Poodle Vulnerability and SSTP

Post your questions about SoftEther VPN software here. Please answer questions if you can afford.
Post Reply
kapp
Posts: 3
Joined: Thu Oct 16, 2014 12:56 pm

Poodle Vulnerability and SSTP

Post by kapp » Thu Oct 16, 2014 12:59 pm

Any concerns about SoftEther's implementation of SSTP and the Poodle Vulnerability with SSL 3.0/2.0 ?

thanks!
Last edited by kapp on Mon Oct 20, 2014 11:52 pm, edited 1 time in total.

ziphead
Posts: 5
Joined: Fri Oct 17, 2014 1:45 am

Re: Poodle Vunerability and SSTP

Post by ziphead » Fri Oct 17, 2014 2:01 am

Joining the question. Shall we use l2p or openvpn instead ssl ? Do we need to wait for the security update ?

maurer
Posts: 3
Joined: Wed Apr 23, 2014 9:46 am

Re: Poodle Vunerability and SSTP

Post by maurer » Fri Oct 17, 2014 7:16 am

+1
Is SoftetherVPN Vulnerable to Poodle?

ziphead
Posts: 5
Joined: Fri Oct 17, 2014 1:45 am

Re: Poodle Vunerability and SSTP

Post by ziphead » Sat Oct 18, 2014 4:45 am

Poodle can be applied via "man in the middle" attack. So I hope self signed or server signed certificates will protect clients. But I didn't find how to make VPN server manager for windows use only certificates to login(not passwords).
And I'm still not sure if poodle can decrypt all the traffic passing through...

kapp
Posts: 3
Joined: Thu Oct 16, 2014 12:56 pm

Re: Poodle Vulnerability and SSTP

Post by kapp » Mon Oct 20, 2014 3:54 pm

Apparently SoftEther's SSTP Server (CentOS 6.5) does accept SSLv3.

This command shows SSL3 is AOK:

openssl s_client -connect your.vpnserver.com:443 -ssl3

Is there any way to disable SSLv3 in SoftEther's implementation on a Linux server?

dnobori
Posts: 230
Joined: Tue Mar 05, 2013 10:04 am

Re: Poodle Vulnerability and SSTP

Post by dnobori » Wed Oct 22, 2014 4:19 pm


kapp
Posts: 3
Joined: Thu Oct 16, 2014 12:56 pm

Re: Poodle Vulnerability and SSTP

Post by kapp » Thu Oct 23, 2014 2:15 pm

This worked great. Thank you.

Post Reply