Weak SSL Cipher support revisited

Need help with FileZilla Server? Something does not work as expected? In this forum you may find an answer.

Moderator: Project members

Post Reply
Message
Author
dasfx
500 Command not understood
Posts: 2
Joined: 2009-11-24 21:20
First name: David
Last name: Shpritz

Weak SSL Cipher support revisited

#1 Post by dasfx » 2009-11-24 21:33

Hello,
Unfortunately I have customers which are required to go through PCI compliance scans. One of the more recent scans flagged the FileZilla server for weak SSL cipher support. Currently the server is running the latest version (0.9.33), so this means no SSLv2, however when testing (OpenSSL, perl and ServerSniff.net) I see the following:
DES-CBC-SHA -- 56 bits, Low Encryption

Which is being flagged by the scanning vendor. Are there plans to remove support for the 56-bit cipher or perhaps a workaround? I know PCI can be BS, but the customers doesn't really have a choice if they want to keep processing credit cards.

Thank you in advance,

Dave

Solido
500 Command not understood
Posts: 1
Joined: 2009-11-26 12:30
First name: Sol
Last name: Ido

Re: Weak SSL Cipher support revisited

#2 Post by Solido » 2009-11-26 12:32

I'm really interested in this concern. Thank you for leverage this question.
Sol

cyberknutte
500 Command not understood
Posts: 1
Joined: 2009-11-30 14:14
First name: Andreas
Last name: Knutsson

Re: Weak SSL Cipher support revisited

#3 Post by cyberknutte » 2009-11-30 14:28

Hi,

I have the same issue. Our company is PCI DSS certified and we would like to use Filezilla Server. We use Qualys as security scanner and this is the result:

Image
Image

Level 3 vulnerabilities is not allowed for PCI DSS compliance.

Best regards,
Andreas

redswimmer
500 Command not understood
Posts: 4
Joined: 2009-12-29 20:13
First name: Andrew
Last name: Savala

Re: Weak SSL Cipher support revisited

#4 Post by redswimmer » 2009-12-29 20:19

Having the same issue with Qualys saying our FileZilla server is using the following "WEAK Ciphers": DES-CBC-SHA and DES-CBC-SHA

User avatar
botg
Site Admin
Posts: 35558
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: Weak SSL Cipher support revisited

#5 Post by botg » 2009-12-29 21:29

These ciphers will be disabled in the next version of FileZilla Server. I thought had disabled them already by disallowing SSLv2, but somehow OpenSSL did still pull them in for some reason.

I sat down with the library and had a stern talk with it about ciphers. :wink:

redswimmer
500 Command not understood
Posts: 4
Joined: 2009-12-29 20:13
First name: Andrew
Last name: Savala

Re: Weak SSL Cipher support revisited

#6 Post by redswimmer » 2009-12-29 22:28

I really appreciate it, thanks. Does the next release have an estimated date by chance?

User avatar
botg
Site Admin
Posts: 35558
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: Weak SSL Cipher support revisited

#7 Post by botg » 2009-12-29 23:04

This year.

redswimmer
500 Command not understood
Posts: 4
Joined: 2009-12-29 20:13
First name: Andrew
Last name: Savala

Re: Weak SSL Cipher support revisited

#8 Post by redswimmer » 2009-12-30 00:06

Excellent. Glad to hear I got in under the wire. Thanks again!

User avatar
boco
Contributor
Posts: 26934
Joined: 2006-05-01 03:28
Location: Germany

Re: Weak SSL Cipher support revisited

#9 Post by boco » 2009-12-30 17:27

botg wrote:This year.
You have plenty of time --- or not? :mrgreen:
No support requests over PM! You will NOT get any reply!!!
FTP connection problems? Please read Network Configuration.
FileZilla connection test: https://filezilla-project.org/conntest.php
FileZilla Pro support: https://customerforum.fileZilla-project.org

monorailpilot
500 Command not understood
Posts: 2
Joined: 2009-03-19 13:20
First name: Jeff
Last name: Carter

Re: Weak SSL Cipher support revisited

#10 Post by monorailpilot » 2010-01-05 13:49

Thanks. Much appreciated here as well.

dasfx
500 Command not understood
Posts: 2
Joined: 2009-11-24 21:20
First name: David
Last name: Shpritz

Re: Weak SSL Cipher support revisited

#11 Post by dasfx » 2010-01-11 20:24

This is why I love open source. Thanks much!

Dave

Post Reply