S4E just found a high top 10 tcp port service scan
medium·SSL Controls·Updated Dec 17, 2024

SSL Crime Vulnerability Scanner

Check your SSL/TLS configuration for CRIME vulnerability. Ensure your server does not use HTTP compression for encrypted sessions.

Est. Time~20 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
9
Times Used
by S4E users
8
Assets Scanned
domains & IPs
8
Vulnerabilities Found
confirmed findings
Detail

What is SSL CRIME Vulnerability?

SSL CRIME (Compression Ratio Info-leak Made Easy) is a vulnerability that exploits HTTP compression in SSL/TLS connections. By analyzing changes in the size of encrypted data packets during compression, an attacker can infer sensitive information such as session cookies or authentication tokens.

The attack involves sending specially crafted requests to a target server and observing the size of the compressed responses. Through multiple iterations, an attacker can deduce sensitive data by exploiting the predictable nature of compression algorithms. CRIME primarily affects SSL/TLS configurations that support HTTP compression, such as DEFLATE or gzip.

To protect against this vulnerability, HTTP compression should be disabled for encrypted sessions. Modern browsers and servers have largely mitigated CRIME by default, but outdated systems remain susceptible.

Solution Advice

To prevent CRIME attacks, disable HTTP compression for SSL/TLS connections. Verify that your server configuration does not allow compression algorithms like gzip or DEFLATE in secure communications.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.