S4E just found a high top 10 tcp port service scan
medium·SSL Controls·Updated Dec 17, 2024

SSL Freak Vulnerability Scanner

Check your SSL/TLS configuration for FREAK vulnerability. Ensure your server does not support export-grade RSA keys.

Est. Time~20 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
79
Times Used
by S4E users
15
Assets Scanned
domains & IPs
16
Vulnerabilities Found
confirmed findings
Detail

What is SSL FREAK Vulnerability?

SSL FREAK (Factoring Attack on RSA-EXPORT Keys) is a vulnerability that exploits weak export-grade RSA keys in SSL/TLS configurations. These export keys, originally introduced due to outdated cryptographic export restrictions, are intentionally weaker (512 bits) and can be cracked by attackers to decrypt secure communications.

The FREAK attack occurs when a server accepts export-grade RSA keys and an attacker forces a client-server connection to use these weaker keys. Once the weak keys are factored, the attacker can decrypt sensitive data, such as session cookies or login credentials, sent over the connection.

Mitigating FREAK involves disabling support for export-grade ciphers on servers, ensuring clients reject weak keys, and upgrading SSL/TLS configurations to prioritize modern, secure encryption standards.

Solution Advice

To prevent FREAK attacks, disable export-grade RSA cipher suites on your server, upgrade to secure encryption protocols, and ensure clients reject insecure keys.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.