TLSSLED
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
TLSSLed is a shell script that evaluates the security of a target SSL/TLS (HTTPS) web server. It wraps sslscan and openssl to provide comprehensive SSL/TLS configuration testing.
BASIC USAGE#
tlssled <target> <port> # Scan target on specified port
EXAMPLES#
# Scan HTTPS on default port tlssled example.com 443 # Scan custom HTTPS port tlssled example.com 8443 # Scan internal web server tlssled 192.168.1.1 443
CHECKS PERFORMED#
# Protocol Support: # - SSLv2 enabled? # - SSLv3 enabled? # - TLS 1.0 enabled? # - TLS 1.1 enabled? # - TLS 1.2 enabled? # Cipher Analysis: # - NULL ciphers (no encryption) # - Weak ciphers (DES, RC4, export) # - Medium strength ciphers # - Strong ciphers (AES, etc.) # - Cipher order preference # Certificate Analysis: # - Certificate details (subject, issuer) # - Validity dates # - Key size # - Signature algorithm # - Self-signed detection # Vulnerability Checks: # - BEAST (CBC ciphers on TLS 1.0) # - CRIME (compression enabled) # - Renegotiation support # - Heartbleed (if sslscan supports it)
OUTPUT SECTIONS#
# [*] Testing protocols... # [*] Testing NULL ciphers... # [*] Testing weak ciphers (DES, RC4)... # [*] Testing medium ciphers... # [*] Testing strong ciphers... # [*] Testing certificate... # [*] Testing renegotiation... # [*] Testing compression...
INTERPRETING RESULTS#
# RED = Critical finding (NULL ciphers, SSLv2) # YELLOW = Warning (weak ciphers, SSLv3, TLS 1.0) # GREEN = Secure configuration # Key issues to look for: # "SSLv2 ENABLED" = CRITICAL - Insecure protocol # "SSLv3 ENABLED" = HIGH - POODLE vulnerability # "NULL cipher accepted" = CRITICAL - No encryption # "Weak cipher accepted" = HIGH - Breakable encryption # "Self-signed cert" = WARNING - Trust issue # "Expired certificate" = HIGH - Invalid certificate
REQUIREMENTS#
# Dependencies: # - sslscan (must be installed) # - openssl (must be installed) # - Bash shell
COMPARISON WITH OTHER TOOLS#
# TLSSLed: Quick wrapper script, easy to use # sslscan: More detailed cipher/protocol analysis # sslyze: Most comprehensive, Python-based, JSON output # testssl.sh: Most thorough, actively maintained alternative
NOTES#
- Bash script wrapping sslscan and openssl - Quick and easy to use for basic SSL/TLS checks - Output is terminal-colored for easy reading - Only requires target hostname/IP and port - Consider testssl.sh for more comprehensive testing - Does not test application-layer security - Non-destructive - safe for production systems