We use cookies.This website uses essential cookies to operate core features. With your consent, we also use analytics cookies to understand traffic and improve the service. For more details, see our .
Was this tool helpful to use?
Your feedback helps us make it better
Scan a specified domain for the SSL FREAK vulnerability (CVE-2015-0204) and assess TLS/SSL security configuration risks.
FREAK: submits host and selected TLS port to testssl.sh and shows its finding, reported version and severity. Missing/timeout is unknown; OK means no issue reported for this check, not a secure website. IP/SNI/edge variation may change results. Scan authorized targets only. Reference
Please enter a domain or IP address to start detection
Overview
Understand what the tool solves, how it works, and the boundaries of its data.
FREAK is associated with forcing an RSA connection down to weak export-grade RSA key exchange. NIST's CVE-2015-0204 record describes a flaw in OpenSSL client code that could allow a remote server to trigger an RSA-to-EXPORT_RSA downgrade. Client exposure and a server's offered cipher suites are related parts of the historical attack story, but they are not the same question.
This checker is a targeted test for the FREAK finding against a host. Its report can include the resolved address, port, status, finding text, and a related vulnerability identifier when returned. A clean status means the focused check did not report its finding; it is not a general assessment of every TLS setting or of client software connecting to the service.
Read the status together with the finding description and the target address shown in the result. If an alert appears, identify the TLS service, proxy, or load balancer serving that address and confirm the relevant software and configuration with its maintainer. If no FREAK finding is returned, record that outcome only for the endpoint actually checked.
Guide
Follow the workflow and verify inputs and outputs with practical examples.
Provide a domain name or IP address for a system you own or are authorized to assess. Confirm that it points to the intended public TLS service.
Wait for the report, then note the resolved address, port, status, and finding description. A vulnerability identifier may appear when the check returns one.
Ask the service owner to verify the TLS implementation and configuration at the reported endpoint. Apply the vendor's applicable remediation, then repeat a focused check after the change.
A domain may resolve to more than one address or be served through a proxy or load balancer. Compare the address shown in the report with the production path you need to assess, and arrange separate authorized checks where coverage is required.
Use cases
See how the tool fits into real work and everyday tasks.
A service maintainer can run the specific FREAK check after changing a test endpoint, then attach the reported target and finding to the change review.
A security team can use the returned host and finding details to identify which externally served endpoint needs review by its TLS owner.
Q&A
Find concise answers to common questions and confusing cases.
NIST scopes this CVE to OpenSSL client code. Server support for export-grade RSA could be part of the attack conditions, so do not treat a server-side signal as a complete answer about client exposure.
No. The report shows identifiers only when the returned finding contains them. Read the status and finding text without inferring an identifier that is not present.
No. It only means this focused check did not report the FREAK finding for the tested endpoint. It does not evaluate all protocol, certificate, cipher, or client risks.
Notes
Review scope, result limitations, and important precautions before use.
This page checks for a specific FREAK-related signal; it is not a complete TLS audit. A clean response does not establish that the service is secure against other weaknesses or that every address behind a domain was checked. The visible port field is not currently included in this tool's FREAK request, so do not rely on changing it to assess a nonstandard port. Use an authorized process that explicitly supports the required port. Only test systems you own or have clear permission to assess.
Related
Discover related tools, collections, and available API capabilities.