[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

This server is vulnerable to MITM attacks because it supports insecure renegotiation. Grade set to F

Posted on 2014-12-11
4
Medium Priority
?
792 Views
Last Modified: 2014-12-18
Ran website through SSL Labs and got this warning

This server is vulnerable to MITM attacks because it supports insecure renegotiation. Grade set to F

Any ideas how to patch? It's running on a server 2003 box.

https://community.qualys.com/blogs/securitylabs/2009/11/05/ssl-and-tls-authentication-gap-vulnerability-discovered
0
Comment
Question by:gman
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 58

Expert Comment

by:Gary
ID: 40494415
Should have been fixed in Windows Update

http://support.microsoft.com/kb/980436
0
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 1000 total points
ID: 40498068
0
 

Author Comment

by:gman
ID: 40500196
IT's running Apache V2.2.25, Windows is fully updated.

Do you think disabling PCT, SSL 2, SSL 3 via the registry will do the trick?

Thanks,
0
 
LVL 58

Assisted Solution

by:Gary
Gary earned 1000 total points
ID: 40500726
From what I can find Apache 2.2.3x is the minimum to fix it.

You should have already disabled SSLv2 and SSLv3 to mitigate the Heartbleed exploit. If you already have an SSL cert you will need to check the OpenSSL version used to create it as it may need updating
0

Featured Post

Simplify Your Workload with One Tool

How do you combat today’s intelligent hacker while managing multiple domains and platforms? By simplifying your workload with one tool. With Lunarpages hosting through Plesk Onyx, you can:

Automate SSL generation and installation with two clicks
Experience total server control

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes Administrators rights are not enough. These cases call for the SYSTEM account. The process in this article outlines the steps required to execute commands using the SYSTEM account.
Will you be ready when the clock on GDPR compliance runs out? Is GDPR even something you need to worry about? Find out more about the upcoming regulation changes and download our comprehensive GDPR checklist today !
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Is your data getting by on basic protection measures? In today’s climate of debilitating malware and ransomware—like WannaCry—that may not be enough. You need to establish more than basics, like a recovery plan that protects both data and endpoints.…

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question