SSLSCAN
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
sslscan queries SSL/TLS services to determine supported ciphers, protocols, and certificate details. It identifies weak configurations like SSLv2/v3 support, weak ciphers, and certificate issues.
BASIC USAGE#
sslscan <target> # Scan default port 443 sslscan <target>:8443 # Scan custom port sslscan --targets=hosts.txt # Scan multiple targets
PROTOCOL OPTIONS#
sslscan --ssl2 <target> # Check SSLv2 support sslscan --ssl3 <target> # Check SSLv3 support sslscan --tls10 <target> # Check TLS 1.0 support sslscan --tls11 <target> # Check TLS 1.1 support sslscan --tls12 <target> # Check TLS 1.2 support sslscan --tls13 <target> # Check TLS 1.3 support sslscan --no-ssl2 <target> # Skip SSLv2 check sslscan --no-ssl3 <target> # Skip SSLv3 check sslscan --no-tls10 <target> # Skip TLS 1.0 check sslscan --no-tls11 <target> # Skip TLS 1.1 check sslscan --no-tls12 <target> # Skip TLS 1.2 check sslscan --no-tls13 <target> # Skip TLS 1.3 check
CIPHER OPTIONS#
sslscan --show-ciphers <target> # Show all supported ciphers
sslscan --no-ciphersuites <target>
# Skip cipher enumeration
CERTIFICATE OPTIONS#
sslscan --show-certificate <target>
# Show full certificate
sslscan --no-certinfo <target> # Skip certificate info
sslscan --ocsp <target> # Check OCSP stapling
CONNECTION OPTIONS#
sslscan --starttls-ftp <target> # STARTTLS for FTP
sslscan --starttls-imap <target> # STARTTLS for IMAP
sslscan --starttls-pop3 <target> # STARTTLS for POP3
sslscan --starttls-smtp <target> # STARTTLS for SMTP
sslscan --starttls-xmpp <target> # STARTTLS for XMPP
sslscan --starttls-ldap <target> # STARTTLS for LDAP
sslscan --http <target> # Test HTTP connection
sslscan --rdp <target> # Test RDP connection
sslscan --bugs <target> # Enable SSL bug workarounds
sslscan --no-fallback <target> # Disable TLS fallback
sslscan --ipv4 <target> # Force IPv4
sslscan --ipv6 <target> # Force IPv6
sslscan --sni-name <name> <target>
# Set SNI hostname
OUTPUT OPTIONS#
sslscan --xml=output.xml <target> # XML output sslscan --no-colour <target> # Disable colored output sslscan --show-times <target> # Show handshake times
VULNERABILITY CHECKS#
sslscan --no-heartbleed <target> # Skip Heartbleed check
sslscan --no-renegotiation <target>
# Skip renegotiation check
sslscan --no-compression <target>
# Skip compression check (CRIME)
sslscan --no-check-certificate <target>
# Skip certificate checks
sslscan --no-groups <target> # Skip group enumeration
EXAMPLES#
# Full scan of HTTPS server sslscan example.com # Scan SMTP with STARTTLS sslscan --starttls-smtp mail.example.com:25 # Scan IMAP with STARTTLS sslscan --starttls-imap mail.example.com:143 # Full scan with certificate details sslscan --show-certificate example.com # Scan with XML output for reporting sslscan --xml=results.xml example.com # Scan multiple targets echo "host1.com" > targets.txt echo "host2.com" >> targets.txt sslscan --targets=targets.txt
INTERPRETING RESULTS#
# Color coding (terminal): # RED = Insecure (SSLv2, SSLv3, weak ciphers, NULL, RC4) # YELLOW = Weak (DES, export ciphers, small key sizes) # GREEN = Secure (AES, strong key sizes) # Key things to check: # - SSLv2/SSLv3 enabled = CRITICAL (POODLE, DROWN) # - TLS 1.0/1.1 enabled = WEAK (deprecated) # - RC4 ciphers = WEAK # - NULL ciphers = CRITICAL # - Export ciphers = CRITICAL (FREAK, Logjam) # - Certificate validity and chain
NOTES#
- Does not require authentication - Safe to run (does not exploit vulnerabilities) - Heartbleed check is non-destructive - STARTTLS support for email protocols - Can scan any SSL/TLS service (not just HTTPS) - Pair with sslyze for deeper analysis - Updated fork: github.com/rbsec/sslscan