rippledj
(Joseph)
21
Sorry, I thought that NASL was using the openvas-scanner network functions under-the-hood. So, since the OP’s issue is described as :
vulnerarbility in the cipher suite also not detected.
The cause may be because NASL currently doesn’t pass a SNI in the Client Hello?
cfi
22
Yes, indeed. This was already explained / described back then in 2023 in the below linked posting.
Note that this is a huge and complex topic and not just about “Sending/passing SNI in the Client Hello and be done”.
1 Like