Crime-Vulnerability-IMAPS/EN: Unterschied zwischen den Versionen

Aus Siwecos
Wechseln zu: Navigation, Suche
(Die Seite wurde neu angelegt: „=== {{:{{PAGENAME}}/Headline}} === If the result is positive, there is no need for further action. If the result is negative, please read the following inst…“)
 
 
Zeile 1: Zeile 1:
 +
 
=== {{:{{PAGENAME}}/Headline}} ===
 
=== {{:{{PAGENAME}}/Headline}} ===
  

Aktuelle Version vom 7. Mai 2020, 10:39 Uhr

CRIME vulnerability check

If the result is positive, there is no need for further action. If the result is negative, please read the following instructions.

Result positive Not vulnerable to CRIME
Result negativ Vulnerable to CRIME
Description The server is vulnerable to CRIME. A vulnerability that allows an attacker to decrypt the communication.
Background The CRIME attack takes advantage of the fact that data compression can change the length of encrypted messages, and this provides conclusions about the plain text. This can be used by a skilled attacker to steal data.
Consequence The server is vulnerable to a vulnerability that allows an attacker to decrypt the communication.
Solution/Tips CRIME can be prevented by disabling the use of compression of data in TLS. Disable TLS compression on your server.