RE: Nessus 1.3.4 NetBIOS tests.
"Zimin, Alex" <[email protected]>
| Newsgroups | gmane.comp.security.nessus.devel |
|---|---|
| Message-ID | <48FB76BF31A47C4B9893827DEDF7DF2A0125AF@sacexch01.lan.towerrecords.com> |
Few corrections: Just verified it's actually Nessus 1.3.4 (it still says 1.3.3 on a website) I had tested it with NessusWX 1.4.2 and with the Nessus GUI client against Win2KPro + SP3 box. Nessusd is running on RedHat 8.0 system. Alex. > I just had installed development version of Nessus (1.3.3) > > Comparing Nessus 1.2.7 and 1.3.3 reports I had found that > 1.3.3 does not report NetBIOS vulnerabilities on port > 139/tcp. Here are some vulnerabilities which are missing by > 1.3.3: 1. Null session 2. Enumerating local/domain users 3. > Showing domain/host SIDs 4. Disabled user accounts check And > other on port 139/tcp > > I had used version 1.3.3 from the www, will try one from cvs > in a few minutes.