Deep SSL/TLS Vulnerability Test

This report provides a deep analysis of the SSL/TLS configuration of www.facebook.com. It checks for protocol support, cipher strength, and known vulnerabilities.

Scan Results

 Start 2026-05-29 11:20:35        -->> 157.240.254.35:443 (www.facebook.com) <<--

 Further IP addresses:   2a03:2880:f175:181:face:b00c:0:25de 
 rDNS (157.240.254.35):  edge-star-mini-shv-02-ord5.facebook.com.
 Service detected:       HTTP

 Testing for server implementation bugs 

 No bugs found.

 Testing HTTP header response @ "/" 

 HTTP Status Code             302 Found, redirecting to "https://www.facebook.com/login/?next=https%3A%2F%2Fwww.facebook.com%2F"
 HTTP clock skew              0 sec from localtime
 Strict Transport Security    180 days=15552000 s, just this domain, preload
 Public Key Pinning           --
 Server banner                (no "Server" line in header, interesting!)
 Application banner           --
 Cookie(s)                    1 issued: 1/1 secure, 1/1 HttpOnly -- maybe better try target URL of 30x
 Security headers             X-Frame-Options: DENY
                              X-Content-Type-Options: nosniff
                              Content-Security-Policy: default-src blob: 'self'
                                https://*.fbsbx.com *.facebook.com *.fbcdn.net
                                *.facebook.net *.whatsapp.com
                                *.whatsapp.net;script-src *.facebook.com
                                *.fbcdn.net *.facebook.net 127.0.0.1:*
                                'nonce-jugiTgl2' blob: 'self'
                                connect.facebook.net 'unsafe-eval'
                                https://accounts.google.com
                                https://*.google-analytics.com
                                *.google.com;style-src *.fbcdn.net data:
                                *.facebook.com 'unsafe-inline'
                                https://accounts.google.com
                                https://fonts.googleapis.com;connect-src
                                *.facebook.com facebook.com *.fbcdn.net
                                *.facebook.net wss://*.facebook.com:*
                                wss://*.whatsapp.com:* wss://*.fbcdn.net
                                attachment.fbsbx.com ws://localhost:* blob:
                                *.cdninstagram.com 'self' http://localhost:3103
                                wss://gateway.facebook.com
                                wss://edge-chat.facebook.com
                                wss://snaptu-d.facebook.com
                                wss://kaios-d.facebook.com/ v.whatsapp.net
                                *.fbsbx.com *.fb.com *.instagram.com
                                https://accounts.google.com
                                https://*.google-analytics.com;font-src data:
                                *.facebook.com *.fbcdn.net *.fbsbx.com
                                https://fonts.gstatic.com;img-src *.fbcdn.net
                                *.facebook.com data: https://*.fbsbx.com
                                facebook.com *.cdninstagram.com fbsbx.com
                                fbcdn.net connect.facebook.net blob:
                                android-webview-video-poster: *.whatsapp.net
                                *.fb.com *.oculuscdn.com *.tenor.co *.tenor.com
                                *.giphy.com https://trustly.one/
                                https://*.trustly.one/
                                https://paywithmybank.com/
                                https://*.paywithmybank.com/
                                https://www.googleadservices.com
                                https://googleads.g.doubleclick.net
                                https://*.google-analytics.com;media-src
                                *.cdninstagram.com blob: *.fbcdn.net
                                *.fbsbx.com www.facebook.com *.facebook.com
                                data: *.tenor.co *.tenor.com
                                https://*.giphy.com;child-src data: blob:
                                'self' https://*.fbsbx.com *.facebook.com
                                *.fbcdn.net;frame-src *.facebook.com
                                *.fbsbx.com fbsbx.com data: www.instagram.com
                                *.fbcdn.net accounts.meta.com
                                *.accounts.meta.com https://trustly.one/
                                https://*.trustly.one/
                                https://paywithmybank.com/
                                https://*.paywithmybank.com/
                                https://www.googleadservices.com
                                https://googleads.g.doubleclick.net
                                https://www.google.com
                                https://td.doubleclick.net *.google.com
                                *.doubleclick.net;manifest-src data: blob:
                                'self' https://*.fbsbx.com *.facebook.com
                                *.fbcdn.net;object-src data: blob: 'self'
                                https://*.fbsbx.com *.facebook.com
                                *.fbcdn.net;worker-src blob: *.facebook.com
                                data:;block-all-mixed-content;upgrade-insecure-requests;
                              Permissions-Policy: accelerometer=(),
                                attribution-reporting=(self), autoplay=(),
                                bluetooth=(), browsing-topics=(self),
                                camera=(self "https://www.fbsbx.com"),
                                ch-device-memory=(), ch-downlink=(), ch-dpr=(),
                                ch-ect=(), ch-rtt=(), ch-save-data=(),
                                ch-ua-arch=(), ch-ua-bitness=(),
                                ch-viewport-height=(), ch-viewport-width=(),
                                ch-width=(), clipboard-read=(self),
                                clipboard-write=(self), compute-pressure=(),
                                display-capture=(self), encrypted-media=(self),
                                fullscreen=(self), gamepad=*,
                                geolocation=(self), gyroscope=(), hid=(),
                                idle-detection=(), interest-cohort=(self),
                                keyboard-map=(), local-fonts=(),
                                magnetometer=(), microphone=(self), midi=(),
                                otp-credentials=(), payment=(),
                                picture-in-picture=(self),
                                private-state-token-issuance=(),
                                publickey-credentials-get=(self),
                                screen-wake-lock=(), serial=(),
                                shared-storage=(),
                                shared-storage-select-url=(),
                                private-state-token-redemption=(), usb=(),
                                unload=(self), window-management=(),
                                xr-spatial-tracking=(self);report-to="permissions_policy"
                              Cross-Origin-Opener-Policy: unsafe-none
                              Cross-Origin-Resource-Policy: same-origin
                              X-XSS-Protection: 0
                              Permissions-Policy: accelerometer=(),
                                attribution-reporting=(self), autoplay=(),
                                bluetooth=(), browsing-topics=(self),
                                camera=(self "https://www.fbsbx.com"),
                                ch-device-memory=(), ch-downlink=(), ch-dpr=(),
                                ch-ect=(), ch-rtt=(), ch-save-data=(),
                                ch-ua-arch=(), ch-ua-bitness=(),
                                ch-viewport-height=(), ch-viewport-width=(),
                                ch-width=(), clipboard-read=(self),
                                clipboard-write=(self), compute-pressure=(),
                                display-capture=(self), encrypted-media=(self),
                                fullscreen=(self), gamepad=*,
                                geolocation=(self), gyroscope=(), hid=(),
                                idle-detection=(), interest-cohort=(self),
                                keyboard-map=(), local-fonts=(),
                                magnetometer=(), microphone=(self), midi=(),
                                otp-credentials=(), payment=(),
                                picture-in-picture=(self),
                                private-state-token-issuance=(),
                                publickey-credentials-get=(self),
                                screen-wake-lock=(), serial=(),
                                shared-storage=(),
                                shared-storage-select-url=(),
                                private-state-token-redemption=(), usb=(),
                                unload=(self), window-management=(),
                                xr-spatial-tracking=(self);report-to="permissions_policy"
                              Cache-Control: private, no-cache, no-store,
                                must-revalidate
                              Pragma: no-cache
 Reverse Proxy banner         --


 Testing vulnerabilities 

 Secure Renegotiation (RFC 5746)           supported (OK)
 Secure Client-Initiated Renegotiation     not vulnerable (OK)
 CRIME, TLS (CVE-2012-4929)                not vulnerable (OK)
 BREACH (CVE-2013-3587)                    no gzip/deflate/compress/br HTTP compression (OK)  - only supplied "/" tested
 POODLE, SSL (CVE-2014-3566)               not vulnerable (OK)
 TLS_FALLBACK_SCSV (RFC 7507)              Downgrade attack prevention supported (OK)
 SWEET32 (CVE-2016-2183, CVE-2016-6329)    VULNERABLE, uses 64 bit block ciphers
 FREAK (CVE-2015-0204)                     not vulnerable (OK)
 DROWN (CVE-2016-0800, CVE-2016-0703)      not vulnerable on this host and port (OK)
                                           make sure you don't use this certificate elsewhere with SSLv2 enabled services, see
                                           https://search.censys.io/search?resource=hosts&virtual_hosts=INCLUDE&q=5DEA05558EE7C2A82D06B99060837E6DEE6FD3E95725035125C23DFDB0E3C078
 LOGJAM (CVE-2015-4000), experimental      not vulnerable (OK): no DH EXPORT ciphers, no DH key detected with <= TLS 1.2
 BEAST (CVE-2011-3389)                     TLS1: ECDHE-ECDSA-AES128-SHA
                                                 ECDHE-ECDSA-AES256-SHA
                                                 ECDHE-RSA-AES128-SHA
                                                 ECDHE-RSA-AES256-SHA
                                                 AES128-SHA AES256-SHA
                                                 ECDHE-ECDSA-DES-CBC3-SHA
                                                 ECDHE-RSA-DES-CBC3-SHA
                                                 DES-CBC3-SHA 
                                           VULNERABLE -- but also supports higher protocols  TLSv1.1 TLSv1.2 (likely mitigated)
 LUCKY13 (CVE-2013-0169), experimental     potentially VULNERABLE, uses obsolete cipher block chaining ciphers with TLS, see server prefs.
 Winshock (CVE-2014-6321), experimental    not vulnerable (OK)
 RC4 (CVE-2013-2566, CVE-2015-2808)        no RC4 ciphers detected (OK)


 Done 2026-05-29 11:21:23 [  58s] -->> 157.240.254.35:443 (www.facebook.com) <<--


About this Scan

This scan uses testssl.sh to check for:

  • Protocols: SSLv2, SSLv3, TLS 1.0, TLS 1.1, TLS 1.2, TLS 1.3
  • Vulnerabilities: Heartbleed, POODLE, FREAK, Logjam, DROWN, etc.
  • Cipher Suites: Weak ciphers, perfect forward secrecy (PFS) support.

Run Another Scan Recent Scans