Mailing List Archive

SSLV3 and cookies
Hi all,



After running a vulnerability scan it came back that ntop has SSLV3 enabled and SSL/TLS is missing the secure cookie attribute.  Which files would I edit to take care of these? 



Thanks in Advance!
Re: SSLV3 and cookies [ In reply to ]
Hi Tim,

Please follow the issue on our github page
https://github.com/ntop/ntopng/issues/1483

Thank you for reporting!
Emanuele

On Tue, Sep 26, 2017 at 1:53 PM, Tim Wolak <tim.wolak@gmail.com> wrote:
> Hi all,
>
> After running a vulnerability scan it came back that ntop has SSLV3
> enabled and SSL/TLS is missing the secure cookie attribute. Which
> files would I edit to take care of these?
>
> Thanks in Advance!
>
>
>
>
Re: SSLV3 and cookies [ In reply to ]
Hi Tim,

Please follow the issue on our github page
https://github.com/ntop/ntopng/issues/1483

Thank you for reporting!
Emanuele

On Tue, Sep 26, 2017 at 1:53 PM, Tim Wolak <tim.wolak@gmail.com> wrote:
> Hi all,
>
> After running a vulnerability scan it came back that ntop has SSLV3
> enabled and SSL/TLS is missing the secure cookie attribute. Which
> files would I edit to take care of these?
>
> Thanks in Advance!
>
>
>
>
Re: SSLV3 and cookies [ In reply to ]
Thank you Emanuele, Can you please tell me the file location so I can make the correction.  Also how do you disable SSLV3?



Thanks,

Tim



From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele Faranda <faranda@ntop.org>
Reply-To: <ntop@unipi.it>
Date: Tuesday, September 26, 2017 at 9:04 AM
To: <ntop@unipi.it>
Cc: <ntop@listgateway.unipi.it>
Subject: Re: [Ntop] SSLV3 and cookies



Hi Tim,



Please follow the issue on our github page https://github.com/ntop/ntopng/issues/1483



Thank you for reporting!

Emanuele


On Tue, Sep 26, 2017 at 1:53 PM, Tim Wolak <tim.wolak@gmail.com> wrote:


Hi all,



After running a vulnerability scan it came back that ntop has SSLV3 enabled and SSL/TLS is missing the secure cookie attribute. Which files would I edit to take care of these?



Thanks in Advance!









_______________________________________________ Ntop mailing list Ntop@listgateway.unipi.it http://listgateway.unipi.it/mailman/listinfo/ntop
Re: SSLV3 and cookies [ In reply to ]
Thank you Emanuele, Can you please tell me the file location so I can make the correction.  Also how do you disable SSLV3?



Thanks,

Tim



From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele Faranda <faranda@ntop.org>
Reply-To: <ntop@unipi.it>
Date: Tuesday, September 26, 2017 at 9:04 AM
To: <ntop@unipi.it>
Cc: <ntop@listgateway.unipi.it>
Subject: Re: [Ntop] SSLV3 and cookies



Hi Tim,



Please follow the issue on our github page https://github.com/ntop/ntopng/issues/1483



Thank you for reporting!

Emanuele


On Tue, Sep 26, 2017 at 1:53 PM, Tim Wolak <tim.wolak@gmail.com> wrote:


Hi all,



After running a vulnerability scan it came back that ntop has SSLV3 enabled and SSL/TLS is missing the secure cookie attribute. Which files would I edit to take care of these?



Thanks in Advance!









_______________________________________________ Ntop mailing list Ntop@listgateway.unipi.it http://listgateway.unipi.it/mailman/listinfo/ntop
Re: SSLV3 and cookies [ In reply to ]
Hi, I've created a new issue with the SSLv3 information. Please check
out https://github.com/ntop/ntopng/issues/1484

The relevant files are HTTPServer.cpp and mongoose.c

Emanuele

On Tue, Sep 26, 2017 at 4:43 PM, Tim Wolak <tim.wolak@gmail.com> wrote:
> Thank you Emanuele, Can you please tell me the file location so I can
> make the correction. Also how do you disable SSLV3?
>
> Thanks,
> Tim
>
> From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele
> Faranda <faranda@ntop.org>
> Reply-To: <ntop@unipi.it>
> Date: Tuesday, September 26, 2017 at 9:04 AM
> To: <ntop@unipi.it>
> Cc: <ntop@listgateway.unipi.it>
> Subject: Re: [Ntop] SSLV3 and cookies
>
> Hi Tim,
>
> Please follow the issue on our github page
> https://github.com/ntop/ntopng/issues/1483
>
> Thank you for reporting!
> Emanuele
>
> On Tue, Sep 26, 2017 at 1:53 PM, Tim Wolak <tim.wolak@gmail.com>
> wrote:
>
>> Hi all,
>>
>> After running a vulnerability scan it came back that ntop has SSLV3
>> enabled and SSL/TLS is missing the secure cookie attribute. Which
>> files would I edit to take care of these?
>>
>> Thanks in Advance!
>>
>>
>>
>>
> _______________________________________________ Ntop mailing list
> Ntop@listgateway.unipi.it
> http://listgateway.unipi.it/mailman/listinfo/ntop
Re: SSLV3 and cookies [ In reply to ]
Hi, I've created a new issue with the SSLv3 information. Please check
out https://github.com/ntop/ntopng/issues/1484

The relevant files are HTTPServer.cpp and mongoose.c

Emanuele

On Tue, Sep 26, 2017 at 4:43 PM, Tim Wolak <tim.wolak@gmail.com> wrote:
> Thank you Emanuele, Can you please tell me the file location so I can
> make the correction. Also how do you disable SSLV3?
>
> Thanks,
> Tim
>
> From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele
> Faranda <faranda@ntop.org>
> Reply-To: <ntop@unipi.it>
> Date: Tuesday, September 26, 2017 at 9:04 AM
> To: <ntop@unipi.it>
> Cc: <ntop@listgateway.unipi.it>
> Subject: Re: [Ntop] SSLV3 and cookies
>
> Hi Tim,
>
> Please follow the issue on our github page
> https://github.com/ntop/ntopng/issues/1483
>
> Thank you for reporting!
> Emanuele
>
> On Tue, Sep 26, 2017 at 1:53 PM, Tim Wolak <tim.wolak@gmail.com>
> wrote:
>
>> Hi all,
>>
>> After running a vulnerability scan it came back that ntop has SSLV3
>> enabled and SSL/TLS is missing the secure cookie attribute. Which
>> files would I edit to take care of these?
>>
>> Thanks in Advance!
>>
>>
>>
>>
> _______________________________________________ Ntop mailing list
> Ntop@listgateway.unipi.it
> http://listgateway.unipi.it/mailman/listinfo/ntop
Re: SSLV3 and cookies [ In reply to ]
Thanks Emanuele, but where are they located?



From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele Faranda <faranda@ntop.org>
Reply-To: <ntop@unipi.it>
Date: Tuesday, September 26, 2017 at 10:05 AM
To: <ntop@unipi.it>
Cc: <ntop@listgateway.unipi.it>
Subject: Re: [Ntop] SSLV3 and cookies



Hi, I've created a new issue with the SSLv3 information. Please check out https://github.com/ntop/ntopng/issues/1484



The relevant files are HTTPServer.cpp and mongoose.c



Emanuele


On Tue, Sep 26, 2017 at 4:43 PM, Tim Wolak <tim.wolak@gmail.com> wrote:


Thank you Emanuele, Can you please tell me the file location so I can make the correction. Also how do you disable SSLV3?



Thanks,

Tim



From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele Faranda <faranda@ntop.org>
Reply-To: <ntop@unipi.it>
Date: Tuesday, September 26, 2017 at 9:04 AM
To: <ntop@unipi.it>
Cc: <ntop@listga teway.un ipi.it>
Subject: Re: [Ntop] SSLV3 and cookies



Hi Tim,



Please follow the issue on our github page https://github.com/ntop/ntopng/issues/1483



Thank you for reporting!

Emanuele


On Tue, Sep 26, 2017 at 1:53 PM, Tim Wolak <tim.wolak@gmail.com> wrote:



Hi all,



After running a vulnerability scan it came back that ntop has SSLV3 enabled and SSL/TLS is missing the secure cookie attribute. Which files would I edit to take care of these?



Thanks in Advance!









_______________________________________________ Ntop mailing list Ntop@ listgate way.unipi.it http://listgateway.unipi.it/mailman/listinfo/ntop

_______________________________________________ Ntop mailing list Ntop@listgateway.unipi.it http://listgateway.unipi.it/mailman/listinfo/ntop
Re: SSLV3 and cookies [ In reply to ]
Thanks Emanuele, but where are they located?



From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele Faranda <faranda@ntop.org>
Reply-To: <ntop@unipi.it>
Date: Tuesday, September 26, 2017 at 10:05 AM
To: <ntop@unipi.it>
Cc: <ntop@listgateway.unipi.it>
Subject: Re: [Ntop] SSLV3 and cookies



Hi, I've created a new issue with the SSLv3 information. Please check out https://github.com/ntop/ntopng/issues/1484



The relevant files are HTTPServer.cpp and mongoose.c



Emanuele


On Tue, Sep 26, 2017 at 4:43 PM, Tim Wolak <tim.wolak@gmail.com> wrote:


Thank you Emanuele, Can you please tell me the file location so I can make the correction. Also how do you disable SSLV3?



Thanks,

Tim



From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele Faranda <faranda@ntop.org>
Reply-To: <ntop@unipi.it>
Date: Tuesday, September 26, 2017 at 9:04 AM
To: <ntop@unipi.it>
Cc: <ntop@listga teway.un ipi.it>
Subject: Re: [Ntop] SSLV3 and cookies



Hi Tim,



Please follow the issue on our github page https://github.com/ntop/ntopng/issues/1483



Thank you for reporting!

Emanuele


On Tue, Sep 26, 2017 at 1:53 PM, Tim Wolak <tim.wolak@gmail.com> wrote:



Hi all,



After running a vulnerability scan it came back that ntop has SSLV3 enabled and SSL/TLS is missing the secure cookie attribute. Which files would I edit to take care of these?



Thanks in Advance!









_______________________________________________ Ntop mailing list Ntop@ listgate way.unipi.it http://listgateway.unipi.it/mailman/listinfo/ntop

_______________________________________________ Ntop mailing list Ntop@listgateway.unipi.it http://listgateway.unipi.it/mailman/listinfo/ntop
Re: SSLV3 and cookies [ In reply to ]
find . -name mongoose.c
./third-party/mongoose/mongoose.c
find . -name HTTPserver.cpp
./src/HTTPserver.cpp

Easy ;)

Please feel free to contribute to the issues and to provide patches

Regards,
Emanuele

On Tue, Sep 26, 2017 at 5:07 PM, Tim Wolak <tim.wolak@gmail.com> wrote:
> Thanks Emanuele, but where are they located?
>
> From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele
> Faranda <faranda@ntop.org>
> Reply-To: <ntop@unipi.it>
> Date: Tuesday, September 26, 2017 at 10:05 AM
> To: <ntop@unipi.it>
> Cc: <ntop@listgateway.unipi.it>
> Subject: Re: [Ntop] SSLV3 and cookies
>
> Hi, I've created a new issue with the SSLv3 information. Please check
> out https://github.com/ntop/ntopng/issues/1484
>
> The relevant files are HTTPServer.cpp and mongoose.c
>
> Emanuele
>
> On Tue, Sep 26, 2017 at 4:43 PM, Tim Wolak <tim.wolak@gmail.com>
> wrote:
>
>> Thank you Emanuele, Can you please tell me the file location so I
>> can make the correction. Also how do you disable SSLV3?
>>
>> Thanks,
>> Tim
>>
>> From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele
>> Faranda <faranda@ntop.org>
>> Reply-To: <ntop@unipi.it>
>> Date: Tuesday, September 26, 2017 at 9:04 AM
>> To: <ntop@unipi.it>
>> Cc: <ntop@listga teway.un ipi.it>
>> Subject: Re: [Ntop] SSLV3 and cookies
>>
>> Hi Tim,
>>
>> Please follow the issue on our github page
>> https://github.com/ntop/ntopng/issues/1483
>>
>> Thank you for reporting!
>> Emanuele
>>
>> On Tue, Sep 26, 2017 at 1:53 PM, Tim Wolak <tim.wolak@gmail.com>
>> wrote:
>>
>>
>>> Hi all,
>>>
>>> After running a vulnerability scan it came back that ntop has SSLV3
>>> enabled and SSL/TLS is missing the secure cookie attribute. Which
>>> files would I edit to take care of these?
>>>
>>> Thanks in Advance!
>>>
>>>
>>>
>>>
>> _______________________________________________ Ntop mailing list
>> Ntop@ listgate way.unipi.it
>> http://listgateway.unipi.it/mailman/listinfo/ntop
> _______________________________________________ Ntop mailing list
> Ntop@listgateway.unipi.it
> http://listgateway.unipi.it/mailman/listinfo/ntop
Re: SSLV3 and cookies [ In reply to ]
find . -name mongoose.c
./third-party/mongoose/mongoose.c
find . -name HTTPserver.cpp
./src/HTTPserver.cpp

Easy ;)

Please feel free to contribute to the issues and to provide patches

Regards,
Emanuele

On Tue, Sep 26, 2017 at 5:07 PM, Tim Wolak <tim.wolak@gmail.com> wrote:
> Thanks Emanuele, but where are they located?
>
> From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele
> Faranda <faranda@ntop.org>
> Reply-To: <ntop@unipi.it>
> Date: Tuesday, September 26, 2017 at 10:05 AM
> To: <ntop@unipi.it>
> Cc: <ntop@listgateway.unipi.it>
> Subject: Re: [Ntop] SSLV3 and cookies
>
> Hi, I've created a new issue with the SSLv3 information. Please check
> out https://github.com/ntop/ntopng/issues/1484
>
> The relevant files are HTTPServer.cpp and mongoose.c
>
> Emanuele
>
> On Tue, Sep 26, 2017 at 4:43 PM, Tim Wolak <tim.wolak@gmail.com>
> wrote:
>
>> Thank you Emanuele, Can you please tell me the file location so I
>> can make the correction. Also how do you disable SSLV3?
>>
>> Thanks,
>> Tim
>>
>> From: <ntop-bounces@listgateway.unipi.it> on behalf of Emanuele
>> Faranda <faranda@ntop.org>
>> Reply-To: <ntop@unipi.it>
>> Date: Tuesday, September 26, 2017 at 9:04 AM
>> To: <ntop@unipi.it>
>> Cc: <ntop@listga teway.un ipi.it>
>> Subject: Re: [Ntop] SSLV3 and cookies
>>
>> Hi Tim,
>>
>> Please follow the issue on our github page
>> https://github.com/ntop/ntopng/issues/1483
>>
>> Thank you for reporting!
>> Emanuele
>>
>> On Tue, Sep 26, 2017 at 1:53 PM, Tim Wolak <tim.wolak@gmail.com>
>> wrote:
>>
>>
>>> Hi all,
>>>
>>> After running a vulnerability scan it came back that ntop has SSLV3
>>> enabled and SSL/TLS is missing the secure cookie attribute. Which
>>> files would I edit to take care of these?
>>>
>>> Thanks in Advance!
>>>
>>>
>>>
>>>
>> _______________________________________________ Ntop mailing list
>> Ntop@ listgate way.unipi.it
>> http://listgateway.unipi.it/mailman/listinfo/ntop
> _______________________________________________ Ntop mailing list
> Ntop@listgateway.unipi.it
> http://listgateway.unipi.it/mailman/listinfo/ntop