Network Management

Active diagnostics reporting SSL v2 drown attack vulnerability

Outdated SSL versions come with vulnerabilities. It is recommended they are disabled.

First published date

5/19/2020 5:47 PM

Last published date

6/9/2022 7:07 PM

Overview

This article goes through the steps to resolve the drown attack vulnerability shown in active diagnostics.

Product section

Network Performance Monitor

Cause

For more information on this issue, please see  Refer to this web article (Creative Commons July 1, 2016 Münster University of Applied Sciences. available at https://drownattack.com/, obtained on June 2 2020)

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.

Resolution

For this tutorial, we will be using the Nartac security tool. 

Visit (Copyright © 2020 Nartac Software. All Rights Reserved. available at https://www.nartac.com/Products/IISCrypto/Download, obtained on June 2 2020) and download the GUI version.


After running the file, make sure SSL v2 is unchecked on both server and client protocols side.
Reboot server.
Test with active diagnostics again

Please note, the checkboxes can be checked and unchecked, even when greyed out. 

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.