Reporting SSL Issues


Hi All,

Long time lurker, first time poster.

I'm Smittix, a fellow pentester, pleased to meet you all.

So... I'm just hoping to get some idea/tips on how others handle this situation. Lately I have been performing very large penetration tests with hundreds of hosts. I was just wondering how other people go about reporting SSL Issues?


For example, I had over 3000 separate issues on one pentest which was time consuming getting evidence for each issue. I've been searching for some kind of parser but no cigar unfortunately.

Ideally I would like something to be able to parse multiple SSLScan (or other utility) and export the results into csv grouped by the issue for example -

  • Poodle
  • LogJam
  • RC4
  • SSL3 & 2
  • Expired Certs

etc etc.


Does anyone know if anyone has done anything like this before before I try and recreate the wheel?


Any help would be greatly appreciated as this could cut my reporting time down significantly.


Thanks in advance people.


