Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix compression detection #80

Merged
merged 3 commits into from
Mar 6, 2016
Merged

Fix compression detection #80

merged 3 commits into from
Mar 6, 2016

Conversation

nuxi
Copy link
Contributor

@nuxi nuxi commented Mar 5, 2016

Three issues here:

  1. sslscan wasn't clearing SSL_OP_NO_COMPRESSION which may be set by default in some builds of OpenSSL
  2. sslscan wasn't verifying that COMP_zlib support was actually present
  3. The static build of openssl wasn't building zlib support

nuxi added 3 commits March 5, 2016 17:36
This flag is set by default in some builds of OpenSSL
OpenSSL can be built with compression support but without any
compression methods. This results in the compression test passing even
if compression is enabled on the remote server.
rbsec added a commit that referenced this pull request Mar 6, 2016
Fix compression detection
@rbsec rbsec merged commit 5afec19 into rbsec:master Mar 6, 2016
rbsec added a commit that referenced this pull request Mar 6, 2016
@rbsec
Copy link
Owner

rbsec commented Mar 6, 2016

Thanks for the PR, it all looks good so I've merged it in.

Statically building with zlib support adds a dependency for zlib1g-dev, so I've added a note into the readme to install it.

~rbsec

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants