Question

SSLV2 removal

Asked by: KCS_SD

I have two Web servers - only one comes up with a SSLV2 vulnerability hit on a Retina Scan - the other doesn't.  I looked at the SChannel/Protocol registry keys on both and they are the same - so I don't see how adding a 'enable' key would make a difference.  There must be something else.  What is it?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-01-23 at 18:09:30ID24079481
Tags

Microsoft Office 2003

,

IIS 6.0

Topics

Microsoft Identity Integration Server

,

Microsoft Office Suite

,

Microsoft IIS Web Server

Participating Experts
2
Points
500
Comments
14

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Scanning Registry
    I tried to scan the registry in order to extract all occurencies of a certain path. I did some coding which works in all HKEYs, except for the _machine HKEY. My code gives an address error here. Please provide a runnable code example. My goal is moving Delphi and some othe...
  2. vulnerability scan
    Hello. Can anyone suggest some software that does a good vulnerability scan for a webserver? including a scan looking for vulnerable php and cgi scrpts etc etc? i'd like to use something that keeps an updated database of vulnerable scripts that it scans for. I'd like to f...
  3. Website Security vulnerabilities
    I have a friend (company) that has their website hosted with Network Solutions. Recently their index.htm was edited and an IFRAME tag was added to that page. I have no idea how this got there but would like to do some security testing. Is there a free Security Scanner that ...
  4. Security Vulnerability
    Hi, I performed a security Vulnerability test on my LAN and have found the following Vulnerability CVE 1999 0519 A NETBIOS/SMB share password is the default, null, or missing I can not find any patch info for this, can anyone tell me how I resolve this issue. Note: the guest...
  5. McAfee Scan Vulnerability
    Hello, We are doing McAfee scan for our sites. We are getting this vulnerability from scan. If any one can help how to resolve this. Unencrypted Login Information Disclosure Description The remote host appears to allow logins over unencrypted (HTTP) connections. This mea...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: meverestPosted on 2009-01-25 at 21:46:57ID: 23464342

Hi,

set the /value/ of 'enabled' to zero - that will turn off sslv2

cheers.

 

by: KCS_SDPosted on 2009-01-26 at 11:41:14ID: 23469999

I understand that ADDING the 'enabled' value and setting it to '0' will disable SSLv2.  

My question is: if that key with that value does NOT EXIST on the server which has SSLv2 DISABLED already, what other setting takes care of this?

 

by: meverestPosted on 2009-01-26 at 13:22:47ID: 23471113

perhaps the actual protocol level has also been removed from the SCNANNEL key under the same path?

Cheers.

 

by: KCS_SDPosted on 2009-03-06 at 11:29:44ID: 23820140

Sorry - could you explain that in simpler terms?

What do you mean?

 

by: ParanormasticPosted on 2009-04-24 at 14:39:10ID: 24229505

Removing the protocol from the registry doesn't do it - then it goes to the 'default' behavior for schannel.  Having a modified schannel.dll could do that, however - I would suggest looking at the version information of this file in system32.  That being said, I don't think that this kind of change has been made in any patch.

I presume you are looking at
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders \SCHANNEL\Protocols\SSL 2.0\Client]
and
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders \SCHANNEL\Protocols\SSL 2.0\Server]

One way that the scan might be fooled is if all lower encryption methods were removed already - so no 40 or 56 bit algorithms, only 128+.  This is not a 'proper' test, but if a test was being run to see if they could introduce forcing a lower protocol than what the server/client handshake would normally produce (i.e. forcing 40bit instead of 128bit), then the test could interpret the lack of 40bit vulnerability as being non-v2.0.  This only tests against the most well known vulnerability of SSL2.0 - the man-in-the-middle scenario.  For more info on the difference:
http://stason.org/TULARC/security/ssl-talk/4-11-What-is-the-difference-between-SSL-2-0-and-3-0.html

You can also run a simple test from OpenSSL:
openssl s_client -connect TARGET_IP:PORT_NUMBER -ssl2

Is there any other main difference between serverA and serverB?  For example, is the vulnerable one running 2003 and the secured one running 2008?  I would need to refresh my memory, but I think that the default was changed to restricted in 08 and it was enabled in 03 - not sure about 03R2.

These are both running IIS, I presume given the zone list?

 

by: KCS_SDPosted on 2009-05-20 at 14:16:58ID: 24436396

Actually, one server is an duplicate image of the other.

Before putting the second on the network, I applied the image of the first and then changed the name.  The first does not come up with this hit, the second one does.

Both are W2K3 R2 Std SP 2.

 

by: ParanormasticPosted on 2009-06-01 at 12:03:09ID: 24520613

How was the server imaged?  Sysprep or direct copy?  Sysprep may have reset certain registry settings, so you may need to reapply them after restoring the image.  I'm not positive how much gets changed in the registry by renaming a box, but you should be using sysprep anyways to avoice duplicate SIDs on the network.

Did you doublecheck the registry settings mentioned on the second box to make sure that stuck through your imaging/renaming procedure?


Also, I'm not sure why this came up for autoclean - it has not been 21 days since last post (5/20/09) from the asker - maybe an EE cleanup check bug that only checks for date since last expert post?

 

by: ParanormasticPosted on 2009-06-01 at 12:06:05ID: 24520643

How did you image the server?  Sysprep or a straight copy?  Sysprep is usually best to avoid duplicate SIDs.

Did you verify the changes you made on one stuck to the restored image after the renaming?  I'm not exactly sure what all get modified in the registry when you rename the computer account.


Also, I'm not sure why this got triggered for cleanup - last post was 5/20/09 which was less than 21 days ago - maybe a cleanup scan bug that only checks against the date of the last expert posting, not the asker?

 

by: KCS_SDPosted on 2009-06-01 at 14:42:05ID: 24522135

Don't know what Sysprep is.  I used Acronis True Image and installed the image on the server when it was off the network then changed the computer name.

But, let me clarify something before looking at the image difference:   I have 4 web servers -  3 of them came up with this SSLV2 hit.

One of the 3 with the hit is a copy of the one without the hit.  The other two I built from scratch.  So I don't think it is a image/copy difference.

 

by: ParanormasticPosted on 2009-06-03 at 14:00:38ID: 24541309

Odd that the acronis image did not duplicate the settings - that should be a full hard drive replication.

Did you double check the registry settings?  

here are a few articles to follow if the above instructions might not have been clear enough:
http://support.microsoft.com/kb/187498
http://support.microsoft.com/kb/245030

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...