RapydBlok 2021 – In Review

“We really appreciate all your support in 2021 and look forward to offering even more value in future, all the best wishes for 2022” – Gordon @RapydBlok

We have had the pleasure of working with some amazing people that have supported us wholeheartedly. We can only hope to build stronger from this amazing baseline.

Some Stats for 2021

  • RapydBlok INSPECT Unique Hosts Scanned: 751
  • RapydBlok DISCOVER Unique Domains Scanned: 59

New Product Released in 2021 – you know it – RapydBlok DISCOVER

DISCOVER is a product released by RapydBlok.com, a free webapp, with commercial API, that can discover and report on SubDomains to assist with Attack Surface Management (ASM).

Follow us on Twitter | Facebook | LinkedIN

New Product Release – RapydBlok DISCOVER

RapydBlok is extremely proud to announce a new product called ‘RapydBlok DISCOVER’

{After rigorous testing, contemplation, planning and coffee…. the team have released a great product that can hopefully assist many to discover & secure their attack surface}

What is RapydBlok DISCOVER?

DISCOVER is a product released by RapydBlok.com, a free webapp, with commercial API, that can discover and report on SubDomains to assist with Attack Surface Management (ASM).

How can Subdomain Discovery help my business or organization?

  • Discover all SubDomains.
  • SubDomain Asset Identification.
  • SubDomain Attack Surface Mapping.
  • Find Hidden or Forgotten SubDomains.
  • Find valid (resolvable) subdomains via SubDomain Enumeration.

[Run a SCAN:] discover.rapydblok.com

What information is supplied?

  • Active SubDomains: List of active SubDomains found.
  • All SubDomains: List of all SubDomains found, sorted and duplicates removed.
  • SubDomain RAW data: Json output inline, via download and email.
  • Count: Count of Active/All SubDomains.

#API

  • RapydBlok DISCOVER also offers an Authorized/Premium API for SubDomain enumeration. Inquire via email.

 

Follow us on Twitter | Facebook | LinkedIN

January ’21 updates released for RapydBlok INSPECT

??? ??????? released for ????????? ??????? – [Jan 2021]

[???? ?? ??????? ??????? ????? ????????]

1: [???????] – Results page ‘Issued To’ section. Changed name of ‘Issuer:’ to ‘Common Name’ and changed ‘Organization’ data to be more accurate.
2: [??? ?????] – Email not sending latest updated scan results, when url was previously scanned.
3: [??? ?????] – Email intermittently sent with a new url scan.
4: [???????] – Updated testssl scanning engine to the latest version, with bug fixes & improvements, see https://github.com/drwetter/testssl.sh

[????] – https://inspect.rapydblok.com

Follow us on Twitter | Facebook | LinkedIN

 

SSL Scan information page

 

RapydBlok – 2020 in Review

“HTTPS & SSL doesn’t mean “trust this.” It means “this is private.” You may be having a private conversation with Satan.” – Scott Hanselman

Best wishes for the festive season from the RapydBlok team. 2020 hasn’t been the easiest year for most, but with all it’s challenges we have persevered. Well wishes for 2021 are in order.”

RapydBlok achieved some milestones this year including;

  • A new product, INSPECT Web App, that can inspect website https security – inspect.rapydblok.com
  • Fixed some bugs, added multi-threading for SCANS and improved on reporting and email delivery of results.
  • Introduced #ScanFriday, to encourage regular security scanning.
  • Gordon emigrated from Cape Town to Munich.

??? ??? ??????? ???? ?? – Most websites have SSL certificates to secure web traffic, ??????? will review the SSL certificate & web server configuration for any related issues and display the full results.

Summary of the common issues found during SSL scans;

It’s not secure enough to just install an SSL certificate, correct configuration is key!

  1. ???? ?????????? ?? ??? ??????????? ?? ??? ?????? ?? ?????? ???/???, it needs to be configured correctly on the web server & some web admins are unaware of this.
  2. ??????????? ????????? ??? ??????????, mainly TLS 1 & TLS1.1 are offered in configuration but actually depreciated. Min of TLS v1.2 and TLS 1.3 should be offered.
  3. ????? ???????? ?? ??? ???????, for certificates often requires a review and Mozilla has some good recommendations on ciphers & client support.
  4. ???????????????, if old or obsolete Ciphers and Protocols are used, it can generally lead to vulnerabilities being available for that host.
  5. ???????? ???? TLS 1.3 ????, doesn’t allow for all web clients to connect, especially older ones but most importantly Internet Explorer users cant connect.

Shoutout to the testssl.sh team, without them there wouldn’t be an INSPECT product

Keep watching this space in 2021, the RapydBlok team will keep pushing the limits and do some great releases.

 

All the best, Fröhliche Weihnachten & Happy Holidays

Gordon Bishop – co-founder

August updates released for RapydBlok INSPECT

The RapydBlok team have been testing and finding ways to improve on the initial release, the below are updates released for RapydBlok INSPECT in August 2020;

[Scan to inspect website https security]

1: [New] – New option to receive results via email, email used once-off and not stored.
2: [Improve] – Option added to download full html report.
3: [Improve] – Multi-threading added for scans to improve scanning times.
4: [Bug Fixes] – Two minor bugs resolved.

[SCAN]https://inspect.rapydblok.com

5: [Listed] – RapydBlok INSPECT has been listed on https://github.com/drwetter/testssl.sh as an ‘External/related project’

RapydBlok INSPECT main page

[TAN-TextAdMobile_Prod]

RapydBlok INSPECT Web App is Live

RapydBlok is proud to announce that the ‘RapydBlok INSPECT’ product is finished and in production!

After many cups of coffee, weeks of planning, development & fine tuning, the team have produced a free web app to audit TLS/SSL configurations.

What is RapydBlok INSPECT?

INSPECT is a free Web application that can audit & report on TLS/SSL ciphers & protocols for configuration issues, cryptographic flaws, vulnerabilities, HTTP security headers. INSPECT is built upon the foundations of the open source, testssl.sh toolset.

How can that help me?

– Most websites have SSL certificates to secure web traffic, INSPECT will review your SSL certificate and web server configuration for any related issues and display the full results.

Run a SCAN: inspect.rapydblok.com

What are the common issues found so far?

1: Just installing an SSL certificate is not enough to secure TLS/SSL, it needs to be configured correctly on the web server & some web admins are unaware of this.

2: Depreciated Protocols are configured, mainly TLS 1 & TLS1.1 are offered in configuration but actually depreciated. Min of TLS v1.2 and TLS 1.3 should be offered.

3: Using obsolete or old ciphers, for certificates often requires a review and Mozilla has some good recommendations on ciphers & client support.

4: Vulnerabilities, if old or obsolete Ciphers and Protocols are used, it can generally lead to vulnerabilities being available for that host.

5: Securing only with TLS1.3, doesn’t allow for all web clients to connect, especially older ones but most importantly Internet Explorer users cant connect.

6: Host scanned multiple times, hosts are being scanned around 3 times on average, as configuration changes are done in small stages, and confirmed correct via re-scans.

 

Results page screenshots;

 

RapydBlok INSPECT Audit SSL

RapydBlok INSPECT Audit SSL

RapydBlok INSPECT Audit SSL

RapydBlok INSPECT Audit SSL

RapydBlok Inspect product is in active development

RapydBlok InspectRapydBlok Inspect logo

 

RapydBlok.com is current building a new product called “Inspect”. RapydBlok Inspect will be a free web application (webapp) that will be able to audit and report on hosts TLS/SSL ciphers and protocols for configuration issues, cryptographic flaws, vulnerabilities, HTTP security headers and more.

We will be building this service upon a solid foundation, using the open source testssl.sh toolset (https://testssl.sh) from Dr Wetter and team.

The RapydBlok Inspect product will not only offer a webapp but also an Application Programming Interface (API), which will allow 3rd party integrations.

Keep watching this space..