Post
Topic
Board Services
Re: [WTS] Government Level Penetration Testing & Security Audits
by
Rawted
on 09/02/2015, 16:28:02 UTC
atomic-trade.com (23.101.121.25)

HTTP server signature   Microsoft-IIS/8.5

Downgrade attack prevention =    No, TLS_FALLBACK_SCSV not supported
This server accepts the RC4 cipher, which is weak. = RC4   Yes   WEAK

Downgrade attack prevention =    No, TLS_FALLBACK_SCSV not supported - Only matters if they are strictly supporting ssl3, and they are not. They are not vulnerable to poodle, this is a false flag.

This server accepts the RC4 cipher, which is weak. = RC4   Yes   WEAK - Great, so they can disable RC4 and be done with it. It's not needed.