Solved

This server is vulnerable to MITM attacks because it supports insecure renegotiation. Grade set to F

Posted on 2014-12-11
4
697 Views
Last Modified: 2014-12-18
Ran website through SSL Labs and got this warning

This server is vulnerable to MITM attacks because it supports insecure renegotiation. Grade set to F

Any ideas how to patch? It's running on a server 2003 box.

https://community.qualys.com/blogs/securitylabs/2009/11/05/ssl-and-tls-authentication-gap-vulnerability-discovered
0
Comment
Question by:gman
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 58

Expert Comment

by:Gary
ID: 40494415
Should have been fixed in Windows Update

http://support.microsoft.com/kb/980436
0
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 250 total points
ID: 40498068
0
 

Author Comment

by:gman
ID: 40500196
IT's running Apache V2.2.25, Windows is fully updated.

Do you think disabling PCT, SSL 2, SSL 3 via the registry will do the trick?

Thanks,
0
 
LVL 58

Assisted Solution

by:Gary
Gary earned 250 total points
ID: 40500726
From what I can find Apache 2.2.3x is the minimum to fix it.

You should have already disabled SSLv2 and SSLv3 to mitigate the Heartbleed exploit. If you already have an SSL cert you will need to check the OpenSSL version used to create it as it may need updating
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
In this blog we highlight approaches to managed security as a service.  We also look into ConnectWise’s value in aiding MSPs’ security management and indicate why critical alerting is a necessary integration.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question