Tools

OpenSSL: Drown attack

This article provides information about OpenSSL vulnerability discussed in the following links: https://access.redhat.com/security/cve/cve-2016-0800 https://arstechnica.com/information-technology/2016/03/more-than-13-million-https-websites-imperiled-by-new-decryption-attack/

First published date

11/29/2018 10:52 PM

Last published date

4/24/2019 2:45 PM

Overview

This article provides information about OpenSSL vulnerability discussed in the following links:


It applies to these environments:

  • Windows Vista/7/8, Server 2008/2012 - C:\ProgramData\RhinoSoft\Serv-U (Folder is Hidden in Windows by default)
  • Windows 2000/XP, Server 2000/2003 - C:\Program Files\RhinoSoft\Serv-U

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Resolution

Serv-U is not vulnerable to drown attack if SSLv2 is disabled in Serv-U (it is disabled by default). If the SSLv2 is not enabled, Serv-U is fine and not vulnerable to drown attack.


Disclaimer: Please note, any content posted here is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.