SSLYZE
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
SSLyze is a fast and powerful SSL/TLS scanning tool and Python library. It analyzes SSL/TLS server configurations, identifies vulnerabilities, and checks certificate validity.
BASIC USAGE#
sslyze <target> # Scan with defaults sslyze <target>:8443 # Custom port sslyze --regular <target> # Regular scan (most useful)
SCAN COMMANDS#
sslyze --regular <target> # Common scan commands combined sslyze --certinfo <target> # Certificate information sslyze --sslv2 <target> # Test SSLv2 support sslyze --sslv3 <target> # Test SSLv3 support sslyze --tlsv1 <target> # Test TLS 1.0 support sslyze --tlsv1_1 <target> # Test TLS 1.1 support sslyze --tlsv1_2 <target> # Test TLS 1.2 support sslyze --tlsv1_3 <target> # Test TLS 1.3 support
VULNERABILITY CHECKS#
sslyze --heartbleed <target> # Test for Heartbleed (CVE-2014-0160) sslyze --openssl_ccs <target> # Test for CCS injection (CVE-2014-0224) sslyze --robot <target> # Test for ROBOT attack sslyze --fallback <target> # Test for downgrade attacks sslyze --reneg <target> # Test renegotiation support sslyze --compression <target> # Test for CRIME (compression) sslyze --early_data <target> # Test TLS 1.3 early data (0-RTT)
CERTIFICATE OPTIONS#
sslyze --certinfo <target> # Full certificate info
sslyze --certinfo --ca_file=ca.pem <target>
# Verify against custom CA
CONNECTION OPTIONS#
sslyze --starttls=smtp <target> # STARTTLS for SMTP
sslyze --starttls=imap <target> # STARTTLS for IMAP
sslyze --starttls=pop3 <target> # STARTTLS for POP3
sslyze --starttls=ftp <target> # STARTTLS for FTP
sslyze --starttls=xmpp <target> # STARTTLS for XMPP
sslyze --starttls=ldap <target> # STARTTLS for LDAP
sslyze --sni=<hostname> <target> # Set SNI hostname
sslyze --xmpp_to=<domain> <target>
# Set XMPP destination
CLIENT AUTHENTICATION#
sslyze --cert=client.pem <target>
# Client certificate for auth
sslyze --key=client.key <target> # Client key
sslyze --keyform=PEM <target> # Key format
sslyze --pass=<password> <target>
# Key passphrase
OUTPUT OPTIONS#
sslyze --json_out=results.json <target>
# JSON output file
sslyze --targets_in=hosts.txt # Scan targets from file
sslyze --slow_connection # Slower but more reliable
sslyze --quiet <target> # Minimal output
MULTIPLE TARGETS#
sslyze host1.com host2.com host3.com
# Scan multiple hosts
sslyze --targets_in=targets.txt # From file (one per line)
EXAMPLES#
# Full regular scan sslyze --regular example.com # Scan SMTP server with STARTTLS sslyze --regular --starttls=smtp mail.example.com:25 # Vulnerability-focused scan sslyze --heartbleed --openssl_ccs --robot --compression example.com # Certificate chain validation sslyze --certinfo --ca_file=/etc/ssl/certs/ca-certificates.crt example.com # JSON output for automation sslyze --regular --json_out=scan_results.json example.com # Scan with client certificate sslyze --regular --cert=client.pem --key=client.key example.com # Multiple targets from file sslyze --regular --targets_in=targets.txt --json_out=results.json
PYTHON API#
# SSLyze can also be used as a Python library: from sslyze import ServerScanRequest, Scanner from sslyze import ScanCommand server = ServerScanRequest(server_location=...) scanner = Scanner() scanner.queue_scans([server])
KEY FINDINGS TO REPORT#
# CRITICAL: # - SSLv2/SSLv3 enabled # - Heartbleed vulnerable # - ROBOT attack possible # - CCS Injection vulnerable # - NULL/export ciphers # HIGH: # - TLS 1.0/1.1 enabled # - RC4 ciphers supported # - Self-signed certificate # - Expired certificate # MEDIUM: # - CRIME (compression enabled) # - Weak DH parameters (<2048 bit) # - Missing OCSP stapling # - Insecure renegotiation
NOTES#
- Python-based, fast concurrent scanning - Can be used as CLI tool or Python library - Non-destructive scanning (safe for production) - Supports client certificate authentication - JSON output ideal for CI/CD integration - More detailed than sslscan for compliance reporting - Actively maintained and updated