Nessus result: SSL Issues - medium strength cipher suites - The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.
Port: 443/tcp/www Hosts - x.x.x.x (public IP)
The scan was run externally, so my thought is just the firewall settings or whatever is open to the public on that specific port.
Here are the NMAP results as well from an external scan to my public IP:
PORT STATE SERVICE
25/tcp filtered smtp
70/tcp open gopher
80/tcp open http
135/tcp filtered msrpc
136/tcp filtered profile
137/tcp filtered netbios-ns
138/tcp filtered netbios-dgm
139/tcp filtered netbios-ssn
443/tcp open https
445/tcp filtered microsoft-ds
I understand cryptography and exactly what they're talking about when it comes to the vulnerability. However, how do I track down exactly what has these settings enabled? That is the part I just can't wrap my head around. 443 is SSL and I have a lot of services that would use SSL - RDGateway, SSL VPN on firewall, IIS Web Server, regular HTTPS traffic from a web browser.
Any explanation would be great!
[link] [comments]
SOCIAL SHARE CARD GENERATOR