Pergunta

I found out my server has SSL v2 enabled. Which is bad. I can't do anything about this as I am on shared hosting (albeit with dedicated IP address).

But when I connect with my browser (chrome and IE11) I see it uses TLS. So my question is, is SSLv2 only used when a really old browser is connecting to the server? Am I right in assuming if someone is connecting with any reasonably in date browser, TLS is likely to be used?

Foi útil?

Solução

Yes and no. A recent browser will connect with TLS to the server, but if somebody can arrange a man-in-the-middle attack he can enforce SSLv2. For more information see https://superuser.com/questions/246074/ssl-whats-the-reason-for-disabling-ssl-v2-support

Licenciado em: CC-BY-SA com atribuição
Não afiliado a StackOverflow
scroll top