Re: Why is my printer not excluded from the scan?

jellybambam <[email protected]>
Newsgroups gmane.comp.security.nessus.general
Message-ID <[email protected]>
Thanks for all replies so far,

the printer is a default unconfigured HP Officejet 6310, not so much
an industrial printer but a 3 in 1 lightweight used as a network
printer.  Maybe this is what the problem is.

>> I am using Nessus 3.2.0 with Client 3.0.0 under XP.  I have created a
>> policy and have not enabled the 'Scan Network Printers' however on my
>> test network the printer is scanned and it shoots out 2 sheets during
>> the scan.

This is also the same under Linux.

>Are the pages blank? If yes, try using the SYN scanner instead of the
>TCP scanner. If this works, I'm afraid I cannot propose a better
>solution.

No not blank,  'Get / Http /1.0' and 'Help' on the other, so I guess
that the remote web service on 80 is being probed there.  The web
service on 8089 appears to be a printer schema.


>> I am leading up to scanning an estate of a few thousand devices, but
>> would like to guarantee excluding printer scanning as much as
>> practically possible - is there anyway I can investigate further why
>> my printer was scanned?

>The nessus report you got on this IP may help us.

HTML attached

>> I may be able to exclude the printer IP addresses but they are not
>> neatly presented within the IP scope, however I could use nmap -O and
>> parse the results to get the majority of printer IPs.

>Using nmap against printers is not a good idea.

Appreciated, but it's quite happy to be scanned with nmap.

>Does this printer answers to SNMP, by the way?

Yes, I've not yet changed from the default read community string.

Thanks again.

_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus
printer results.html (text/html, 24.2 KB)
<html>
	<style type="text/css">
	<!--
	BODY {BACKGROUND-COLOR: #ffffff }
	A { TEXT-DECORATION: none }
	A {COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif }
				 A:link {COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif; TEXT-DECORATION:underline }
				 A:active {COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif; TEXT-DECORATION:underline }
	P {COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif;  FONT-SIZE:8pt}
	TD {	COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif; FONT-SIZE:8pt }
	TR {	COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif; FONT-SIZE:8pt }
	!-->
	</style>

<center><img src="file:///C:\Program Files\Tenable\Nessus\NessusHTMLHeader.png" border=0>
	<table width="755">
	<tr>
	<td>
<table width="100%">
	<tr bgcolor="397AB2">
	<td align=left><b><font color="#FFFFFF" size=+2>List of hosts</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
	<td><center><table width=100%>
<a name="toc"></a>
<tr><td width=60%%><a href="#toc_192.168.0.109">192.168.0.109</td><td width=40%%><font color=red>High Severity problem(s) found</font></td></tr>
</table></center></table>
<a name="toc_192.168.0.109"></a><p align="right"><a href="#toc">[^] Back</a>
<center><table width="100%" bgcolor="#EEF2F3">
		<tr bgcolor="#CC0000">
		<td align=left colspan=2><b><font color="#FFFFFF" size=+2>192.168.0.109</font></b></align></td>
		</tr>
		<tr bgcolor="#EEF2F3">
		<td>
		<br><br>
		<table width=100%>
		<tr><td><u>Scan time :</u><br><table width=80%>
			 <tr><td align=right>Start time : </td><td align=right>Thu Apr 24 06:32:02 2008</td></tr>
			 <tr><td align=right>End time : </td><td align=right>Thu Apr 24 06:35:48 2008</td></tr></table></tr></td>
	   <tr><td><u>Number of vulnerabilities :</u><br><table width=80%>
			 <tr><td align=right>Open ports : </td><td align=right>14</td></tr>
					<tr><td align=right>Low : </td><td align=right>16</td></tr>
				 <tr><td align=right>Medium : </td><td align=right>3</td></tr>
				   <tr><td align=right>High : </td><td align=right>2</td></tr></table></tr></td>
		<tr><td colspan=2><hr></td></tr>
	<tr><td><u>Information about the remote host :</u><br><br><table width=100%>
	   <tr><td align=right>Operating system : </td><td align=right>HP JetDirect Printer</td></tr>
		   <tr><td align=right>NetBIOS name : </td><td align=right>HP0016354CDF35</td></tr>
			   <tr><td align=right>DNS name : </td><td align=right>HP0016354CDF35.</td></tr></table></tr></td>
		</table>
		</tr>
			 </table></center></html><a name="192.168.0.109_netbios-ns (137/udp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port netbios-ns (137/udp)</font></b></td>
</tr>
	</table><html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">Using NetBIOS to retrieve information from a Windows host</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br><b>Synopsis :</b><br><br>It is possible to obtain the network name of the remote host.<br><br><b>Description :</b><br><br>The remote host listens on udp port 137 and replies to NetBIOS nbtscan<br>requests.  By sending a wildcard request it is possible to obtain the<br>name of the remote system and the name of its domain. <br><br><b>Risk factor :</b><br><br>None<br><br><b>Plugin output :</b><br><br>The following 3 NetBIOS names have been gathered :<br><br> HP0016354CDF35   = Computer name<br> HP0016354CDF35   = File Server Service<br> PRINTER          = Computer name<br><br>The remote host has the following MAC address on its adapter :<br>   00:16:35:4c:df:35<br>CVE : CVE-1999-0621, CVE-1999-0621<br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10150">10150</a>
    </td>
	</tr>
	</table>
<a name="192.168.0.109_ismserver (9500/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port ismserver (9500/tcp)</font></b></td>
</tr>
	</table><a name="192.168.0.109_sidewinder-game-voice (9110/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port sidewinder-game-voice (9110/tcp)</font></b></td>
</tr>
	</table><a name="192.168.0.109_general/udp"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port general/udp</font></b></td>
</tr>
	</table><html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">Traceroute</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    For your information, here is the traceroute from 192.168.0.106 to 192.168.0.109 : <br>192.168.0.106<br>192.168.0.109<br><br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10287">10287</a>
    </td>
	</tr>
	</table>
<a name="192.168.0.109_snmp (161/udp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port snmp (161/udp)</font></b></td>
</tr>
	</table><html>
	<table width="100%">
	<tr bgcolor="#FDBE00">
	<td align=left colspan=2><b><font color="#FFFFFF">Obtain system info type via SNMP</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br><b>Synopsis :</b><br><br>The System Information of the remote host can be obtained via SNMP.<br><br><b>Description :</b><br><br>It is possible to obtain the system information about the remote<br>host by sending SNMP requests with the OID 1.3.6.1.2.1.1.1.<br><br>An attacker may use this information to gain more knowledge about<br>the target host.<br><br><b>Solution :</b> <br><br>Disable the SNMP service on the remote host if you do not use it,<br>or filter incoming UDP packets going to this port.<br><br><b>Risk factor :</b> <br><br>Medium / CVSS Base Score : 5.0<br>(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)<br><br><b>Plugin output :</b><br><br>System information :<br> sysDescr     : HP ETHERNET MULTI-ENVIRONMENT<br> sysObjectID  : 1.3.6.1.4.1.11.2.3.9.1<br> sysUptime    : 0d 0h 1m 24s<br> sysContact   : <br> sysName      : printer<br> sysLocation  : <br> sysServices  : 72<br><br><br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10800">10800</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#FDBE00">
	<td align=left colspan=2><b><font color="#FFFFFF">Obtain network interfaces list via SNMP</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br><b>Synopsis :</b><br><br>The list of network interfaces cards of the remote host can be obtained via<br>SNMP.<br><br><b>Description :</b><br><br>It is possible to obtain the list of the network interfaces installed<br>on the remote host by sending SNMP requests with the OID 1.3.6.1.2.1.2.1.0<br><br>An attacker may use this information to gain more knowledge about<br>the target host.<br><br><b>Solution :</b> <br><br>Disable the SNMP service on the remote host if you do not use it,<br>or filter incoming UDP packets going to this port.<br><br><b>Risk factor :</b> <br><br>Medium / CVSS Base Score : 5.0<br>(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)<br><br><b>Plugin output :</b><br><br>Interface 1 information :<br> ifIndex       : 2<br> ifDescr       : Eth0<br> ifPhysAddress : 0016354cdf35<br><br>Interface 2 information :<br> ifIndex       : Eth0<br> ifDescr       : <br> ifPhysAddress : <br><br><br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10551">10551</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#CC0000">
	<td align=left colspan=2><b><font color="#FFFFFF">Discover HP JetDirect EWS Password via SNMP</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br><b>Synopsis :</b><br><br>The administrative password of the remote HP JetDirect printer can be obtained<br>using SNMP.<br><br><br><b>Description :</b><br><br>It is possible to obtain the password of the remote HP JetDirect<br>web server by sending SNMP requests.<br><br>An attacker may use this information to gain administrative access<br>to the remote printer.<br><br><b>Solution :</b> <br><br>Disable the SNMP service on the remote host if you do not use it,<br>or filter incoming UDP packets going to this port.<br><br><a href="http://www.securityfocus.com/archive/1/313714/2003-03-01/2003-03-07/0">http://www.securityfocus.com/archive/1/313714/2003-03-01/2003-03-07/0</a><br><br><b>Risk factor :</b> <br><br>High<br><br><b>Plugin output :</b><br><br>Remote printer password is : <br>CVE : CVE-2002-1048<br>BID : 5331, 7001<br></a><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=11317">11317</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#CC0000">
	<td align=left colspan=2><b><font color="#FFFFFF">Default community names of the SNMP Agent</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br><b>Synopsis :</b><br><br>The community name of the remote SNMP server can be guessed.<br><br><b>Description :</b><br><br>It is possible to obtain the default community names of the remote<br>SNMP server.<br><br>An attacker may use this information to gain more knowledge about<br>the remote host, or to change the configuration of the remote<br>system (if the default community allow such modifications).<br><br><b>Solution :</b> <br><br>Disable the SNMP service on the remote host if you do not use it,<br>filter incoming UDP packets going to this port, or change the <br>default community string.<br><br><b>Risk factor :</b> <br><br>High / CVSS Base Score : 7.5<br>(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)<br><br><b>Plugin output :</b><br><br>The remote SNMP server replies to the following default community<br>strings :<br><br>private<br>public<br><br>CVE : CVE-1999-0186, CVE-1999-0254, CVE-1999-0516, CVE-1999-0517, CVE-2004-0311, CVE-2004-1474<br>BID : 11237, 10576, 177, 2112, 6825, 7081, 7212, 7317, 9681, 986<br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10264">10264</a>
    </td>
	</tr>
	</table>
<a name="192.168.0.109_pdl-datastream (9100/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port pdl-datastream (9100/tcp)</font></b></td>
</tr>
	</table><a name="192.168.0.109_unknown (7435/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port unknown (7435/tcp)</font></b></td>
</tr>
	</table><html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">Service detection</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    The service closed the connection without sending any data<br>It might be protected by some TCP wrapper<br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=22964">22964</a>
    </td>
	</tr>
	</table>
<a name="192.168.0.109_general/tcp"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port general/tcp</font></b></td>
</tr>
	</table><html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">Host FQDN</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    192.168.0.109 resolves as HP0016354CDF35.<br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=12053">12053</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">OS Identification</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br>Remote operating system : HP JetDirect Printer<br>Confidence Level : 100<br>Method : SNMP<br><br>Not all fingerprints could give a match - please email the following to [email protected] :<br>HTTP:!:Server: Virata-EmWeb/R6_0_1<br>SinFP:!:<br>   P1:B11013:F0x12:W17520:O0204ffff:M1460:<br>   P2:B11013:F0x12:W17376:O0204ffff01030300010104020101080affffffff44454144:M1460:<br>   P3:B11020:F0x04:W0:O0:M0<br>   P4:3205_7_p=9290R<br>SNMP:HP ETHERNET MULTI-ENVIRONMENT<br><br> <br>The remote host is running HP JetDirect Printer<br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=11936">11936</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">Information about the scan</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    Information about this scan : <br><br>Nessus version : 3.2.0<br>Plugin feed version : 200804231534<br>Type of plugin feed : Registered (7 days delay)<br>Scanner IP : 192.168.0.106<br>Port scanner(s) : synscan <br>Port range : 1-65535<br>Thorough tests : no<br>Experimental tests : no<br>Paranoia level : 1<br>Report Verbosity : 1<br>Safe checks : yes<br>Optimize the test : yes<br>Max hosts : 10<br>Max checks : 5<br>Recv timeout : 5<br>Scan Start Date : 2008/4/24 6:32<br>Scan duration : 223 sec<br><br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=19506">19506</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">Check open ports</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    The following ports were open at the beginning of the scan but are now closed:<br><br>Port 7435 was detected as being open but is now closed<br>Port 9101 was detected as being open but is now closed<br>Port 9102 was detected as being open but is now closed<br><br>This might be an availability problem related which might be due to the following reasons :<br><br>- The remote host is now down, either because a user turned it off during the scan<br>- A network outage has been experienced during the scan, and the remote <br>network cannot be reached from the Vulnerability Scanner any more<br>- This Vulnerability Scanner has been blacklisted by the system administrator<br>or by automatic intrusion detection/prevention systems which have detected the <br>vulnerability assessment.<br><br>In any case, the audit of the remote host might be incomplete and may need to<br>be done again<br><br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10919">10919</a>
    </td>
	</tr>
	</table>
<a name="192.168.0.109_unknown (9290/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port unknown (9290/tcp)</font></b></td>
</tr>
	</table><a name="192.168.0.109_unknown (6839/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port unknown (6839/tcp)</font></b></td>
</tr>
	</table><html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">Service detection</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    The service closed the connection without sending any data<br>It might be protected by some TCP wrapper<br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=22964">22964</a>
    </td>
	</tr>
	</table>
<a name="192.168.0.109_http (80/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port http (80/tcp)</font></b></td>
</tr>
	</table><html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">Service detection</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    A web server is running on this port.<br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=22964">22964</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">HTTP Server type and version</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br><b>Synopsis :</b><br><br>A web server is running on the remote host.<br><br><b>Description :</b><br><br>This plugin attempts to determine the type and the version of<br>the remote web server.<br><br><b>Risk factor :</b> <br><br>None<br><br><b>Plugin output :</b><br><br>The remote web server type is :<br><br>Virata-EmWeb/R6_0_1<br><br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10107">10107</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">HyperText Transfer Protocol Information</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br><b>Synopsis :</b><br><br>Some information about the remote HTTP configuration can be extracted. <br><br><b>Description :</b><br><br>This test gives some information about the remote HTTP protocol - the<br>version used, whether HTTP Keep-Alive and HTTP pipelining are enabled,<br>etc... <br><br>This test is informational only and does not denote any security<br>problem<br><br><b>Solution :</b><br><br>None.<br><br><b>Risk factor :</b><br><br>None<br><br><b>Plugin output :</b><br><br>Protocol version : HTTP/1.1<br>SSL : no<br>Pipelining : yes<br>Keep-Alive : no<br>Options allowed : (Not implemented)<br>Headers :<br><br>  Server: Virata-EmWeb/R6_0_1<br>  Transfer-Encoding: chunked<br>  Content-Type: text/html<br>  Cache-Control: no-cache<br>  Pragma: no-cache<br>  <br><br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=24260">24260</a>
    </td>
	</tr>
	</table>
<a name="192.168.0.109_unknown (9220/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port unknown (9220/tcp)</font></b></td>
</tr>
	</table><a name="192.168.0.109_bacula-fd (9102/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port bacula-fd (9102/tcp)</font></b></td>
</tr>
	</table><a name="192.168.0.109_netbios-ssn (139/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port netbios-ssn (139/tcp)</font></b></td>
</tr>
	</table><html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">SMB Detection</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    An SMB server is running on this port<br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=11011">11011</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">SMB NativeLanMan</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br><b>Synopsis :</b><br><br>It is possible to obtain information about the remote operating<br>system.<br><br><b>Description :</b><br><br>It is possible to get the remote operating system name and<br>version (Windows and/or Samba) by sending an authentication<br>request to port 139 or 445.<br><br><b>Risk factor :</b><br><br>None<br><br><b>Plugin output :</b><br><br>The remote Operating System is : [<br>The remote native lan manager is : <br>The remote SMB Domain Name is : <br><br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10785">10785</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">SMB log in</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br><b>Synopsis :</b><br><br>It is possible to log into the remote host.<br><br><b>Description :</b><br><br>The remote host is running one of the Microsoft Windows operating<br>systems.  It was possible to log into it using one of the following<br>account :<br><br>- NULL session<br>- Guest account<br>- Given Credentials<br><br><b>See also :</b><br><br><a href="http://support.microsoft.com/support/kb/articles/Q143/4/74.ASP">http://support.microsoft.com/support/kb/articles/Q143/4/74.ASP</a><br><a href="http://support.microsoft.com/support/kb/articles/Q246/2/61.ASP">http://support.microsoft.com/support/kb/articles/Q246/2/61.ASP</a><br><br><b>Risk factor :</b><br><br>none<br><br><b>Plugin output :</b><br><br>- NULL sessions are enabled on the remote host<br>- Remote users are authenticated as 'Guest'<br><br>CVE : CVE-1999-0504, CVE-1999-0505, CVE-1999-0506, CVE-2000-0222, CVE-2002-1117, CVE-2005-3595<br>BID : 494, 990, 11199<br></a><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=10394">10394</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#FDBE00">
	<td align=left colspan=2><b><font color="#FFFFFF">SMB guest account for all users</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br><b>Synopsis :</b><br><br>It is possible to log into the remote host. <br><br><b>Description :</b><br><br>The remote host is running one of the Microsoft Windows operating<br>systems.  It was possible to log into it as a guest user using a <br>random account.<br><br><br><b>Solution :</b><br><br>In the group policy change the setting for <br>'Network access: Sharing and security model for local accounts' from<br>'Guest only - local users authenticate as Guest' to<br>'Classic - local users authenticate as themselves'.<br><br><b>Risk factor :</b><br><br>Medium / CVSS Base Score : 5.0<br>(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)<br>CVE : CVE-1999-0505<br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=26919">26919</a>
    </td>
	</tr>
	</table>
<html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">SMB NULL session</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    <br><b>Synopsis :</b><br><br>It is possible to log into the remote host. <br><br><b>Description :</b><br><br>The remote host is running one of the Microsoft Windows operating<br>systems.  It was possible to log into it using a NULL session.<br><br>A NULL session (no login/password) allows to get information about<br>the remote host.<br><br><b>See also :</b><br><br><a href="http://support.microsoft.com/support/kb/articles/Q143/4/74.ASP">http://support.microsoft.com/support/kb/articles/Q143/4/74.ASP</a><br><a href="http://support.microsoft.com/support/kb/articles/Q246/2/61.ASP">http://support.microsoft.com/support/kb/articles/Q246/2/61.ASP</a><br><br><b>Risk factor :</b><br><br>None<br>CVE : CVE-2002-1117<br>BID : 494<br></a><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=26920">26920</a>
    </td>
	</tr>
	</table>
<a name="192.168.0.109_bacula-dir (9101/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port bacula-dir (9101/tcp)</font></b></td>
</tr>
	</table><a name="192.168.0.109_apache-administration-server (8089/tcp)"></a><p align=right><a href="#toc_192.168.0.109">[^] Back to 192.168.0.109</a></p><table width="100%">
<tr bgcolor="#0F346C">
<td><b><font color=#FFFFFF>Port apache-administration-server (8089/tcp)</font></b></td>
</tr>
	</table><html>
	<table width="100%">
	<tr bgcolor="#397AB2">
	<td align=left colspan=2><b><font color="#FFFFFF">Service detection</font></b></align></td>
	</tr>
	<tr bgcolor="#EEF2F3">
    <td colspan=2>
    A web server is running on this port.<br><br>
			Nessus ID : <a href="http://www.nessus.org/plugins/index.php?view=single&id=22964">22964</a>
    </td>
	</tr>
	</table>
</td></tr></table></center>
</html>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.