mirror of
https://github.com/davidalvarezp/websec-audit.git
synced 2026-06-23 11:48:28 +02:00
v1.0.1
This commit is contained in:
@@ -0,0 +1,126 @@
|
||||
{
|
||||
"metadata": {
|
||||
"tool": "websec-audit",
|
||||
"version": "1.0.1",
|
||||
"author": "davidalvarezp",
|
||||
"target": "https://example.com",
|
||||
"domain": "example.com",
|
||||
"ip": "104.18.27.120",
|
||||
"start_time": "2026-03-23 16:15:31",
|
||||
"duration_secs": 1541
|
||||
},
|
||||
"summary": {
|
||||
"total": 104,
|
||||
"critical": 4,
|
||||
"high": 2,
|
||||
"medium": 25,
|
||||
"low": 66,
|
||||
"info": 7
|
||||
},
|
||||
"findings": [
|
||||
{"id":1,"severity":"INFO","module":"INIT","title":"Audit started against https://example.com","description":"Resolved IP: 104.18.27.120 | Mode: NORMAL","evidence":"","recommendation":"","timestamp":"2026-03-23T15:15:36Z"},
|
||||
{"id":2,"severity":"INFO","module":"RECON","title":"WHOIS data collected for example.com","description":"Registrar: N/A | Expiry: 2026-08-13","evidence":"","recommendation":"","timestamp":"2026-03-23T15:15:36Z"},
|
||||
{"id":3,"severity":"INFO","module":"RECON","title":"Subdomain enumeration: 37616 hosts discovered","description":"0000.example.com 001.example.com 01.example.com 02.example.com 03.example.com 03----may----rrdd.example.com 04.example.com 05----apr----rrdd.example.com 05.example.com 06----apr----rrdd.example.com ","evidence":"/root/websec-audit/results_example_com_20260323_161531/recon/subdomains.txt","recommendation":"","timestamp":"2026-03-23T15:16:22Z"},
|
||||
{"id":4,"severity":"INFO","module":"FINGERPRINT","title":"WAF detected: Cloudflare (Cloudflare Inc.) WAF.","description":"The target appears to be protected by a Web Application Firewall.","evidence":"Cloudflare (Cloudflare Inc.) WAF.","recommendation":"","timestamp":"2026-03-23T15:16:25Z"},
|
||||
{"id":5,"severity":"LOW","module":"FINGERPRINT","title":"Version disclosure via 'Server' header","description":"The server reveals technology/version info in response headers.","recommendation":"Remove or neutralise the 'Server' header in your web server configuration.","timestamp":"2026-03-23T15:16:25Z"},
|
||||
{"id":6,"severity":"LOW","module":"SSL","title":"testssl: [TLS1] offered (deprecated)","description":"","evidence":"","recommendation":"Refer to testssl documentation for TLS1","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":7,"severity":"LOW","module":"SSL","title":"testssl: [TLS1_1] offered (deprecated)","description":"","evidence":"","recommendation":"Refer to testssl documentation for TLS1_1","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":8,"severity":"MEDIUM","module":"SSL","title":"testssl: [cipherlist_3DES_IDEA] offered","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipherlist_3DES_IDEA","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":9,"severity":"LOW","module":"SSL","title":"testssl: [cipherlist_OBSOLETED] offered","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipherlist_OBSOLETED","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":10,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_xc013] TLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_xc013","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":11,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_x2f] TLSv1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_x2f","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":12,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_xc014] TLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_xc014","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":13,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_x35] TLSv1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_x35","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":14,"severity":"MEDIUM","module":"SSL","title":"testssl: [cipher-tls1_x0a] TLSv1 x0a DES-CBC3-SHA RSA 3DES 168 TLS_RSA_WITH_3DES_EDE_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_x0a","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":15,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_1_xc013] TLSv1.1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_1_xc013","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":16,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_1_x2f] TLSv1.1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_1_x2f","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":17,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_1_xc014] TLSv1.1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_1_xc014","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":18,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_1_x35] TLSv1.1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_1_x35","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":19,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc009] TLSv1.2 xc009 ECDHE-ECDSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc009","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":20,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc00a] TLSv1.2 xc00a ECDHE-ECDSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc00a","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":21,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc023] TLSv1.2 xc023 ECDHE-ECDSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc023","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":22,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc024] TLSv1.2 xc024 ECDHE-ECDSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc024","timestamp":"2026-03-23T15:19:44Z"},
|
||||
{"id":23,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc013] TLSv1.2 xc013 ECDHE-RSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc013","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":24,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_x2f] TLSv1.2 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_x2f","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":25,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc014] TLSv1.2 xc014 ECDHE-RSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc014","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":26,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_x35] TLSv1.2 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_x35","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":27,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc027] TLSv1.2 xc027 ECDHE-RSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA25","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc027","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":28,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_x3c] TLSv1.2 x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_x3c","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":29,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc028] TLSv1.2 xc028 ECDHE-RSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc028","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":30,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_x3d] TLSv1.2 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_x3d","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":31,"severity":"HIGH","module":"SSL","title":"testssl: [cert_keyUsage <hostCert#1>] Certificate incorrectly used for key encipherment: 'Digital Signature'","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_keyUsage <hostCert#1>","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":32,"severity":"CRITICAL","module":"SSL","title":"testssl: [cert_chain_of_trust <hostCert#1>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_chain_of_trust <hostCert#1>","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":33,"severity":"MEDIUM","module":"SSL","title":"testssl: [cert_expirationStatus <hostCert#1>] expires < 60 days (52)","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_expirationStatus <hostCert#1>","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":34,"severity":"MEDIUM","module":"SSL","title":"testssl: [cert_notAfter <hostCert#1>] 2026-05-14 18:57","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_notAfter <hostCert#1>","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":35,"severity":"LOW","module":"SSL","title":"testssl: [DNS_CAArecord <hostCert#1>] --","description":"","evidence":"","recommendation":"Refer to testssl documentation for DNS_CAArecord <hostCert#1>","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":36,"severity":"CRITICAL","module":"SSL","title":"testssl: [cert_chain_of_trust <hostCert#2>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_chain_of_trust <hostCert#2>","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":37,"severity":"MEDIUM","module":"SSL","title":"testssl: [cert_expirationStatus <hostCert#2>] expires < 60 days (52)","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_expirationStatus <hostCert#2>","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":38,"severity":"MEDIUM","module":"SSL","title":"testssl: [cert_notAfter <hostCert#2>] 2026-05-14 18:57","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_notAfter <hostCert#2>","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":39,"severity":"LOW","module":"SSL","title":"testssl: [DNS_CAArecord <hostCert#2>] --","description":"","evidence":"","recommendation":"Refer to testssl documentation for DNS_CAArecord <hostCert#2>","timestamp":"2026-03-23T15:19:45Z"},
|
||||
{"id":40,"severity":"LOW","module":"SSL","title":"testssl: [HSTS] not offered","description":"","evidence":"","recommendation":"Refer to testssl documentation for HSTS","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":41,"severity":"MEDIUM","module":"SSL","title":"testssl: [security_headers] --","description":"","evidence":"","recommendation":"Refer to testssl documentation for security_headers","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":42,"severity":"MEDIUM","module":"SSL","title":"testssl: [BREACH] potentially VULNERABLE, gzip HTTP compression detected - only supplied '/' tested","description":"","evidence":"","recommendation":"Refer to testssl documentation for BREACH","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":43,"severity":"LOW","module":"SSL","title":"testssl: [SWEET32] uses 64 bit block ciphers","description":"","evidence":"","recommendation":"Refer to testssl documentation for SWEET32","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":44,"severity":"MEDIUM","module":"SSL","title":"testssl: [BEAST_CBC_TLS1] ECDHE-RSA-AES128-SHA AES128-SHA ECDHE-RSA-AES256-SHA AES256-SHA DES-CBC3-SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for BEAST_CBC_TLS1","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":45,"severity":"LOW","module":"SSL","title":"testssl: [BEAST] VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated)","description":"","evidence":"","recommendation":"Refer to testssl documentation for BEAST","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":46,"severity":"LOW","module":"SSL","title":"testssl: [LUCKY13] potentially vulnerable, uses TLS CBC ciphers","description":"","evidence":"","recommendation":"Refer to testssl documentation for LUCKY13","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":47,"severity":"MEDIUM","module":"SSL","title":"testssl: [overall_grade] B","description":"","evidence":"","recommendation":"Refer to testssl documentation for overall_grade","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":48,"severity":"LOW","module":"SSL","title":"testssl: [TLS1] offered (deprecated)","description":"","evidence":"","recommendation":"Refer to testssl documentation for TLS1","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":49,"severity":"LOW","module":"SSL","title":"testssl: [TLS1_1] offered (deprecated)","description":"","evidence":"","recommendation":"Refer to testssl documentation for TLS1_1","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":50,"severity":"MEDIUM","module":"SSL","title":"testssl: [cipherlist_3DES_IDEA] offered","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipherlist_3DES_IDEA","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":51,"severity":"LOW","module":"SSL","title":"testssl: [cipherlist_OBSOLETED] offered","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipherlist_OBSOLETED","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":52,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_xc013] TLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_xc013","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":53,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_x2f] TLSv1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_x2f","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":54,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_xc014] TLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_xc014","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":55,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_x35] TLSv1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_x35","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":56,"severity":"MEDIUM","module":"SSL","title":"testssl: [cipher-tls1_x0a] TLSv1 x0a DES-CBC3-SHA RSA 3DES 168 TLS_RSA_WITH_3DES_EDE_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_x0a","timestamp":"2026-03-23T15:19:46Z"},
|
||||
{"id":57,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_1_xc013] TLSv1.1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_1_xc013","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":58,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_1_x2f] TLSv1.1 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_1_x2f","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":59,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_1_xc014] TLSv1.1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_1_xc014","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":60,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_1_x35] TLSv1.1 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_1_x35","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":61,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc009] TLSv1.2 xc009 ECDHE-ECDSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc009","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":62,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc00a] TLSv1.2 xc00a ECDHE-ECDSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc00a","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":63,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc023] TLSv1.2 xc023 ECDHE-ECDSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc023","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":64,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc024] TLSv1.2 xc024 ECDHE-ECDSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc024","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":65,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc013] TLSv1.2 xc013 ECDHE-RSA-AES128-SHA ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc013","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":66,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_x2f] TLSv1.2 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_x2f","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":67,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc014] TLSv1.2 xc014 ECDHE-RSA-AES256-SHA ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc014","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":68,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_x35] TLSv1.2 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_x35","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":69,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc027] TLSv1.2 xc027 ECDHE-RSA-AES128-SHA256 ECDH 253 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA25","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc027","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":70,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_x3c] TLSv1.2 x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_x3c","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":71,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_xc028] TLSv1.2 xc028 ECDHE-RSA-AES256-SHA384 ECDH 253 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA38","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_xc028","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":72,"severity":"LOW","module":"SSL","title":"testssl: [cipher-tls1_2_x3d] TLSv1.2 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256","description":"","evidence":"","recommendation":"Refer to testssl documentation for cipher-tls1_2_x3d","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":73,"severity":"HIGH","module":"SSL","title":"testssl: [cert_keyUsage <hostCert#1>] Certificate incorrectly used for key encipherment: 'Digital Signature'","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_keyUsage <hostCert#1>","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":74,"severity":"CRITICAL","module":"SSL","title":"testssl: [cert_chain_of_trust <hostCert#1>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_chain_of_trust <hostCert#1>","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":75,"severity":"MEDIUM","module":"SSL","title":"testssl: [cert_expirationStatus <hostCert#1>] expires < 60 days (52)","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_expirationStatus <hostCert#1>","timestamp":"2026-03-23T15:19:47Z"},
|
||||
{"id":76,"severity":"MEDIUM","module":"SSL","title":"testssl: [cert_notAfter <hostCert#1>] 2026-05-14 18:57","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_notAfter <hostCert#1>","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":77,"severity":"LOW","module":"SSL","title":"testssl: [DNS_CAArecord <hostCert#1>] --","description":"","evidence":"","recommendation":"Refer to testssl documentation for DNS_CAArecord <hostCert#1>","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":78,"severity":"CRITICAL","module":"SSL","title":"testssl: [cert_chain_of_trust <hostCert#2>] Some certificate trust checks failed -> Mozilla (chain incomplete) , OK -> Microsoft Linux Java Apple","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_chain_of_trust <hostCert#2>","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":79,"severity":"MEDIUM","module":"SSL","title":"testssl: [cert_expirationStatus <hostCert#2>] expires < 60 days (52)","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_expirationStatus <hostCert#2>","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":80,"severity":"MEDIUM","module":"SSL","title":"testssl: [cert_notAfter <hostCert#2>] 2026-05-14 18:57","description":"","evidence":"","recommendation":"Refer to testssl documentation for cert_notAfter <hostCert#2>","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":81,"severity":"LOW","module":"SSL","title":"testssl: [DNS_CAArecord <hostCert#2>] --","description":"","evidence":"","recommendation":"Refer to testssl documentation for DNS_CAArecord <hostCert#2>","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":82,"severity":"LOW","module":"SSL","title":"testssl: [HSTS] not offered","description":"","evidence":"","recommendation":"Refer to testssl documentation for HSTS","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":83,"severity":"MEDIUM","module":"SSL","title":"testssl: [security_headers] --","description":"","evidence":"","recommendation":"Refer to testssl documentation for security_headers","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":84,"severity":"MEDIUM","module":"SSL","title":"testssl: [BREACH] potentially VULNERABLE, gzip HTTP compression detected - only supplied '/' tested","description":"","evidence":"","recommendation":"Refer to testssl documentation for BREACH","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":85,"severity":"LOW","module":"SSL","title":"testssl: [SWEET32] uses 64 bit block ciphers","description":"","evidence":"","recommendation":"Refer to testssl documentation for SWEET32","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":86,"severity":"MEDIUM","module":"SSL","title":"testssl: [BEAST_CBC_TLS1] ECDHE-RSA-AES128-SHA AES128-SHA ECDHE-RSA-AES256-SHA AES256-SHA DES-CBC3-SHA","description":"","evidence":"","recommendation":"Refer to testssl documentation for BEAST_CBC_TLS1","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":87,"severity":"LOW","module":"SSL","title":"testssl: [BEAST] VULNERABLE -- but also supports higher protocols TLSv1.1 TLSv1.2 (likely mitigated)","description":"","evidence":"","recommendation":"Refer to testssl documentation for BEAST","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":88,"severity":"LOW","module":"SSL","title":"testssl: [LUCKY13] potentially vulnerable, uses TLS CBC ciphers","description":"","evidence":"","recommendation":"Refer to testssl documentation for LUCKY13","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":89,"severity":"MEDIUM","module":"SSL","title":"testssl: [overall_grade] B","description":"","evidence":"","recommendation":"Refer to testssl documentation for overall_grade","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":90,"severity":"MEDIUM","module":"SSL","title":"Certificate expires in 52 days","description":"","evidence":"May 14 18:57:50 2026 GMT","recommendation":"Plan certificate renewal.","timestamp":"2026-03-23T15:19:48Z"},
|
||||
{"id":91,"severity":"MEDIUM","module":"SSL","title":"HSTS header not configured","description":"Strict-Transport-Security is absent — browsers may access the site over HTTP.","evidence":"","recommendation":"Add: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload","timestamp":"2026-03-23T15:19:49Z"},
|
||||
{"id":92,"severity":"LOW","module":"HEADERS","title":"Permissions-Policy missing","description":"The response is missing the 'permissions-policy' security header.","evidence":"","recommendation":"Add: Permissions-Policy: geolocation=(), microphone=(), camera=()","timestamp":"2026-03-23T15:19:49Z"},
|
||||
{"id":93,"severity":"LOW","module":"HEADERS","title":"Cross-Origin-Resource-Policy (CORP) missing","description":"The response is missing the 'cross-origin-resource-policy' security header.","evidence":"","recommendation":"Add: Cross-Origin-Resource-Policy: same-origin","timestamp":"2026-03-23T15:19:49Z"},
|
||||
{"id":94,"severity":"LOW","module":"HEADERS","title":"Cross-Origin-Opener-Policy (COOP) missing","description":"The response is missing the 'cross-origin-opener-policy' security header.","evidence":"","recommendation":"Add: Cross-Origin-Opener-Policy: same-origin","timestamp":"2026-03-23T15:19:49Z"},
|
||||
{"id":95,"severity":"LOW","module":"HEADERS","title":"X-Content-Type-Options missing — MIME sniffing risk","description":"The response is missing the 'x-content-type-options' security header.","evidence":"","recommendation":"Add: X-Content-Type-Options: nosniff","timestamp":"2026-03-23T15:19:49Z"},
|
||||
{"id":96,"severity":"MEDIUM","module":"HEADERS","title":"X-Frame-Options missing — clickjacking risk","description":"The response is missing the 'x-frame-options' security header.","evidence":"","recommendation":"Add: X-Frame-Options: SAMEORIGIN","timestamp":"2026-03-23T15:19:49Z"},
|
||||
{"id":97,"severity":"MEDIUM","module":"HEADERS","title":"Content-Security-Policy (CSP) missing","description":"The response is missing the 'content-security-policy' security header.","evidence":"","recommendation":"Implement a strict CSP to mitigate XSS and data injection attacks.","timestamp":"2026-03-23T15:19:49Z"},
|
||||
{"id":98,"severity":"LOW","module":"HEADERS","title":"Referrer-Policy missing","description":"The response is missing the 'referrer-policy' security header.","evidence":"","recommendation":"Add: Referrer-Policy: strict-origin-when-cross-origin","timestamp":"2026-03-23T15:19:49Z"},
|
||||
{"id":99,"severity":"LOW","module":"HEADERS","title":"Informative header exposed: Server","description":"Server reveals technology details via 'Server' header.","evidence":"se","recommendation":"Remove or anonymise the 'Server' header in your server configuration.","timestamp":"2026-03-23T15:19:49Z"},
|
||||
{"id":100,"severity":"MEDIUM","module":"HEADERS","title":"HTTP does not redirect to HTTPS (HTTP 200)","description":"Requests over HTTP are not automatically upgraded to HTTPS.","evidence":"http://example.com → 200","recommendation":"Configure a permanent 301 redirect from HTTP to HTTPS.","timestamp":"2026-03-23T15:19:49Z"},
|
||||
{"id":101,"severity":"LOW","module":"HEADERS","title":"Cache-Control header missing","description":"Without Cache-Control, sensitive pages may be cached by intermediaries.","evidence":"","recommendation":"Add: Cache-Control: no-store, no-cache on authenticated/sensitive pages.","timestamp":"2026-03-23T15:19:49Z"},
|
||||
{"id":102,"severity":"INFO","module":"SQLI","title":"No obvious SQLi on primary URL","description":"Manual testing with specific parameters recommended.","evidence":"","recommendation":"","timestamp":"2026-03-23T15:20:05Z"},
|
||||
{"id":103,"severity":"INFO","module":"CMS","title":"CMS detected: unknown","description":"","evidence":"","recommendation":"","timestamp":"2026-03-23T15:21:12Z"},
|
||||
{"id":104,"severity":"INFO","module":"SSRF","title":"No in-band SSRF detected on common parameters","description":"Out-of-band (OOB) SSRF may still exist. Use Burp Collaborator or Interactsh for blind testing.","evidence":"","recommendation":"","timestamp":"2026-03-23T15:26:05Z"}
|
||||
]
|
||||
}
|
||||
Reference in New Issue
Block a user