stapling

CONNECTION OPTIONS#

sslscan --starttls-ftp <target>  # STARTTLS for FTP
sslscan --starttls-imap <target> # STARTTLS for IMAP
sslscan --starttls-pop3 <target> # STARTTLS for POP3
sslscan --starttls-smtp <target> # STARTTLS for SMTP
sslscan --starttls-xmpp <target> # STARTTLS for XMPP
sslscan --starttls-ldap <target> # STARTTLS for LDAP
sslscan --http <target>          # Test HTTP connection
sslscan --rdp <target>           # Test RDP connection
sslscan --bugs <target>          # Enable SSL bug workarounds
sslscan --no-fallback <target>   # Disable TLS fallback
sslscan --ipv4 <target>          # Force IPv4
sslscan --ipv6 <target>          # Force IPv6
sslscan --sni-name <name> <target>
                                 # Set SNI hostname

OUTPUT OPTIONS#

sslscan --xml=output.xml <target>  # XML output
sslscan --no-colour <target>       # Disable colored output
sslscan --show-times <target>      # Show handshake times

VULNERABILITY CHECKS#

sslscan --no-heartbleed <target> # Skip Heartbleed check
sslscan --no-renegotiation <target>
                                 # Skip renegotiation check
sslscan --no-compression <target>
                                 # Skip compression check (CRIME)
sslscan --no-check-certificate <target>
                                 # Skip certificate checks
sslscan --no-groups <target>     # Skip group enumeration

EXAMPLES#

# Full scan of HTTPS server
sslscan example.com

# Scan SMTP with STARTTLS
sslscan --starttls-smtp mail.example.com:25

# Scan IMAP with STARTTLS
sslscan --starttls-imap mail.example.com:143

# Full scan with certificate details
sslscan --show-certificate example.com

# Scan with XML output for reporting
sslscan --xml=results.xml example.com

# Scan multiple targets
echo "host1.com" > targets.txt
echo "host2.com" >> targets.txt
sslscan --targets=targets.txt

INTERPRETING RESULTS#

# Color coding (terminal):
# RED      = Insecure (SSLv2, SSLv3, weak ciphers, NULL, RC4)
# YELLOW   = Weak (DES, export ciphers, small key sizes)
# GREEN    = Secure (AES, strong key sizes)

# Key things to check:
# - SSLv2/SSLv3 enabled = CRITICAL (POODLE, DROWN)
# - TLS 1.0/1.1 enabled = WEAK (deprecated)
# - RC4 ciphers = WEAK
# - NULL ciphers = CRITICAL
# - Export ciphers = CRITICAL (FREAK, Logjam)
# - Certificate validity and chain

NOTES#

- Does not require authentication
- Safe to run (does not exploit vulnerabilities)
- Heartbleed check is non-destructive
- STARTTLS support for email protocols
- Can scan any SSL/TLS service (not just HTTPS)
- Pair with sslyze for deeper analysis
- Updated fork: github.com/rbsec/sslscan