Hello Everyone,

As many of you aware OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the “CCS Injection” vulnerability.

Following is the script to scan internal systems offline detection tool.  This offline tool is not supported and is provided for informational purposes only. Download the tool or use the following script:

 

 

 [/fusion_builder_column][/fusion_builder_row][/fusion_builder_container]