Re: Why is my printer not excluded from the scan?
jellybambam <[email protected]>
| Newsgroups | gmane.comp.security.nessus.general |
|---|---|
| Message-ID | <[email protected]> |
Thanks for all replies so far, the printer is a default unconfigured HP Officejet 6310, not so much an industrial printer but a 3 in 1 lightweight used as a network printer. Maybe this is what the problem is. >> I am using Nessus 3.2.0 with Client 3.0.0 under XP. I have created a >> policy and have not enabled the 'Scan Network Printers' however on my >> test network the printer is scanned and it shoots out 2 sheets during >> the scan. This is also the same under Linux. >Are the pages blank? If yes, try using the SYN scanner instead of the >TCP scanner. If this works, I'm afraid I cannot propose a better >solution. No not blank, 'Get / Http /1.0' and 'Help' on the other, so I guess that the remote web service on 80 is being probed there. The web service on 8089 appears to be a printer schema. >> I am leading up to scanning an estate of a few thousand devices, but >> would like to guarantee excluding printer scanning as much as >> practically possible - is there anyway I can investigate further why >> my printer was scanned? >The nessus report you got on this IP may help us. HTML attached >> I may be able to exclude the printer IP addresses but they are not >> neatly presented within the IP scope, however I could use nmap -O and >> parse the results to get the majority of printer IPs. >Using nmap against printers is not a good idea. Appreciated, but it's quite happy to be scanned with nmap. >Does this printer answers to SNMP, by the way? Yes, I've not yet changed from the default read community string. Thanks again. _______________________________________________ Nessus mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus
printer results.html
(text/html, 24.2 KB)
<html>
<style type="text/css">
<!--
BODY {BACKGROUND-COLOR: #ffffff }
A { TEXT-DECORATION: none }
A {COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif }
A:link {COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif; TEXT-DECORATION:underline }
A:active {COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif; TEXT-DECORATION:underline }
P {COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif; FONT-SIZE:8pt}
TD { COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif; FONT-SIZE:8pt }
TR { COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif; FONT-SIZE:8pt }
!-->
</style>
<center><img src="file:///C:\Program Files\Tenable\Nessus\NessusHTMLHeader.png" border=0>
<table width="755">
<tr>
<td>
<table width="100%">
<tr bgcolor="397AB2">
<td align=left><b><font color="#FFFFFF" size=+2>List of hosts</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td><center><table width=100%>
<a name="toc"></a>
<tr><td width=60%%><a href="#toc_192.168.0.109">192.168.0.109</td><td width=40%%><font color=red>High Severity problem(s) found</font></td></tr>
</table></center></table>
<a name="toc_192.168.0.109"></a><p align="right"><a href="#toc">[^] Back</a>
<center><table width="100%" bgcolor="#EEF2F3">
<tr bgcolor="#CC0000">
<td align=left colspan=2><b><font color="#FFFFFF" size=+2>192.168.0.109</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td>
<br><br>
<table width=100%>
<tr><td><u>Scan time :</u><br><table width=80%>
<tr><td align=right>Start time : </td><td align=right>Thu Apr 24 06:32:02 2008</td></tr>
<tr><td align=right>End time : </td><td align=right>Thu Apr 24 06:35:48 2008</td></tr></table></tr></td>
<tr><td><u>Number of vulnerabilities :</u><br><table width=80%>
<tr><td align=right>Open ports : </td><td align=right>14</td></tr>
<tr><td align=right>Low : </td><td align=right>16</td></tr>
<tr><td align=right>Medium : </td><td align=right>3</td></tr>
<tr><td align=right>High : </td><td align=right>2</td></tr></table></tr></td>
<tr><td colspan=2><hr></td></tr>
<tr><td><u>Information about the remote host :</u><br><br><table width=100%>
<tr><td align=right>Operating system : </td><td align=right>HP JetDirect Printer</td></tr>
<tr><td align=right>NetBIOS name : </td><td align=right>HP0016354CDF35</td></tr>
<tr><td align=right>DNS name : </td><td align=right>HP0016354CDF35.</td></tr></table></tr></td>
</table>
</tr>
</table></center></html><a name="192.168.0.109_netbios-ns (137/udp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port netbios-ns (137/udp)</font></b></td>
</tr>
</table><html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">Using NetBIOS to retrieve information from a Windows host</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br><b>Synopsis :</b><br><br>It is possible to obtain the network name of the remote host.<br><br><b>Description :</b><br><br>The remote host listens on udp port 137 and replies to NetBIOS nbtscan<br>requests. By sending a wildcard request it is possible to obtain the<br>name of the remote system and the name of its domain. <br><br><b>Risk factor :</b><br><br>None<br><br><b>Plugin output :</b><br><br>The following 3 NetBIOS names have been gathered :<br><br> HP0016354CDF35 = Computer name<br> HP0016354CDF35 = File Server Service<br> PRINTER = Computer name<br><br>The remote host has the following MAC address on its adapter :<br> 00:16:35:4c:df:35<br>CVE : CVE-1999-0621, CVE-1999-0621<br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10150">10150</a>
</td>
</tr>
</table>
<a name="192.168.0.109_ismserver (9500/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port ismserver (9500/tcp)</font></b></td>
</tr>
</table><a name="192.168.0.109_sidewinder-game-voice (9110/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port sidewinder-game-voice (9110/tcp)</font></b></td>
</tr>
</table><a name="192.168.0.109_general/udp"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port general/udp</font></b></td>
</tr>
</table><html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">Traceroute</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
For your information, here is the traceroute from 192.168.0.106 to 192.168.0.109 : <br>192.168.0.106<br>192.168.0.109<br><br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10287">10287</a>
</td>
</tr>
</table>
<a name="192.168.0.109_snmp (161/udp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port snmp (161/udp)</font></b></td>
</tr>
</table><html>
<table width="100%">
<tr bgcolor="#FDBE00">
<td align=left colspan=2><b><font color="#FFFFFF">Obtain system info type via SNMP</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br><b>Synopsis :</b><br><br>The System Information of the remote host can be obtained via SNMP.<br><br><b>Description :</b><br><br>It is possible to obtain the system information about the remote<br>host by sending SNMP requests with the OID 1.3.6.1.2.1.1.1.<br><br>An attacker may use this information to gain more knowledge about<br>the target host.<br><br><b>Solution :</b> <br><br>Disable the SNMP service on the remote host if you do not use it,<br>or filter incoming UDP packets going to this port.<br><br><b>Risk factor :</b> <br><br>Medium / CVSS Base Score : 5.0<br>(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)<br><br><b>Plugin output :</b><br><br>System information :<br> sysDescr : HP ETHERNET MULTI-ENVIRONMENT<br> sysObjectID : 1.3.6.1.4.1.11.2.3.9.1<br> sysUptime : 0d 0h 1m 24s<br> sysContact : <br> sysName : printer<br> sysLocation : <br> sysServices : 72<br><br><br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10800">10800</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#FDBE00">
<td align=left colspan=2><b><font color="#FFFFFF">Obtain network interfaces list via SNMP</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br><b>Synopsis :</b><br><br>The list of network interfaces cards of the remote host can be obtained via<br>SNMP.<br><br><b>Description :</b><br><br>It is possible to obtain the list of the network interfaces installed<br>on the remote host by sending SNMP requests with the OID 1.3.6.1.2.1.2.1.0<br><br>An attacker may use this information to gain more knowledge about<br>the target host.<br><br><b>Solution :</b> <br><br>Disable the SNMP service on the remote host if you do not use it,<br>or filter incoming UDP packets going to this port.<br><br><b>Risk factor :</b> <br><br>Medium / CVSS Base Score : 5.0<br>(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)<br><br><b>Plugin output :</b><br><br>Interface 1 information :<br> ifIndex : 2<br> ifDescr : Eth0<br> ifPhysAddress : 0016354cdf35<br><br>Interface 2 information :<br> ifIndex : Eth0<br> ifDescr : <br> ifPhysAddress : <br><br><br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10551">10551</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#CC0000">
<td align=left colspan=2><b><font color="#FFFFFF">Discover HP JetDirect EWS Password via SNMP</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br><b>Synopsis :</b><br><br>The administrative password of the remote HP JetDirect printer can be obtained<br>using SNMP.<br><br><br><b>Description :</b><br><br>It is possible to obtain the password of the remote HP JetDirect<br>web server by sending SNMP requests.<br><br>An attacker may use this information to gain administrative access<br>to the remote printer.<br><br><b>Solution :</b> <br><br>Disable the SNMP service on the remote host if you do not use it,<br>or filter incoming UDP packets going to this port.<br><br><a href="http://www.securityfocus.com/archive/1/313714/2003-03-01/2003-03-07/0">http://www.securityfocus.com/archive/1/313714/2003-03-01/2003-03-07/0</a><br><br><b>Risk factor :</b> <br><br>High<br><br><b>Plugin output :</b><br><br>Remote printer password is : <br>CVE : CVE-2002-1048<br>BID : 5331, 7001<br></a><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=11317">11317</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#CC0000">
<td align=left colspan=2><b><font color="#FFFFFF">Default community names of the SNMP Agent</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br><b>Synopsis :</b><br><br>The community name of the remote SNMP server can be guessed.<br><br><b>Description :</b><br><br>It is possible to obtain the default community names of the remote<br>SNMP server.<br><br>An attacker may use this information to gain more knowledge about<br>the remote host, or to change the configuration of the remote<br>system (if the default community allow such modifications).<br><br><b>Solution :</b> <br><br>Disable the SNMP service on the remote host if you do not use it,<br>filter incoming UDP packets going to this port, or change the <br>default community string.<br><br><b>Risk factor :</b> <br><br>High / CVSS Base Score : 7.5<br>(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)<br><br><b>Plugin output :</b><br><br>The remote SNMP server replies to the following default community<br>strings :<br><br>private<br>public<br><br>CVE : CVE-1999-0186, CVE-1999-0254, CVE-1999-0516, CVE-1999-0517, CVE-2004-0311, CVE-2004-1474<br>BID : 11237, 10576, 177, 2112, 6825, 7081, 7212, 7317, 9681, 986<br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10264">10264</a>
</td>
</tr>
</table>
<a name="192.168.0.109_pdl-datastream (9100/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port pdl-datastream (9100/tcp)</font></b></td>
</tr>
</table><a name="192.168.0.109_unknown (7435/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port unknown (7435/tcp)</font></b></td>
</tr>
</table><html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">Service detection</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
The service closed the connection without sending any data<br>It might be protected by some TCP wrapper<br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=22964">22964</a>
</td>
</tr>
</table>
<a name="192.168.0.109_general/tcp"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port general/tcp</font></b></td>
</tr>
</table><html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">Host FQDN</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
192.168.0.109 resolves as HP0016354CDF35.<br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=12053">12053</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">OS Identification</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br>Remote operating system : HP JetDirect Printer<br>Confidence Level : 100<br>Method : SNMP<br><br>Not all fingerprints could give a match - please email the following to [email protected] :<br>HTTP:!:Server: Virata-EmWeb/R6_0_1<br>SinFP:!:<br> P1:B11013:F0x12:W17520:O0204ffff:M1460:<br> P2:B11013:F0x12:W17376:O0204ffff01030300010104020101080affffffff44454144:M1460:<br> P3:B11020:F0x04:W0:O0:M0<br> P4:3205_7_p=9290R<br>SNMP:HP ETHERNET MULTI-ENVIRONMENT<br><br> <br>The remote host is running HP JetDirect Printer<br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=11936">11936</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">Information about the scan</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
Information about this scan : <br><br>Nessus version : 3.2.0<br>Plugin feed version : 200804231534<br>Type of plugin feed : Registered (7 days delay)<br>Scanner IP : 192.168.0.106<br>Port scanner(s) : synscan <br>Port range : 1-65535<br>Thorough tests : no<br>Experimental tests : no<br>Paranoia level : 1<br>Report Verbosity : 1<br>Safe checks : yes<br>Optimize the test : yes<br>Max hosts : 10<br>Max checks : 5<br>Recv timeout : 5<br>Scan Start Date : 2008/4/24 6:32<br>Scan duration : 223 sec<br><br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=19506">19506</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">Check open ports</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
The following ports were open at the beginning of the scan but are now closed:<br><br>Port 7435 was detected as being open but is now closed<br>Port 9101 was detected as being open but is now closed<br>Port 9102 was detected as being open but is now closed<br><br>This might be an availability problem related which might be due to the following reasons :<br><br>- The remote host is now down, either because a user turned it off during the scan<br>- A network outage has been experienced during the scan, and the remote <br>network cannot be reached from the Vulnerability Scanner any more<br>- This Vulnerability Scanner has been blacklisted by the system administrator<br>or by automatic intrusion detection/prevention systems which have detected the <br>vulnerability assessment.<br><br>In any case, the audit of the remote host might be incomplete and may need to<br>be done again<br><br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10919">10919</a>
</td>
</tr>
</table>
<a name="192.168.0.109_unknown (9290/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port unknown (9290/tcp)</font></b></td>
</tr>
</table><a name="192.168.0.109_unknown (6839/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port unknown (6839/tcp)</font></b></td>
</tr>
</table><html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">Service detection</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
The service closed the connection without sending any data<br>It might be protected by some TCP wrapper<br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=22964">22964</a>
</td>
</tr>
</table>
<a name="192.168.0.109_http (80/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port http (80/tcp)</font></b></td>
</tr>
</table><html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">Service detection</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
A web server is running on this port.<br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=22964">22964</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">HTTP Server type and version</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br><b>Synopsis :</b><br><br>A web server is running on the remote host.<br><br><b>Description :</b><br><br>This plugin attempts to determine the type and the version of<br>the remote web server.<br><br><b>Risk factor :</b> <br><br>None<br><br><b>Plugin output :</b><br><br>The remote web server type is :<br><br>Virata-EmWeb/R6_0_1<br><br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10107">10107</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">HyperText Transfer Protocol Information</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br><b>Synopsis :</b><br><br>Some information about the remote HTTP configuration can be extracted. <br><br><b>Description :</b><br><br>This test gives some information about the remote HTTP protocol - the<br>version used, whether HTTP Keep-Alive and HTTP pipelining are enabled,<br>etc... <br><br>This test is informational only and does not denote any security<br>problem<br><br><b>Solution :</b><br><br>None.<br><br><b>Risk factor :</b><br><br>None<br><br><b>Plugin output :</b><br><br>Protocol version : HTTP/1.1<br>SSL : no<br>Pipelining : yes<br>Keep-Alive : no<br>Options allowed : (Not implemented)<br>Headers :<br><br> Server: Virata-EmWeb/R6_0_1<br> Transfer-Encoding: chunked<br> Content-Type: text/html<br> Cache-Control: no-cache<br> Pragma: no-cache<br> <br><br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=24260">24260</a>
</td>
</tr>
</table>
<a name="192.168.0.109_unknown (9220/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port unknown (9220/tcp)</font></b></td>
</tr>
</table><a name="192.168.0.109_bacula-fd (9102/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port bacula-fd (9102/tcp)</font></b></td>
</tr>
</table><a name="192.168.0.109_netbios-ssn (139/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port netbios-ssn (139/tcp)</font></b></td>
</tr>
</table><html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">SMB Detection</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
An SMB server is running on this port<br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=11011">11011</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">SMB NativeLanMan</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br><b>Synopsis :</b><br><br>It is possible to obtain information about the remote operating<br>system.<br><br><b>Description :</b><br><br>It is possible to get the remote operating system name and<br>version (Windows and/or Samba) by sending an authentication<br>request to port 139 or 445.<br><br><b>Risk factor :</b><br><br>None<br><br><b>Plugin output :</b><br><br>The remote Operating System is : [<br>The remote native lan manager is : <br>The remote SMB Domain Name is : <br><br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10785">10785</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">SMB log in</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br><b>Synopsis :</b><br><br>It is possible to log into the remote host.<br><br><b>Description :</b><br><br>The remote host is running one of the Microsoft Windows operating<br>systems. It was possible to log into it using one of the following<br>account :<br><br>- NULL session<br>- Guest account<br>- Given Credentials<br><br><b>See also :</b><br><br><a href="http://support.microsoft.com/support/kb/articles/Q143/4/74.ASP">http://support.microsoft.com/support/kb/articles/Q143/4/74.ASP</a><br><a href="http://support.microsoft.com/support/kb/articles/Q246/2/61.ASP">http://support.microsoft.com/support/kb/articles/Q246/2/61.ASP</a><br><br><b>Risk factor :</b><br><br>none<br><br><b>Plugin output :</b><br><br>- NULL sessions are enabled on the remote host<br>- Remote users are authenticated as 'Guest'<br><br>CVE : CVE-1999-0504, CVE-1999-0505, CVE-1999-0506, CVE-2000-0222, CVE-2002-1117, CVE-2005-3595<br>BID : 494, 990, 11199<br></a><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10394">10394</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#FDBE00">
<td align=left colspan=2><b><font color="#FFFFFF">SMB guest account for all users</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br><b>Synopsis :</b><br><br>It is possible to log into the remote host. <br><br><b>Description :</b><br><br>The remote host is running one of the Microsoft Windows operating<br>systems. It was possible to log into it as a guest user using a <br>random account.<br><br><br><b>Solution :</b><br><br>In the group policy change the setting for <br>'Network access: Sharing and security model for local accounts' from<br>'Guest only - local users authenticate as Guest' to<br>'Classic - local users authenticate as themselves'.<br><br><b>Risk factor :</b><br><br>Medium / CVSS Base Score : 5.0<br>(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)<br>CVE : CVE-1999-0505<br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=26919">26919</a>
</td>
</tr>
</table>
<html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">SMB NULL session</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
<br><b>Synopsis :</b><br><br>It is possible to log into the remote host. <br><br><b>Description :</b><br><br>The remote host is running one of the Microsoft Windows operating<br>systems. It was possible to log into it using a NULL session.<br><br>A NULL session (no login/password) allows to get information about<br>the remote host.<br><br><b>See also :</b><br><br><a href="http://support.microsoft.com/support/kb/articles/Q143/4/74.ASP">http://support.microsoft.com/support/kb/articles/Q143/4/74.ASP</a><br><a href="http://support.microsoft.com/support/kb/articles/Q246/2/61.ASP">http://support.microsoft.com/support/kb/articles/Q246/2/61.ASP</a><br><br><b>Risk factor :</b><br><br>None<br>CVE : CVE-2002-1117<br>BID : 494<br></a><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=26920">26920</a>
</td>
</tr>
</table>
<a name="192.168.0.109_bacula-dir (9101/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port bacula-dir (9101/tcp)</font></b></td>
</tr>
</table><a name="192.168.0.109_apache-administration-server (8089/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port apache-administration-server (8089/tcp)</font></b></td>
</tr>
</table><html>
<table width="100%">
<tr bgcolor="#397AB2">
<td align=left colspan=2><b><font color="#FFFFFF">Service detection</font></b></align></td>
</tr>
<tr bgcolor="#EEF2F3">
<td colspan=2>
A web server is running on this port.<br><br>
Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=22964">22964</a>
</td>
</tr>
</table>
</td></tr></table></center>
</html>