So what’s the real world impact of a server running sslv2?
So what’s the real world impact of a server running sslv2?
https://www.cs.umd.edu/class/spring2021/cmsc614/papers/drown...
1) It makes it easier for attackers to mount attacks. It gives them another tool they can use to attack your service. My guess is supporting SSLv2 makes it easier to mount downgrade attacks against a server (i.e. an attack where you can trick the client and the server to use SSLv2 instead of a secure protocol).
2) You should not run unnecessary code on your services. It gives attackers a chance to hack your service because the unnecessary code can be exploited.
2) This one yes.
Iirc it was possible to perform downgrade attacks upto sslv3, but again the client must accept these algorithms - modern browsers reject them.
Disabling port 80 has no value[1], unless clients who do not respect hsts are of concern (I think curl does not).
2) Is there any public case studies of remotely exploitable code via sslv2? granted poodle etc are still a thing, but they are cryptgraphic attacks which rely on the client accepting ssl in the first place.
imo more importantly, if they are running SSLv2 they almost certainly have really bad vulnerabilities somewhere as they’re clearly running legacy systems evidenced by sslv2, but I am not aware of any directly exploitable servers due specifically to sslv2 being enabled.
This kind of alarmism creates security fatigue, wasting time and resources rather than focusing on actual security issues.