Plug-in 10430 false positive using a domain administrator account
Filipe Custódio <[email protected]>
| Newsgroups | gmane.comp.security.nessus.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, Excuse me and please correct me if this is the wrong forum. I have been having some difficulties with Nessus plug-in 10430 (SMB Registry : permissions of keys that can lead to admin) When configured with a domain administrator account, Nessus reports this vulnerability on all the servers in the network, regarding the keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx These are configured to "Full Control" only for the Administrators and System group. I would like to help debugging this false positive, if someone could point me to the source or documentation of the NASL2 function "registry_key_writeable_by_non_admin" used in the plug-in. Best regards, Filipe Custódio Novabase Consulting