Search

Insufficient Encryption (The Most by far)

  • Http not Https (High if found on a web server)
    • Allows for Man in the middle (MITM) attack and intercept traffic
  • The more common ones (they require MITM)(Put them on a table and tick for each IP):
    • SSL 2/3
    • TLS 1.0
    • SWEET32
    • RC4 (Bar Mitzvah)
    • Self-Signed Certificate