<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7267320703085764135.post9136266752224235795..comments</id><updated>2012-01-20T07:55:49.690-08:00</updated><category term='Windows XP'/><category term='Instructions'/><category term='Fedora'/><category term='firearm'/><category term='Credit Card'/><category term='Joseph O&apos;Connor'/><category term='McAfee'/><category term='Apple'/><category term='Abraham Lincoln'/><category term='BlackHat'/><category term='Sync'/><category term='Kaminsky'/><category term='Weapon of mass destruction'/><category term='Food security'/><category term='Online Training'/><category term='Clients'/><category term='Application Window Grouping'/><category term='OWASP'/><category term='Tony Robbins'/><category term='Vulnerability'/><category term='Airline'/><category term='Warfare'/><category term='Apache'/><category term='CalDAV'/><category term='Thankfulness'/><category term='Get Things Done'/><category term='Strategic'/><category term='Professional certification'/><category term='Doxpara.com'/><category term='attack'/><category term='Policies'/><category term='Counter-terrorism'/><category term='Geeks'/><category term='Baydin'/><category term='Navy SEALs'/><category term='Metasploit'/><category term='Restricted Data'/><category term='Child Safety'/><category term='Meese'/><category term='Uncomplicated Firewall'/><category term='EXIF'/><category term='IIS'/><category term='Gnome'/><category term='United States'/><category term='Untitled'/><category term='ITIL'/><category term='Firefox'/><category term='Robert Dilts'/><category term='Emergency management'/><category term='Online Communities'/><category term='Kamala Harris'/><category term='Security awareness'/><category term='Viruses'/><category term='Cyberwarfare'/><category term='Computer security'/><category term='ICloud'/><category term='Gay Hendricks'/><category term='technology'/><category term='Microsoft'/><category term='InfranView'/><category term='West Midlands Police'/><category term='Prosperity'/><category term='ecto'/><category term='scotts valley sportmen&apos;s club'/><category term='Washington Post'/><category term='Forensics'/><category term='IP address'/><category term='Balance'/><category term='Leopard'/><category term='OS X'/><category term='Neuromancer'/><category term='Yankee Doodle'/><category term='TiVo'/><category term='day events'/><category term='tcsh'/><category term='Leadership'/><category term='Confidential'/><category term='Blackberry'/><category term='Las Vegas'/><category term='Xinhua News Agency'/><category term='InfoSec'/><category term='Obama'/><category term='Manualism'/><category term='SSL'/><category term='Risk'/><category term='Crypto'/><category term='High School'/><category term='Threat Matrix'/><category term='Warfare and Conflict'/><category term='Dirk Kollberg'/><category term='IT Organization'/><category term='Certification'/><category term='usb'/><category term='robotics'/><category term='Debian'/><category term='Hackers'/><category term='Penetration Testing'/><category term='Risk Rating'/><category term='ssh'/><category term='Attitude of Gratitude'/><category term='Audiobook'/><category term='penetration test'/><category term='Exploit'/><category term='Registry'/><category term='FreedBSD'/><category term='linksys'/><category term='Open Source'/><category term='Business'/><category term='GTD'/><category term='Five Wishes'/><category term='United States Department of Defense'/><category term='Google Chrome'/><category term='compliance'/><category term='Host Security'/><category term='Yahoo IM'/><category term='Spirituality'/><category term='Secure Sockets Layer'/><category term='Google Voice'/><category term='7 Habits of Highly Effective People'/><category term='Cecil Dill'/><category term='combat'/><category term='Burning Chrome'/><category term='ICQ'/><category term='HowTo'/><category term='Crime'/><category term='Certified Information Systems Security Professional'/><category term='Jim Stephens'/><category term='Todo+Cal+Sync'/><category term='Manure'/><category term='Mythtv'/><category term='Derren Brown'/><category term='Opinion OpenSSL'/><category term='Focus'/><category term='Privately held company'/><category term='(ISC)²'/><category term='Quote'/><category term='Attacks'/><category term='Pentagon'/><category term='Buckingham and Coffman'/><category term='iTouch'/><category term='Fraud'/><category term='Privacy'/><category term='Hurricane Irene'/><category term='vim'/><category term='Pessimism'/><category term='CVSS'/><category term='SCADA'/><category term='Ethics'/><category term='Preview'/><category term='Conflict of Interest'/><category term='Julian Russell'/><category term='White House'/><category term='Booby trap'/><category term='ifw'/><category term='iCal'/><category term='SANS'/><category term='Tracking Stolen iPhone'/><category term='Coaching'/><category term='Karminsky'/><category term='Common Sense Media'/><category term='Meetings'/><category term='Memorial Day'/><category term='David Hooper'/><category term='IT Security'/><category term='WEP'/><category term='Divinitation'/><category term='syncml'/><category term='Calaboration'/><category term='Hardy Heron'/><category term='SSN'/><category term='Release Management'/><category term='Hacking'/><category term='Gettysburg'/><category term='Education'/><category term='itunes'/><category term='Operational'/><category term='Phishing'/><category term='Twitter'/><category term='Backups'/><category term='Tricks of the Mind'/><category term='Architecture'/><category term='Personal Development'/><category term='gun'/><category term='EXIF Viewer'/><category term='Calendar'/><category term='The Secret'/><category term='IT'/><category term='Problem Management'/><category term='Configuration Management'/><category term='Cyberspace'/><category term='Government'/><category term='flybot'/><category term='William Gibson'/><category term='Sexy'/><category term='ReQall'/><category term='Conference'/><category term='Passwords'/><category term='Federal Bureau of Investigation'/><category term='Book'/><category term='Lost iPhone'/><category term='Operating System'/><category term='Hand Music'/><category term='blue screen'/><category term='CERT'/><category term='Web Design and Development'/><category term='Joke'/><category term='PCI'/><category term='Body Temple'/><category term='Tactical'/><category term='California'/><category term='Music'/><category term='Radio'/><category term='XMPP'/><category term='pico'/><category term='PCI DSS'/><category term='pistol'/><category term='Hypnosis'/><category term='Ideomotor Movement'/><category term='SLA'/><category term='Sexting'/><category term='Browser'/><category term='Malware'/><category term='Birmingham'/><category term='Domain Name System'/><category term='Convention'/><category term='Enterprise Security'/><category term='Google Calendar'/><category term='Mobile phone'/><category term='Social network'/><category term='Internet safety'/><category term='Password'/><category term='Service Level Management'/><category term='Google Apps'/><category term='PropertyShark'/><category term='AIM'/><category term='United States House Permanent Select Committee on Intelligence'/><category term='Audit'/><category term='BASIC'/><category term='IT Services'/><category term='Off Topic'/><category term='Desktop'/><category term='Risk Management'/><category term='Investigation'/><category term='Terrorism'/><category term='Photo'/><category term='P226R'/><category term='Windows'/><category term='SigArms'/><category term='Boomerang'/><category term='Dumb Little Man'/><category term='Jan Drömer'/><category term='vmx'/><category term='Identity Theft'/><category term='Cantina Band'/><category term='Remember The Milk'/><category term='video game systems'/><category term='Homeland security'/><category term='Dynamic Laws of Prosperity'/><category term='Police'/><category term='PVR'/><category term='Stephen Covey'/><category term='Arrest'/><category term='Oracle Calendar'/><category term='Apple II'/><category term='Budget'/><category term='8310'/><category term='Business Continuity'/><category term='FBI'/><category term='Cyber'/><category term='Strategy'/><category term='Personality'/><category term='ASV'/><category term='Availability Management'/><category term='harvard'/><category term='National security'/><category term='Gratitude'/><category term='ATT'/><category term='War on Terrorism'/><category term='Hardening'/><category term='Humility'/><category term='Organisational Structure'/><category term='SyncML2iCal'/><category term='iTrackr'/><category term='RIM'/><category term='Cryptography'/><category term='Unix'/><category term='Risk Analysis'/><category term='CorporateTime'/><category term='dd-wrt'/><category term='Podcast'/><category term='Consulting'/><category term='OpenSSL'/><category term='September 11 2001'/><category term='Encryption'/><category term='Oracle'/><category term='Astrid Alauda'/><category term='Edwin Meese'/><category term='Toolbox'/><category term='Christmas and holiday season'/><category term='RedHat'/><category term='Network Security'/><category term='AVS'/><category term='Wealth'/><category term='Instant Messaging'/><category term='OLA'/><category term='Research and Development'/><category term='FCC'/><category term='Facebook'/><category term='IM'/><category term='KUSP'/><category term='NLP'/><category term='Anne Deering'/><category term='Psychiatrist'/><category term='Journler'/><category term='Virtual world'/><category term='Google'/><category term='Social Security Number'/><category term='iPhone Calendar'/><category term='Outsource'/><category term='Comcast'/><category term='Data Security Standard'/><category term='Federal Communications Commission'/><category term='Dutch Ruppersberger'/><category term='Star Wars'/><category term='Dilbert'/><category term='Ubuntu'/><category term='Sophos'/><category term='USA Today'/><category term='wrt54gl'/><category term='DNS'/><category term='Agenda'/><category term='RTM'/><category term='VLADIMIR TSASTSIN'/><category term='Financial Management'/><category term='HTTPS'/><category term='Tracking iPhone'/><category term='Procedures'/><category term='Objectives'/><category term='DEFCON'/><category term='BIND'/><category term='Food and Drug Administration'/><category term='Flight Status'/><category term='OpenVPN'/><category term='Processes'/><category term='Incident Management'/><category term='Productivity'/><category term='RatProxy'/><category term='iphone'/><category term='Payment Card Industry'/><category term='SophosLabs'/><category term='DSL'/><category term='Questions'/><category term='Mac'/><category term='darpa'/><category term='PC'/><category term='Ronald Reagan'/><category term='Policy'/><category term='California Attorney General'/><category term='United States Chamber of Commerce'/><category term='Water industry'/><category term='WPA'/><category term='vmware'/><category term='Mythbrowser'/><category term='Gmail'/><category term='Self Improvement'/><category term='BBS'/><category term='Consultants'/><category term='hacker'/><category term='SSLv2'/><category term='Text messaging'/><category term='Symantec'/><category term='Alan Weiss'/><category term='Illinois'/><category term='Incident Response'/><category term='Success'/><category term='Process'/><category term='Employee Retention'/><category term='Organisation'/><category term='Abundance'/><category term='email attachments'/><category term='day notes'/><category term='Janet Napolitano'/><category term='Apple ID'/><category term='Legal'/><category term='Pony'/><category term='VU#800113'/><category term='Capabilities'/><category term='Stolen iPhone'/><category term='Sunday Post'/><category term='Andrea Lages'/><category term='CISSP'/><category term='Synthesis AG'/><category term='P226'/><category term='Firewall'/><category term='Information Security'/><category term='Security'/><category term='Proactive'/><category term='Joel Brenner'/><category term='Mozilla'/><category term='TRS-80'/><category term='Alex Shalman'/><category term='Jott'/><category term='Koobface'/><category term='Confidence'/><category term='Fyodor'/><category term='Catherine Ponder'/><category term='Magic'/><category term='Manualist'/><category term='linux'/><category term='Federal Trade Commission'/><category term='Network Manager'/><category term='Alpha Leadership'/><category term='emacs'/><category term='Charlie Chaplin'/><category term='wii'/><category term='Taskbar'/><category term='Web 2.0'/><category term='Phone'/><category term='Pandemic'/><category term='Pentest'/><category term='handgun'/><category term='United States Department of Homeland Security'/><category term='Google Talk'/><category term='Small business'/><category term='Reagan'/><category term='SUSE'/><category term='Intrusion Detection'/><category term='Industrial control system'/><category term='Cable Modem'/><category term='Training'/><category term='Tricks'/><category term='vlnerability scan'/><category term='WiFi'/><category term='read-only'/><category term='Cyber-bullying'/><title type='text'>Comments on Zen One: PCI Compliance - Disable SSLv2 and Weak Ciphers</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.zenone.org/feeds/9136266752224235795/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default?start-index=26&amp;max-results=25'/><author><name>Steve</name><uri>http://www.blogger.com/profile/05731012323706683031</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/_Oub6BciJUzM/TK_NOS6ZmgI/AAAAAAAAAA8/Pl1czUOP6Yo/S220/suit.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>45</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-5496937014193778698</id><published>2012-01-20T06:06:25.245-08:00</published><updated>2012-01-20T06:06:25.245-08:00</updated><title type='text'>hi..interesting article and thanks for the info..
...</title><content type='html'>hi..interesting article and thanks for the info..&lt;br /&gt;&lt;br /&gt;Weve applied the &amp;quot;fixes&amp;quot; onto 4 of our servers..all the same setup/implementation etc yet this has only blocked SSLv2 on two of them and not the others...Anybody seen this before or any ideas please??? Weve checked registry settings/spelling/hex/dec values/rebooted etc TIA.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/5496937014193778698'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/5496937014193778698'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1327068385245#c5496937014193778698' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1668261342'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-6792157964373063142</id><published>2011-12-20T08:27:25.552-08:00</published><updated>2011-12-20T08:27:25.552-08:00</updated><title type='text'>Hi there All 

I&amp;#39;m having issues to b PCI comp...</title><content type='html'>Hi there All &lt;br /&gt;&lt;br /&gt;I&amp;#39;m having issues to b PCI compliment&lt;br /&gt;But they weird thing is i ve got no IIS or Apache or any web service running on that IP &lt;br /&gt;This is where it all starts &lt;br /&gt;TCP Port:88 Risk:4 result FAIL &lt;br /&gt;Description: SSL server accepts weak ciphers Severity: Potential Problem Impact: A remote attacker with the ability to sniff network traffic could decrypt an encrypted session&lt;br /&gt;On Netstat&lt;br /&gt;Proto  Local Address          Foreign Address        State           PID&lt;br /&gt;TCP    192.168.100.150:88     192.168.100.29:1755    CLOSE_WAIT      972&lt;br /&gt;Tasklist &lt;br /&gt;PID 972 is used by lsass.exe 972 Service&lt;br /&gt;its somehow related to Kerberos don&amp;#39;t know why Can anyone help ?/&lt;br /&gt;Thx</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/6792157964373063142'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/6792157964373063142'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1324398445552#c6792157964373063142' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2006141418'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-3194563067741095123</id><published>2011-10-10T22:57:49.202-07:00</published><updated>2011-10-10T22:57:49.202-07:00</updated><title type='text'>Tried this over the weekend and it worked perfectl...</title><content type='html'>Tried this over the weekend and it worked perfectly. Thanks</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/3194563067741095123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/3194563067741095123'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1318312669202#c3194563067741095123' title=''/><author><name>us vpn</name><uri>http://www.foxyvpn.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-819798638'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-860590074403296803</id><published>2011-06-02T20:01:13.260-07:00</published><updated>2011-06-02T20:01:13.260-07:00</updated><title type='text'>Thank you much. This was very helpful in my first ...</title><content type='html'>Thank you much. This was very helpful in my first PCI compliance scan/fix.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/860590074403296803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/860590074403296803'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1307070073260#c860590074403296803' title=''/><author><name>stagnant</name><uri>http://www.blogger.com/profile/07717407667299247909</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-523270756'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-6159282076542854485</id><published>2011-05-11T16:15:54.538-07:00</published><updated>2011-05-11T16:15:54.538-07:00</updated><title type='text'>Hello,

I have created a simple free tool that all...</title><content type='html'>Hello,&lt;br /&gt;&lt;br /&gt;I have created a simple free tool that allows you to disable all weak ciphers on Windows Server 2003/2008.  It also has a template button for PCI and FIPS-140 compliance. Check out &lt;a href="https://www.nartac.com/Products/IISCrypto/Default.aspx" rel="nofollow"&gt;IIS Crypto&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Let me know what you think, thanks!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/6159282076542854485'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/6159282076542854485'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1305155754538#c6159282076542854485' title=''/><author><name>Jeff</name><uri>http://www.blogger.com/profile/06131778196655292199</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1255804979'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-8652561278829075342</id><published>2011-03-29T07:29:37.834-07:00</published><updated>2011-03-29T07:29:37.834-07:00</updated><title type='text'>Hi, does the DSS specifically state you can not us...</title><content type='html'>Hi, does the DSS specifically state you can not use ssl v2? I don&amp;#39;t see that even in version 2.0 of the DSS. I thought you only had to disable the weak ciphers.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/8652561278829075342'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/8652561278829075342'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1301408977834#c8652561278829075342' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1353089338'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-7588904329840693266</id><published>2011-03-10T07:27:17.074-08:00</published><updated>2011-03-10T07:27:17.074-08:00</updated><title type='text'>Has anyone (instead of completely disabling SSLv2 ...</title><content type='html'>Has anyone (instead of completely disabling SSLv2 / Weak Ciphers) successfully put in a redirect?  I am getting pressure to land our customers who have out of date browsers onto a page that gives them a link to go and upgrade their browser instead.  They still can&amp;#39;t continue to our website so in effect, we have disabled SSLv2 support.  Wondering if we can pass a PCI ASV scan with this approach?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/7588904329840693266'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/7588904329840693266'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1299770837074#c7588904329840693266' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1285179761'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-309298772601312896</id><published>2011-02-23T02:35:12.260-08:00</published><updated>2011-02-23T02:35:12.260-08:00</updated><title type='text'>PCI DSS is a real pain but important, the diy appr...</title><content type='html'>PCI DSS is a real pain but important, the diy approach is becoming hard and hard this is one of the reasons I use a hosted solution (SaaS)for my e commerce site, take to problem out of my hands, as long as they are PCI compliant then all well &lt;br /&gt;&lt;br /&gt; Ant&lt;br /&gt;&lt;a href="http://www.kaybeedoors.co.uk/doors/INTERNAL-DOORS/" rel="nofollow"&gt;internal doors&lt;/a&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/309298772601312896'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/309298772601312896'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1298457312260#c309298772601312896' title=''/><author><name>ant</name><uri>http://http;//www.kaybeedoors.co.uk</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-457318779'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-8650948608465162466</id><published>2011-02-16T09:49:44.734-08:00</published><updated>2011-02-16T09:49:44.734-08:00</updated><title type='text'>Thank you for the great post, it has helped me mov...</title><content type='html'>Thank you for the great post, it has helped me move forward in becoming PCI compliant.  However, my situation is that after following your guide, I still have SSLv2 and weak ciphers for a few ports.  Following your instructions helped a few problems, but not all.  Any clues on where I should look next to take care of this?  I have a virtual dedicated hosting plan running CentOS 5.5. Thank you.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/8650948608465162466'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/8650948608465162466'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1297878584734#c8650948608465162466' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-667934242'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-2721830621648451571</id><published>2010-12-29T11:24:33.032-08:00</published><updated>2010-12-29T11:24:33.032-08:00</updated><title type='text'>Just so you know, this is a perfect post in regard...</title><content type='html'>Just so you know, this is a perfect post in regards to a simple way to test and disable sslv2. I had to request 2 scans that failed before I found this wonderful post... Thanks so much and keep writing!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/2721830621648451571'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/2721830621648451571'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1293650673032#c2721830621648451571' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-890795412'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-5803904200757748976</id><published>2010-11-17T23:30:53.142-08:00</published><updated>2010-11-17T23:30:53.142-08:00</updated><title type='text'>I&amp;#39;ve recently started a blog, the information ...</title><content type='html'>I&amp;#39;ve recently started a blog, the information you provide on this site has helped me tremendously. Thank you for all of your time &amp;amp; work.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/5803904200757748976'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/5803904200757748976'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1290065453142#c5803904200757748976' title=''/><author><name>windows 7 starter</name><uri>http://www.windows7-key.net/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1776320024'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-3031051263028657392</id><published>2010-09-20T09:43:28.821-07:00</published><updated>2010-09-20T09:43:28.821-07:00</updated><title type='text'>I could use some help I am failing a PCI DSS scan ...</title><content type='html'>I could use some help I am failing a PCI DSS scan and I read thru the blog and noticed I am not running any kind of open ssl or Apache it looks like. I am running Server 2003 R2 Standard sp2 with IIS6 I have made the changes to the registry for the ciphers but still getting failed scans. Look forward to the comments and suggestions.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/3031051263028657392'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/3031051263028657392'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1285001008821#c3031051263028657392' title=''/><author><name>Zgnf05</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1963711982'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-4839738923527093467</id><published>2010-08-21T01:27:56.034-07:00</published><updated>2010-08-21T01:27:56.034-07:00</updated><title type='text'>Thanks this is the info: Apache/2.2.9 (Debian) PHP...</title><content type='html'>Thanks this is the info: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0 Server at www.privatebox.co.nz Port 80&lt;br /&gt;&lt;br /&gt;We are getting from firefox 4.3 ssl_error_renegotiation_not_allowed&lt;br /&gt;&lt;br /&gt;do you have any suggestions? I do not want to give out our website as it will appear on a google search.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/4839738923527093467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/4839738923527093467'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1282379276034#c4839738923527093467' title=''/><author><name>Steveonz</name><uri>http://www.blogger.com/profile/17961371152751851154</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1922485224'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-2804872480239979419</id><published>2010-08-21T00:16:08.028-07:00</published><updated>2010-08-21T00:16:08.028-07:00</updated><title type='text'>#Steveonz - Not sure what you&amp;#39;re running on yo...</title><content type='html'>#Steveonz - Not sure what you&amp;#39;re running on your end, but for starters, make sure OpenSSL is updated (anything prior to 0.9.8l will pose a problem). As well, make sure mod_ssl in Apache is updated (v2.2.14 and earlier will be an issue).</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/2804872480239979419'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/2804872480239979419'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1282374968028#c2804872480239979419' title=''/><author><name>Steve Zenone</name><uri>http://www.blogger.com/profile/18092491053989613420</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://1.bp.blogspot.com/_f5zPJR8dXDg/SaoJqtY-c7I/AAAAAAAAETE/Q9mzpADRrPg/S220/profilepic.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1869070143'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-4651083988340816398</id><published>2010-08-20T23:31:19.043-07:00</published><updated>2010-08-20T23:31:19.043-07:00</updated><title type='text'>Hey,

We have disabled SSLv2 and weak Cyphers but ...</title><content type='html'>Hey,&lt;br /&gt;&lt;br /&gt;We have disabled SSLv2 and weak Cyphers but this is causing issues on firefox b 4.3 and OSX Chrome.&lt;br /&gt;&lt;br /&gt;This is what firefox state: SSL3 &amp;amp; TLS Renegotiation Vulnerability&lt;br /&gt;&lt;br /&gt;    See CVE-2009-3555 and US-CERT VU#120541 for more information about this security vulnerability.&lt;br /&gt;&lt;br /&gt;    All SSL/TLS renegotiation is disabled by default in NSS 3.12.5. This will cause programs that attempt to perform renegotiation to experience failures where they formerly experienced successes, and is necessary for them to not be vulnerable, until such time as a new safe renegotiation scheme is standardized by the IETF.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;What can be done?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/4651083988340816398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/4651083988340816398'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1282372279043#c4651083988340816398' title=''/><author><name>Steveonz</name><uri>http://www.blogger.com/profile/17961371152751851154</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1922485224'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-2173321291794747677</id><published>2010-06-01T02:13:23.142-07:00</published><updated>2010-06-01T02:13:23.142-07:00</updated><title type='text'>Hello there, quick question, I&amp;#39;ve modified the...</title><content type='html'>Hello there, quick question, I&amp;#39;ve modified the SSLCipherSuite string as suggested then restart Apache&lt;br /&gt;&lt;br /&gt;SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM&lt;br /&gt;&lt;br /&gt;However, to verify it&amp;#39;s working I&amp;#39;m using Nessus which once again shows that I&amp;#39;m using weak/medium strenght cipher suite.&lt;br /&gt;&lt;br /&gt;I&amp;#39;ve read something that might be the browsers, I mean, you&amp;#39;ve configured correctly the server but if the browser doesn&amp;#39;t accept STRONG ciphers, then the cipher is downgraded or something like that, so I&amp;#39;m wondering if this could be the reason of the findings in Nessus. Any suggestion?&lt;br /&gt;&lt;br /&gt;Thx!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/2173321291794747677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/2173321291794747677'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1275383603142#c2173321291794747677' title=''/><author><name>ViKBaNg</name><uri>http://www.blogger.com/profile/14550343642911150132</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://4.bp.blogspot.com/_g2et53lBHm4/SJp1SbxaCUI/AAAAAAAABow/q8WaYat7MFg/s1600-R/me2.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-294072498'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-3108632951224068883</id><published>2010-04-26T09:25:42.695-07:00</published><updated>2010-04-26T09:25:42.695-07:00</updated><title type='text'>Anonymous wrote:
&amp;gt; Is there a script or any too...</title><content type='html'>Anonymous wrote:&lt;br /&gt;&amp;gt; Is there a script or any tool that &lt;br /&gt;&amp;gt; can check SSL with this condition:&lt;br /&gt;&lt;br /&gt;Check out SSLscan:&lt;br /&gt;http://sourceforge.net/projects/sslscan/</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/3108632951224068883'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/3108632951224068883'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1272299142695#c3108632951224068883' title=''/><author><name>Steve Zenone</name><uri>http://www.blogger.com/profile/18092491053989613420</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='28' src='http://1.bp.blogspot.com/_f5zPJR8dXDg/SaoJqtY-c7I/AAAAAAAAETE/Q9mzpADRrPg/S220/profilepic.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1869070143'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-9079463377305799123</id><published>2010-04-26T09:17:22.289-07:00</published><updated>2010-04-26T09:17:22.289-07:00</updated><title type='text'>Thanks alot!</title><content type='html'>Thanks alot!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/9079463377305799123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/9079463377305799123'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1272298642289#c9079463377305799123' title=''/><author><name>Interior Doors</name><uri>http://www.doorsuppliesonline.co.uk/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1113617381'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-6215022154410178003</id><published>2010-04-25T16:47:12.036-07:00</published><updated>2010-04-25T16:47:12.036-07:00</updated><title type='text'>Hi,

Is there a script or any tool that can check ...</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;Is there a script or any tool that can check SSL with this condition:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;    * SSL Server Allows Cleartext Encryption&lt;br /&gt;    * SSL Server May Be Forced to Use Weak Encryption&lt;br /&gt;    * SSL Server Allows Anonymous Authentication&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/6215022154410178003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/6215022154410178003'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1272239232036#c6215022154410178003' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-491163418'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-7562816467373004979</id><published>2010-04-16T15:34:55.520-07:00</published><updated>2010-04-16T15:34:55.520-07:00</updated><title type='text'>The Microsoft KB article worked like a champ. The ...</title><content type='html'>The Microsoft KB article worked like a champ. The only catch for me was when I got to the end of the registry key the final key &amp;quot;Server&amp;quot; was not present on my machine so I had to create a Key named &amp;quot;server&amp;quot; then place a new DWORD, name it &amp;quot;Enabled&amp;quot; within the key and set the Hex value to 00000000. Reboot, and then all was good.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/7562816467373004979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/7562816467373004979'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1271457295520#c7562816467373004979' title=''/><author><name>Jonny B</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-206125528'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-4459835106696709652</id><published>2010-03-07T02:57:40.362-08:00</published><updated>2010-03-07T02:57:40.362-08:00</updated><title type='text'>Clear and straight to the point. Thanks.</title><content type='html'>Clear and straight to the point. Thanks.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/4459835106696709652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/4459835106696709652'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1267959460362#c4459835106696709652' title=''/><author><name>Marco</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-57469765'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-1930362720326890286</id><published>2010-01-12T10:06:49.098-08:00</published><updated>2010-01-12T10:06:49.098-08:00</updated><title type='text'>fyi, sslscan can be found here: http://sourceforge...</title><content type='html'>fyi, sslscan can be found here: http://sourceforge.net/projects/sslscan/</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/1930362720326890286'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/1930362720326890286'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1263319609098#c1930362720326890286' title=''/><author><name>jcran</name><uri>http://www.0x0e.org</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-118831825'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-7598754312703483080</id><published>2010-01-12T10:05:17.718-08:00</published><updated>2010-01-12T10:05:17.718-08:00</updated><title type='text'>sslscan is an (easier) way to do this. it lists al...</title><content type='html'>sslscan is an (easier) way to do this. it lists all ciphers: &lt;br /&gt;&lt;br /&gt; jcran@aldatmak:~$ sslscan www.google.com|  grep -i accepted&lt;br /&gt;    Accepted  SSLv3  256 bits  AES256-SHA&lt;br /&gt;    Accepted  SSLv3  128 bits  AES128-SHA&lt;br /&gt;    Accepted  SSLv3  168 bits  DES-CBC3-SHA&lt;br /&gt;    Accepted  SSLv3  128 bits  RC4-SHA&lt;br /&gt;    Accepted  SSLv3  128 bits  RC4-MD5&lt;br /&gt;    Accepted  TLSv1  256 bits  AES256-SHA&lt;br /&gt;    Accepted  TLSv1  128 bits  AES128-SHA&lt;br /&gt;    Accepted  TLSv1  168 bits  DES-CBC3-SHA&lt;br /&gt;    Accepted  TLSv1  128 bits  RC4-SHA&lt;br /&gt;    Accepted  TLSv1  128 bits  RC4-MD5</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/7598754312703483080'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/7598754312703483080'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1263319517718#c7598754312703483080' title=''/><author><name>jcran</name><uri>http://www.0x0e.org</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-118831825'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-7595083394038878366</id><published>2010-01-11T18:25:51.647-08:00</published><updated>2010-01-11T18:25:51.647-08:00</updated><title type='text'>very informative! Thanks!</title><content type='html'>very informative! Thanks!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/7595083394038878366'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/7595083394038878366'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1263263151647#c7595083394038878366' title=''/><author><name>Alberto Siow</name><uri>http://www.blogger.com/profile/12194695190087628573</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://4.bp.blogspot.com/_FNdm0iK4Nuo/SMXxXbTnsxI/AAAAAAAAAI0/nUEEWSzRbkM/S220/zhi.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1815009506'/></entry><entry><id>tag:blogger.com,1999:blog-7267320703085764135.post-2532672073173528961</id><published>2010-01-05T21:56:19.726-08:00</published><updated>2010-01-05T21:56:19.726-08:00</updated><title type='text'>Hi,
We are planning to upgrade IIS from SSL v2 to ...</title><content type='html'>Hi,&lt;br /&gt;We are planning to upgrade IIS from SSL v2 to v3. If the secure sites have server certificates installed, what changes need to be done? Do we need to reinstall the certificates? What other configuration changes have to be done?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/2532672073173528961'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7267320703085764135/9136266752224235795/comments/default/2532672073173528961'/><link rel='alternate' type='text/html' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html?showComment=1262757379726#c2532672073173528961' title=''/><author><name>Amshu</name><uri>http://www.blogger.com/profile/09082253098863949988</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html' ref='tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795' source='http://www.blogger.com/feeds/7267320703085764135/posts/default/9136266752224235795' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1886544385'/></entry></feed>
