문제

I found out my server has SSL v2 enabled. Which is bad. I can't do anything about this as I am on shared hosting (albeit with dedicated IP address).

But when I connect with my browser (chrome and IE11) I see it uses TLS. So my question is, is SSLv2 only used when a really old browser is connecting to the server? Am I right in assuming if someone is connecting with any reasonably in date browser, TLS is likely to be used?

도움이 되었습니까?

해결책

Yes and no. A recent browser will connect with TLS to the server, but if somebody can arrange a man-in-the-middle attack he can enforce SSLv2. For more information see https://superuser.com/questions/246074/ssl-whats-the-reason-for-disabling-ssl-v2-support

라이센스 : CC-BY-SA ~와 함께 속성
제휴하지 않습니다 StackOverflow
scroll top