2013-07-17 20:49:22 +02:00
|
|
|
#!/usr/bin/env bash
|
|
|
|
|
2013-08-04 04:07:13 +02:00
|
|
|
DOBENCHMARK=0
|
2013-07-19 15:45:06 +02:00
|
|
|
BENCHMARKITER=30
|
|
|
|
OPENSSLBIN="./openssl"
|
2013-11-20 15:30:52 +01:00
|
|
|
#OPENSSLBIN="/usr/bin/openssl"
|
2013-08-04 04:07:13 +02:00
|
|
|
TIMEOUT=10
|
2013-11-20 16:30:14 +01:00
|
|
|
CIPHERSUITE="ALL:COMPLEMENTOFALL"
|
2013-07-17 20:49:22 +02:00
|
|
|
REQUEST="GET / HTTP/1.1
|
|
|
|
Host: $TARGET
|
|
|
|
|
|
|
|
|
|
|
|
"
|
|
|
|
|
|
|
|
|
|
|
|
verbose() {
|
|
|
|
if [ $VERBOSE -eq 1 ];then
|
|
|
|
echo $@
|
|
|
|
fi
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
# Connect to a target host with the selected ciphersuite
|
|
|
|
test_cipher_on_target() {
|
|
|
|
local sslcommand=$@
|
|
|
|
local tmp=$(mktemp)
|
2013-07-17 21:06:34 +02:00
|
|
|
$sslcommand 1>"$tmp" 2>/dev/null << EOF
|
2013-07-17 20:49:22 +02:00
|
|
|
$REQUEST
|
|
|
|
EOF
|
|
|
|
# Parse the result
|
2013-09-24 17:02:31 +02:00
|
|
|
result="$(grep "New, " $tmp|awk '{print $5}') $(grep -E "^\s+Protocol\s+:" $tmp|awk '{print $3}') $(grep 'Server Temp Key' $tmp|awk '{print $4$5$6$7}')"
|
2013-07-17 21:06:34 +02:00
|
|
|
rm "$tmp"
|
2013-08-07 16:40:03 +02:00
|
|
|
if [ -z "$result" ]; then
|
2013-08-04 04:07:13 +02:00
|
|
|
verbose "handshake failed, no ciphersuite was returned"
|
|
|
|
result='ConnectionFailure'
|
|
|
|
return 2
|
2013-09-24 17:02:31 +02:00
|
|
|
elif [ "$result" == '(NONE) ' ]; then
|
2013-07-17 20:49:22 +02:00
|
|
|
verbose "handshake failed, server returned ciphersuite '$result'"
|
|
|
|
return 1
|
|
|
|
else
|
|
|
|
verbose "handshake succeeded, server returned ciphersuite '$result'"
|
|
|
|
return 0
|
|
|
|
fi
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
# Calculate the average handshake time for a specific ciphersuite
|
|
|
|
bench_cipher() {
|
|
|
|
local ciphersuite="$1"
|
2013-08-04 04:07:13 +02:00
|
|
|
local sslcommand="timeout $TIMEOUT $OPENSSLBIN s_client -connect $TARGET -cipher $ciphersuite"
|
2013-07-17 20:49:22 +02:00
|
|
|
local t="$(date +%s%N)"
|
|
|
|
verbose "Benchmarking handshake on '$TARGET' with ciphersuite '$ciphersuite'"
|
|
|
|
for i in $(seq 1 $BENCHMARKITER); do
|
|
|
|
$sslcommand 2>/dev/null 1>/dev/null << EOF
|
|
|
|
$REQUEST
|
|
|
|
EOF
|
2013-08-04 04:07:13 +02:00
|
|
|
if [ $? -gt 0 ]; then
|
|
|
|
break
|
|
|
|
fi
|
2013-07-17 20:49:22 +02:00
|
|
|
done
|
|
|
|
# Time interval in nanoseconds
|
|
|
|
local t="$(($(date +%s%N) - t))"
|
|
|
|
verbose "Benchmarking done in $t nanoseconds"
|
2013-07-19 15:45:06 +02:00
|
|
|
# Microseconds
|
|
|
|
cipherbenchms="$((t/1000/$BENCHMARKITER))"
|
2013-07-17 20:49:22 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
# Connect to the target and retrieve the chosen cipher
|
|
|
|
get_cipher_pref() {
|
|
|
|
local ciphersuite="$1"
|
2013-08-04 04:07:13 +02:00
|
|
|
local sslcommand="timeout $TIMEOUT $OPENSSLBIN s_client -connect $TARGET -cipher $ciphersuite"
|
2013-07-17 20:49:22 +02:00
|
|
|
verbose "Connecting to '$TARGET' with ciphersuite '$ciphersuite'"
|
|
|
|
test_cipher_on_target "$sslcommand"
|
|
|
|
local success=$?
|
2013-08-04 04:07:13 +02:00
|
|
|
cipherspref=("${cipherspref[@]}" "$result")
|
2013-07-17 20:49:22 +02:00
|
|
|
# If the connection succeeded with the current cipher, benchmark and store
|
|
|
|
if [ $success -eq 0 ]; then
|
2013-08-07 16:40:03 +02:00
|
|
|
pciph=$(echo $result|awk '{print $1}')
|
|
|
|
get_cipher_pref "!$pciph:$ciphersuite"
|
2013-07-17 20:49:22 +02:00
|
|
|
return 0
|
|
|
|
fi
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
if [ -z $1 ]; then
|
|
|
|
echo "
|
|
|
|
usage: $0 <target:port> <-v>
|
|
|
|
|
|
|
|
$0 attempts to connect to a target site using all the ciphersuites it knowns.
|
|
|
|
jvehent - ulfr - 2013
|
|
|
|
"
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
TARGET=$1
|
|
|
|
VERBOSE=0
|
2013-08-04 04:07:13 +02:00
|
|
|
ALLCIPHERS=0
|
2013-07-17 20:49:22 +02:00
|
|
|
if [ ! -z $2 ]; then
|
|
|
|
if [ "$2" == "-v" ]; then
|
|
|
|
VERBOSE=1
|
2013-11-20 16:30:14 +01:00
|
|
|
echo "Loading $($OPENSSLBIN ciphers -v $CIPHERSUITE 2>/dev/null|grep Kx|wc -l) ciphersuites from $(echo -n $($OPENSSLBIN version 2>/dev/null))"
|
2013-07-17 20:49:22 +02:00
|
|
|
$OPENSSLBIN ciphers ALL 2>/dev/null
|
|
|
|
fi
|
2013-08-04 04:07:13 +02:00
|
|
|
if [ "$2" == "-a" ]; then
|
|
|
|
ALLCIPHERS=1
|
|
|
|
fi
|
2013-07-17 20:49:22 +02:00
|
|
|
fi
|
|
|
|
|
|
|
|
cipherspref=();
|
|
|
|
results=()
|
2013-11-20 16:30:14 +01:00
|
|
|
|
|
|
|
# Call to the recursive loop that retrieves the cipher preferences
|
|
|
|
get_cipher_pref $CIPHERSUITE
|
2013-07-17 20:49:22 +02:00
|
|
|
ctr=1
|
|
|
|
for cipher in "${cipherspref[@]}"; do
|
2013-08-07 16:40:03 +02:00
|
|
|
pciph=$(echo $cipher|awk '{print $1}')
|
2013-07-17 20:49:22 +02:00
|
|
|
if [ $DOBENCHMARK -eq 1 ]; then
|
2013-08-07 16:40:03 +02:00
|
|
|
bench_cipher "$pciph"
|
2013-07-19 15:45:06 +02:00
|
|
|
r="$ctr $cipher $cipherbenchms"
|
2013-07-17 20:49:22 +02:00
|
|
|
else
|
2013-07-19 15:45:06 +02:00
|
|
|
r="$ctr $cipher"
|
2013-07-17 20:49:22 +02:00
|
|
|
fi
|
|
|
|
results=("${results[@]}" "$r")
|
|
|
|
ctr=$((ctr+1))
|
|
|
|
done
|
|
|
|
|
2013-07-19 15:45:06 +02:00
|
|
|
if [ $DOBENCHMARK -eq 1 ]; then
|
2013-09-24 17:02:31 +02:00
|
|
|
header="prio ciphersuite protocol pfs_keysize avg_handshake_microsec"
|
2013-07-19 15:45:06 +02:00
|
|
|
else
|
2013-09-24 17:02:31 +02:00
|
|
|
header="prio ciphersuite protocol pfs_keysize"
|
2013-07-19 15:45:06 +02:00
|
|
|
fi
|
|
|
|
ctr=0
|
2013-07-17 20:49:22 +02:00
|
|
|
for result in "${results[@]}"; do
|
2013-07-19 15:45:06 +02:00
|
|
|
if [ $ctr -eq 0 ]; then
|
|
|
|
echo $header
|
|
|
|
ctr=$((ctr+1))
|
|
|
|
fi
|
2013-11-05 21:51:00 +01:00
|
|
|
echo $result|grep -v '(NONE)'
|
2013-07-19 15:45:06 +02:00
|
|
|
done|column -t
|
2013-08-04 04:07:13 +02:00
|
|
|
|
|
|
|
if [ $ALLCIPHERS -gt 0 ]; then
|
|
|
|
echo; echo "All accepted ciphersuites"
|
|
|
|
for cipher in $($OPENSSLBIN ciphers -v ALL:COMPLEMENTOFALL 2>/dev/null |awk '{print $1}'|sort|uniq); do
|
|
|
|
osslcommand="timeout $TIMEOUT $OPENSSLBIN s_client -connect $TARGET -cipher $cipher"
|
|
|
|
test_cipher_on_target "$osslcommand"
|
|
|
|
r=$?
|
|
|
|
if [ $r -eq 0 ]; then
|
|
|
|
echo -en '\E[40;32m'"OK"; tput sgr0
|
|
|
|
else
|
|
|
|
echo -en '\E[40;31m'"KO"; tput sgr0
|
|
|
|
fi
|
|
|
|
echo " $cipher"
|
|
|
|
done
|
|
|
|
fi
|