Skip to content

ROBOT false negative #504

@weddige

Description

@weddige

Describe the bug
The lines 187-201 in _robot_tester.py (https://github.com/nabla-c0d3/sslyze/blob/release/sslyze/plugins/robot/_robot_tester.py#L186) are never executed and lead to false negatives when scanning servers for the ROBOT vulnerability.

To Reproduce
At the moment, I can't reveal the vulnerable server. However, I encountered it in the wild.

Expected behavior
A vulnerable server should never report NOT_VULNERABLE_NO_ORACLE.

Python environment (please complete the following information):

  • OS: Windows 10
  • Python version: 3.8

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions