About Nessus 3.0.6 for Linux
"Gisella Linares" <[email protected]>
| Newsgroups | gmane.comp.security.nessus.general |
|---|---|
| Organization | Dirección de Informática - PUCP |
| Message-ID | <[email protected]> |
Hi,
I am system administrator of Pontificia Universidad Catolica del Peru. We
use Nessus 3.0.6 for Linux (free version) in our servers.
When we scan a web server with :
- Red Hat 5 (64 bits)
- php-5.1.6-20.el5_2.1
- Apache: httpd-2.2.3-11.el5_1.3
and the nessus report shows some critical vulnerabilities in php and
suggests update the version of php (The attach "output.prueba.20080725"
shows the results).
After that, we reported this to Red Hat support and they told us that this
scanner has an approach which not checking individual security
vulnerabilities and because of this it can produce some false positives.
Because of this, we want to know if this Nessus version is compatible with
RedHat 5 (64 bits) and we appreciate you can confirm if these results are
false positives or not.
Thank you very much for your help.
Regards,
****************************************
Gisella Linares Chong
Oficina de Soporte Informatico
Direccion de Informatica - PUCP
Telef: 626-2000 anexo 3378
http://dirinfo.pucp.edu.pe
****************************************
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus
output.prueba.20080725.html
(text/html, 34.5 KB)
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>
<TITLE>Nessus Scan Report</TITLE>
<meta http-equiv="Content-Type" content="text/html; charset="iso-8859-1">
<style type="text/css">
<!--
BODY {
BACKGROUND-COLOR: #ffffff
}
A { TEXT-DECORATION: none }
A:visited { COLOR: #0000cf; TEXT-DECORATION: none }
A:link { COLOR: #0000cf; TEXT-DECORATION: none }
A:active { COLOR: #0000cf; TEXT-DECORATION: underline }
A:hover { COLOR: #0000cf; TEXT-DECORATION: underline }
OL { COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif }
UL { COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif }
P { COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif }
BODY { COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif }
TD { COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif }
TR { COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif }
TH { COLOR: #333333; FONT-FAMILY: tahoma,helvetica,sans-serif }
FONT.title { BACKGROUND-COLOR: white; COLOR: #363636; FONT-FAMILY: tahoma,helvetica,verdana,lucida console,utopia; FONT-SIZE: 10pt; FONT-WEIGHT: bold }
FONT.sub { BACKGROUND-COLOR: white; COLOR: #000000; FONT-FAMILY: tahoma,helvetica,verdana,lucida console,utopia; FONT-SIZE: 10pt }
FONT.layer { COLOR: #ff0000; FONT-FAMILY: courrier,sans-serif,arial,helvetica; FONT-SIZE: 8pt; TEXT-ALIGN: left }
TD.title { BACKGROUND-COLOR: #A2B5CD; COLOR: #555555; FONT-FAMILY: tahoma,helvetica,verdana,lucida console,utopia; FONT-SIZE: 10pt; FONT-WEIGHT: bold; HEIGHT: 20px; TEXT-ALIGN: right }
TD.sub { BACKGROUND-COLOR: #DCDCDC; COLOR: #555555; FONT-FAMILY: tahoma,helvetica,verdana,lucida console,utopia; FONT-SIZE: 10pt; FONT-WEIGHT: bold; HEIGHT: 18px; TEXT-ALIGN: left }
TD.content { BACKGROUND-COLOR: white; COLOR: #000000; FONT-FAMILY: tahoma,arial,helvetica,verdana,lucida console,utopia; FONT-SIZE: 8pt; TEXT-ALIGN: left; VERTICAL-ALIGN: middle }
TD.default { BACKGROUND-COLOR: WHITE; COLOR: #000000; FONT-FAMILY: tahoma,arial,helvetica,verdana,lucida console,utopia; FONT-SIZE: 8pt; }
TD.border { BACKGROUND-COLOR: #cccccc; COLOR: black; FONT-FAMILY: tahoma,helvetica,verdana,lucida console,utopia; FONT-SIZE: 10pt; HEIGHT: 25px }
TD.border-HILIGHT { BACKGROUND-COLOR: #ffffcc; COLOR: black; FONT-FAMILY: verdana,arial,helvetica,lucida console,utopia; FONT-SIZE: 10pt; HEIGHT: 25px }
-->
</style>
</HEAD>
<BODY>
<table bgcolor="#a1a1a1" border=0 cellpadding=0 cellspacing=0 width="95%">
<tbody>
<tr><td>
<table border=0 cellpadding=2 cellspacing=1 width="100%">
<tbody>
<tr>
<td class=title>Nessus Scan Report</td></tr>
<tr>
<td class=content>This report gives details on hosts that were tested
and issues that were found. Please follow the recommended
steps and procedures to eradicate these threats.
</td></tr></tbody></table></td></tr></tbody></table><br>
<table bgcolor="#a1a1a1" border=0 cellpadding=0 cellspacing=0 width="60%">
<tbody><tr><td>
<table border=0 cellpadding=2 cellspacing=1 width="100%">
<tbody>
<tr>
<td class=title colspan=2>Scan Details</td></tr>
<tr>
<td class=default width="60%">Hosts which were alive and responding during test</td>
<td class=default width="30%">1</td></tr>
<tr>
<td class=default width="60%">Number of security holes found</td>
<td class=default width="30%">5</td></tr>
<tr>
<td class=default width="60%">Number of security warnings found</td>
<td class=default width="30%">1</td></tr>
</tbody></table></td></tr></tbody></table><br><br>
<a name="toc"></a><table bgcolor="#a1a1a1" border=0 cellpadding=0 cellspacing=0 width="60%">
<tbody><tr><td>
<table border=0 cellpadding=2 cellspacing=1 width="100%">
<tbody>
<tr>
<td class=title colspan=2>Host List</td></tr>
<tr>
<td class=sub width="60%">Host(s)</td>
<td class=sub width="40%">Possible Issue</td></tr>
<tr>
<td class=default width="60%"><a href="#hermes4_pucp_edu_pe">hermes4.pucp.edu.pe</a></td>
<td class=default width="40%"><font color=red>Security hole(s) found</font></td></tr>
</tbody></table></td></tr></tbody></table>
<a name="hermes4_pucp_edu_pe"></a>
<a name="hermes4_pucp_edu_pe_toc"></a>
<div align="left"><font size=-2><a href="#toc">[ return to top ]</a></font></div><br><br>
<table bgcolor="#a1a1a1" border=0 cellpadding=0 cellspacing=0 width="60%">
<tbody><tr><td>
<table cellpadding=2 cellspacing=1 border=0 width="100%">
<tbody>
<tr>
<td class=title colspan=3>Analysis of Host</td></tr>
<tr>
<td class=sub width="20%">Address of Host</td>
<td class=sub width="30%">Port/Service</td>
<td class=sub width="30%">Issue regarding Port</td></tr>
<tr>
<td class=default width="20%">hermes4.pucp.edu.pe</td>
<td class=default width="30%"><a href="#hermes4_pucp_edu_pe_22_tcp">ssh (22/tcp)</a></td>
<td class=default width="30%">Security notes found</td></tr>
<tr>
<td class=default width="20%">hermes4.pucp.edu.pe</td>
<td class=default width="30%"><a href="#hermes4_pucp_edu_pe_123_udp">ntp (123/udp)</a></td>
<td class=default width="30%">Security notes found</td></tr>
<tr>
<td class=default width="20%">hermes4.pucp.edu.pe</td>
<td class=default width="30%"><a href="#hermes4_pucp_edu_pe_694_udp">ha-cluster (694/udp)</a></td>
<td class=default width="30%">Security notes found</td></tr>
<tr>
<td class=default width="20%">hermes4.pucp.edu.pe</td>
<td class=default width="30%"><a href="#hermes4_pucp_edu_pe_111_udp">sunrpc (111/udp)</a></td>
<td class=default width="30%">Security notes found</td></tr>
<tr>
<td class=default width="20%">hermes4.pucp.edu.pe</td>
<td class=default width="30%"><a href="#hermes4_pucp_edu_pe_general_udp">general/udp</a></td>
<td class=default width="30%">Security notes found</td></tr>
<tr>
<td class=default width="20%">hermes4.pucp.edu.pe</td>
<td class=default width="30%"><a href="#hermes4_pucp_edu_pe_general_tcp">general/tcp</a></td>
<td class=default width="30%">Security notes found</td></tr>
<tr>
<td class=default width="20%">hermes4.pucp.edu.pe</td>
<td class=default width="30%"><a href="#hermes4_pucp_edu_pe_general_icmp">general/icmp</a></td>
<td class=default width="30%">Security notes found</td></tr>
<tr>
<td class=default width="20%">hermes4.pucp.edu.pe</td>
<td class=default width="30%"><a href="#hermes4_pucp_edu_pe_80_tcp">http (80/tcp)</a></td>
<td class=default width="30%"><font color=red>Security hole found</font></td></tr>
<tr>
<td class=default width="20%">hermes4.pucp.edu.pe</td>
<td class=default width="30%"><a href="#hermes4_pucp_edu_pe_111_tcp">sunrpc (111/tcp)</a></td>
<td class=default width="30%">Security notes found</td></tr>
<tr>
<td class=default width="20%">hermes4.pucp.edu.pe</td>
<td class=default width="30%"><a href="#hermes4_pucp_edu_pe_697_tcp">uuidgen (697/tcp)</a></td>
<td class=default width="30%">Security notes found</td></tr>
<tr>
<td class=default width="20%">hermes4.pucp.edu.pe</td>
<td class=default width="30%"><a href="#hermes4_pucp_edu_pe_3306_tcp">mysql (3306/tcp)</a></td>
<td class=default width="30%">Security notes found</td></tr>
</tbody></table></td></tr></tbody></table><br><br>
<table bgcolor="#a1a1a1" cellpadding=0 cellspacing=0 border=0 width="75%">
<tbody><tr><td>
<table cellpadding=2 cellspacing=1 border=0 width="100%">
<td class=title colspan=3>Security Issues and Fixes: hermes4.pucp.edu.pe</td></tr>
<tr>
<td class=sub width="10%">Type</td>
<td class=sub width="10%">Port</td>
<td class=sub width="80%">Issue and Fix</td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_22_tcp"></a>ssh (22/tcp)</td>
<td class=default width="80%">An ssh server is running on this port<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=10330">10330</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_22_tcp"></a>ssh (22/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
An SSH server is running on the remote host. <br>
<br>
Description :<br>
<br>
This plugin determines the versions of the SSH protocol supported by<br>
the remote SSH daemon. <br>
<br>
Risk factor : <br>
<br>
None<br>
<br>
Plugin output :<br>
<br>
The remote SSH daemon supports the following versions of the<br>
SSH protocol :<br>
<br>
. 1.99<br>
. 2.0<br>
<br>
<br>
SSHv2 host key fingerprint : f2:01:2a:fb:d0:df:09:ea:50:8b:df:11:27:78:73:c0<br>
<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=10881">10881</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_22_tcp"></a>ssh (22/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
An SSH server is listening on this port.<br>
<br>
Description :<br>
<br>
It is possible to obtain information about the remote SSH<br>
server by sending an empty authentication request.<br>
<br>
Risk factor :<br>
<br>
None<br>
<br>
Plugin output :<br>
<br>
SSH version : SSH-2.0-OpenSSH_4.3<br>
SSH supported authentication : publickey,gssapi-with-mic,password<br>
<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=10267">10267</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_123_udp"></a>ntp (123/udp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
An NTP server is listening on the remote host.<br>
<br>
Description :<br>
<br>
An NTP (Network Time Protocol) server is listening on this port.<br>
It provides information about the current date and time of the<br>
remote system and may provide system information.<br>
<br>
Risk factor :<br>
<br>
None<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=10884">10884</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_694_udp"></a>ha-cluster (694/udp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
An ONC RPC service is running on the remote host.<br>
<br>
Description :<br>
<br>
By sending a DUMP request to the portmapper it was possible to<br>
enumerate the ONC RPC services running on the remote port.<br>
Using this information it is possible to connect and bind to<br>
each service by sending an RPC request to the remote port.<br>
<br>
Risk factor :<br>
<br>
None<br>
<br>
Plugin output :<br>
<br>
The following RPC services are available on UDP port 694 :<br>
<br>
- program: 100024 (status), version: 1<br>
<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=11111">11111</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_111_udp"></a>sunrpc (111/udp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
An ONC RPC service is running on the remote host.<br>
<br>
Description :<br>
<br>
By sending a DUMP request to the portmapper it was possible to<br>
enumerate the ONC RPC services running on the remote port.<br>
Using this information it is possible to connect and bind to<br>
each service by sending an RPC request to the remote port.<br>
<br>
Risk factor :<br>
<br>
None<br>
<br>
Plugin output :<br>
<br>
The following RPC services are available on UDP port 111 :<br>
<br>
- program: 100000 (portmapper), version: 2<br>
<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=11111">11111</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_general_udp"></a>general/udp</td>
<td class=default width="80%">For your information, here is the traceroute from 200.16.1.240 to 200.16.5.219 : <br>
200.16.1.240<br>
200.16.1.225<br>
200.16.5.219<br>
<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=10287">10287</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_general_tcp"></a>general/tcp</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
The remote service implements TCP timestamps.<br>
<br>
Description :<br>
<br>
The remote host implements TCP timestamps, as defined by RFC1323.<br>
A side effect of this feature is that the uptime of the remote <br>
host can sometimes be computed.<br>
<br>
See also :<br>
<br>
<a href="http://www.ietf.org/rfc/rfc1323.txt">http://www.ietf.org/rfc/rfc1323.txt</a><br>
<br>
Risk factor : <br>
<br>
None<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=25220">25220</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_general_tcp"></a>general/tcp</td>
<td class=default width="80%">Information about this scan : <br>
<br>
Nessus version : 3.0.6 (Nessus 3.2.1 is available - consider upgrading)<br>
<br>
Plugin feed version : 200807241934<br>
Type of plugin feed : Registered (7 days delay)<br>
<br>
This scanner is using the Registered Feed which is going to be <br>
discontinued on July 31st.<br>
<br>
Please read <a href="http://www.nessus.org/products/directfeed/change.php">http://www.nessus.org/products/directfeed/change.php</a><br>
<br>
Scanner IP : 200.16.1.240<br>
Port scanner(s) : nessus_tcp_scanner <br>
Port range : default<br>
Thorough tests : no<br>
Experimental tests : no<br>
Paranoia level : 1<br>
Report Verbosity : 1<br>
Safe checks : yes<br>
Optimize the test : yes<br>
Max hosts : 20<br>
Max checks : 4<br>
Recv timeout : 5<br>
Scan Start Date : 2008/7/25 12:48<br>
Scan duration : 70 sec<br>
<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=19506">19506</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_general_tcp"></a>general/tcp</td>
<td class=default width="80%"><br>
Remote operating system : Linux Kernel 2.6<br>
Confidence Level : 65<br>
Method : SinFP<br>
<br>
<br>
The remote host is running Linux Kernel 2.6<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=11936">11936</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_general_tcp"></a>general/tcp</td>
<td class=default width="80%">200.16.5.219 resolves as hermes4.pucp.edu.pe.<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=12053">12053</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_general_icmp"></a>general/icmp</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
It is possible to determine the exact time set on the remote host. <br>
<br>
Description :<br>
<br>
The remote host answers to an ICMP timestamp request. This allows an<br>
attacker to know the date which is set on your machine. <br>
<br>
This may help him to defeat all your time based authentication<br>
protocols. <br>
<br>
Solution :<br>
<br>
Filter out the ICMP timestamp requests (13), and the outgoing ICMP<br>
timestamp replies (14). <br>
<br>
Risk factor :<br>
<br>
None<br>
<br>
Plugin output :<br>
<br>
The remote clock is synchronized with the local clock.<br>
<br>
CVE : <a href="http://cgi.nessus.org/cve.php3?cve=CVE-1999-0524">CVE-1999-0524</a><br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=10114">10114</a></td></tr>
<tr>
<td valign=top class=default width="10%"><font color=red>Vulnerability</font></td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_80_tcp"></a>http (80/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
The remote web server uses a version of PHP that is affected by<br>
multiple flaws. <br>
<br>
Description :<br>
<br>
According to its banner, the version of PHP installed on the remote<br>
host is older than 5.2.6. Such versions may be affected by the<br>
following issues :<br>
<br>
- A stack buffer overflow in FastCGI SAPI.<br>
<br>
- An integer overflow in printf().<br>
<br>
- An security issue arising from improper calculation<br>
of the length of PATH_TRANSLATED in cgi_main.c.<br>
<br>
- A safe_mode bypass in cURL.<br>
<br>
- Incomplete handling of multibyte chars inside<br>
escapeshellcmd().<br>
<br>
- Issues in the bundled PCRE fixed by version 7.6.<br>
<br>
See also :<br>
<br>
<a href="http://archives.neohapsis.com/archives/bugtraq/2008-03/0321.html">http://archives.neohapsis.com/archives/bugtraq/2008-03/0321.html</a><br>
<a href="http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0103.html">http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0103.html</a><br>
<a href="http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0107.html">http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0107.html</a><br>
<a href="http://www.php.net/releases/5_2_6.php">http://www.php.net/releases/5_2_6.php</a><br>
<br>
Solution :<br>
<br>
Upgrade to PHP version 5.2.6 or later. <br>
<br>
Risk factor : <br>
<br>
High / CVSS Base Score : 7.5<br>
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)<br>
<br>
Plugin output :<br>
<br>
PHP version PHP/5.1.6 appears to be running on the remote host<br>
based on the following Server response header :<br>
<br>
Server: Apache<br>
<br>
CVE : <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-4850">CVE-2007-4850</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2008-0599">CVE-2008-0599</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2008-1384">CVE-2008-1384</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2008-2050">CVE-2008-2050</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2008-2051">CVE-2008-2051</a><br>
BID : <a href="http://cgi.nessus.org/bid.php3?bid=27413">27413</a>, <a href="http://cgi.nessus.org/bid.php3?bid=28392">28392</a>, <a href="http://cgi.nessus.org/bid.php3?bid=29009">29009</a><br>
Other references : OSVDB:43219, Secunia:30048<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=32123">32123</a> </td></tr>
<tr>
<td valign=top class=default width="10%"><font color=red>Vulnerability</font></td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_80_tcp"></a>http (80/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
The remote web server uses a version of PHP that is affected by<br>
multiple buffer overflows. <br>
<br>
Description :<br>
<br>
According to its banner, the version of PHP installed on the remote<br>
host is older than 5.2. Such versions may be affected by several<br>
buffer overflows. <br>
<br>
To exploit these issues, an attacker would need the ability to upload<br>
an arbitrary PHP script on the remote server, or to be able to<br>
manipulate several variables processed by some PHP functions such as<br>
htmlentities(). <br>
<br>
See also :<br>
<br>
<a href="http://www.php.net/releases/5_2_0.php">http://www.php.net/releases/5_2_0.php</a><br>
<br>
Solution :<br>
<br>
Upgrade to PHP version 5.2.0 or later. <br>
<br>
Risk factor : <br>
<br>
High / CVSS Base Score : 7.5<br>
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)<br>
CVE : <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2006-5465">CVE-2006-5465</a><br>
BID : <a href="http://cgi.nessus.org/bid.php3?bid=20879">20879</a><br>
Other references : OSVDB:30178, OSVDB:30179<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=31649">31649</a> </td></tr>
<tr>
<td valign=top class=default width="10%"><font color=red>Vulnerability</font></td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_80_tcp"></a>http (80/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
The remote web server uses a version of PHP that is affected by<br>
multiple flaws. <br>
<br>
Description :<br>
<br>
According to its banner, the version of PHP installed on the remote<br>
host is older than 5.2.1. Such versions may be affected by several<br>
issues, including buffer overflows, format string vulnerabilities,<br>
arbitrary code execution, 'safe_mode' and 'open_basedir' bypasses, and<br>
clobbering of super-globals. <br>
<br>
See also :<br>
<br>
<a href="http://www.php.net/releases/5_2_1.php">http://www.php.net/releases/5_2_1.php</a><br>
<br>
Solution :<br>
<br>
Upgrade to PHP version 5.2.1 or later. <br>
<br>
Risk factor : <br>
<br>
High / CVSS Base Score : 7.5<br>
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)<br>
CVE : <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2006-6383">CVE-2006-6383</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-0905">CVE-2007-0905</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-0906">CVE-2007-0906</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-0907">CVE-2007-0907</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-0908">CVE-2007-0908</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-0909">CVE-2007-0909</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-0910">CVE-2007-0910</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1376">CVE-2007-1376</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1380">CVE-2007-1380</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1453">CVE-2007-1453</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1700">CVE-2007-1700</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1701">CVE-2007-1701</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1824">CVE-2007-1824</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1825">CVE-2007-1825</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1884">CVE-2007-1884</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1885">CVE-2007-1885</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1886">CVE-2007-1886</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1887">CVE-2007-1887</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1890">CVE-2007-1890</a><br>
BID : <a href="http://cgi.nessus.org/bid.php3?bid=21508">21508</a>, <a href="http://cgi.nessus.org/bid.php3?bid=22496">22496</a>, <a href="http://cgi.nessus.org/bid.php3?bid=22805">22805</a>, <a href="http://cgi.nessus.org/bid.php3?bid=22806">22806</a>, <a href="http://cgi.nessus.org/bid.php3?bid=22862">22862</a>, <a href="http://cgi.nessus.org/bid.php3?bid=22922">22922</a>, <a href="http://cgi.nessus.org/bid.php3?bid=23119">23119</a>, <a href="http://cgi.nessus.org/bid.php3?bid=23120">23120</a>, <a href="http://cgi.nessus.org/bid.php3?bid=23219">23219</a>, <a href="http://cgi.nessus.org/bid.php3?bid=23233">23233</a>, <a href="http://cgi.nessus.org/bid.php3?bid=23234">23234</a>, <a href="http://cgi.nessus.org/bid.php3?bid=23235">23235</a>, <a href="http://cgi.nessus.org/bid.php3?bid=23236">23236</a>, <a href="http://cgi.nessus.org/bid.php3?bid=23237">23237</a>, <a href="http://cgi.nessus.org/bid.php3?bid=23238">23238</a><br>
Other references : OSVDB:32776, OSVDB:32781, OSVDB:33955, OSVDB:34767<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=24907">24907</a> </td></tr>
<tr>
<td valign=top class=default width="10%"><font color=red>Vulnerability</font></td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_80_tcp"></a>http (80/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
The remote web server uses a version of PHP that is affected by<br>
multiple flaws. <br>
<br>
Description :<br>
<br>
According to its banner, the version of PHP installed on the remote<br>
host is older than 5.2.4. Such versions may be affected by various<br>
issues, including but not limited to several overflows.<br>
<br>
See also :<br>
<br>
<a href="http://www.php.net/releases/5_2_4.php">http://www.php.net/releases/5_2_4.php</a><br>
<br>
Solution :<br>
<br>
Upgrade to PHP version 5.2.4 or later. <br>
<br>
Risk factor : <br>
<br>
High / CVSS Base Score : 7.5<br>
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)<br>
CVE : <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-2872">CVE-2007-2872</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-3378">CVE-2007-3378</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-3806">CVE-2007-3806</a><br>
BID : <a href="http://cgi.nessus.org/bid.php3?bid=24661">24661</a>, <a href="http://cgi.nessus.org/bid.php3?bid=24261">24261</a>, <a href="http://cgi.nessus.org/bid.php3?bid=24922">24922</a>, <a href="http://cgi.nessus.org/bid.php3?bid=25498">25498</a><br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=25971">25971</a> </td></tr>
<tr>
<td valign=top class=default width="10%"><font color=red>Vulnerability</font></td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_80_tcp"></a>http (80/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
The remote web server uses a version of PHP that is affected by<br>
multiple flaws. <br>
<br>
Description :<br>
<br>
According to its banner, the version of PHP installed on the remote<br>
host is older than 5.2.5. Such versions may be affected by various<br>
issues, including but not limited to several buffer overflows. <br>
<br>
See also :<br>
<br>
<a href="http://www.php.net/releases/5_2_5.php">http://www.php.net/releases/5_2_5.php</a><br>
<br>
Solution :<br>
<br>
Upgrade to PHP version 5.2.5 or later. <br>
<br>
Risk factor : <br>
<br>
High / CVSS Base Score : 7.5<br>
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)<br>
CVE : <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-4887">CVE-2007-4887</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-5898">CVE-2007-5898</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-5900">CVE-2007-5900</a><br>
BID : <a href="http://cgi.nessus.org/bid.php3?bid=26403">26403</a><br>
Other references : OSVDB:38680, OSVDB:38681, OSVDB:38682, OSVDB:38683, OSVDB:38684, OSVDB:38685<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=28181">28181</a> </td></tr>
<tr>
<td valign=top class=default width="10%">Warning</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_80_tcp"></a>http (80/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
The remote web server uses a version of PHP that is affected by<br>
multiple flaws. <br>
<br>
Description :<br>
<br>
According to its banner, the version of PHP installed on the remote<br>
host is older than 5.2.3. Such versions may be affected by several<br>
issues, including an integer overflow, 'safe_mode' and 'open_basedir'<br>
bypass, and a denial of service vulnerability. <br>
<br>
See also :<br>
<br>
<a href="http://www.php.net/releases/5_2_3.php">http://www.php.net/releases/5_2_3.php</a><br>
<br>
Solution :<br>
<br>
Upgrade to PHP version 5.2.3 or later. <br>
<br>
Risk factor : <br>
<br>
Medium / CVSS Base Score : 6.8<br>
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)<br>
CVE : <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-1900">CVE-2007-1900</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-2756">CVE-2007-2756</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-2872">CVE-2007-2872</a>, <a href="http://cgi.nessus.org/cve.php3?cve=CVE-2007-3007">CVE-2007-3007</a><br>
BID : <a href="http://cgi.nessus.org/bid.php3?bid=23359">23359</a>, <a href="http://cgi.nessus.org/bid.php3?bid=24089">24089</a>, <a href="http://cgi.nessus.org/bid.php3?bid=24259">24259</a>, <a href="http://cgi.nessus.org/bid.php3?bid=24261">24261</a><br>
Other references : OSVDB:33962, OSVDB:35788, OSVDB:36083, OSVDB:36084, OSVDB:36643<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=25368">25368</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_80_tcp"></a>http (80/tcp)</td>
<td class=default width="80%">A web server is running on this port<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=10330">10330</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_80_tcp"></a>http (80/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
Some information about the remote HTTP configuration can be extracted. <br>
<br>
Description :<br>
<br>
This test gives some information about the remote HTTP protocol - the<br>
version used, whether HTTP Keep-Alive and HTTP pipelining are enabled,<br>
etc... <br>
<br>
This test is informational only and does not denote any security<br>
problem<br>
<br>
Solution :<br>
<br>
None.<br>
<br>
Risk factor :<br>
<br>
None<br>
<br>
Plugin output :<br>
<br>
Protocol version : HTTP/1.1<br>
SSL : no<br>
Pipelining : no<br>
Keep-Alive : no<br>
Options allowed : GET,HEAD,POST,OPTIONS,TRACE<br>
Headers :<br>
<br>
Date: Fri, 25 Jul 2008 17:49:10 GMT
<br>
Server: Apache
<br>
X-Powered-By: PHP/5.1.6
<br>
Content-Length: 68
<br>
Connection: close
<br>
Content-Type: text/html; charset=ISO-8859-1
<br>
<br>
<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=24260">24260</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_80_tcp"></a>http (80/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
A web server is running on the remote host.<br>
<br>
Description :<br>
<br>
This plugin attempts to determine the type and the version of<br>
the remote web server.<br>
<br>
Risk factor : <br>
<br>
None<br>
<br>
Plugin output :<br>
<br>
The remote web server type is :<br>
<br>
Apache
<br>
<br>
and the 'ServerTokens' directive is ProductOnly<br>
Apache does not offer a way to hide the server type.<br>
<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=10107">10107</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_80_tcp"></a>http (80/tcp)</td>
<td class=default width="80%">The following CGI have been discovered :<br>
<br>
Syntax : cginame (arguments [default value])<br>
<br>
/manual/style/ (C=M;O [A] C=N;O [D] C=S;O [A] C=D;O [A] )<br>
/manual/images/ (C=M;O [A] C=N;O [D] C=S;O [A] C=D;O [A] )<br>
/idea/ (lin_proy_tambo.htm [] pub_electro.htm [] contacto.htm [] e...)<br>
/manual/style/css/ (C=M;O [A] C=N;O [D] C=S;O [A] C=D;O [A] )<br>
<br>
<br>
Directory index found at /manual/style/css/<br>
Directory index found at /manual/style/<br>
Directory index found at /manual/images/<br>
<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=10662">10662</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_80_tcp"></a>http (80/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
It is possible to enumerate web directories.<br>
<br>
Description :<br>
<br>
This plugin attempts to determine the presence of various<br>
common dirs on the remote web server.<br>
<br>
Risk factor : <br>
<br>
None<br>
<br>
Plugin output :<br>
<br>
The following directories were discovered:<br>
/webstats, /error, /icons, /idea, /img, /manual<br>
<br>
While this is not, in and of itself, a bug, you should manually inspect <br>
these directories to ensure that they are in compliance with company<br>
security standards<br>
<br>
Other references : OWASP:OWASP-CM-006<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=11032">11032</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_111_tcp"></a>sunrpc (111/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
An ONC RPC portmapper is running on the remote host.<br>
<br>
Description :<br>
<br>
The RPC portmapper is running on this port.<br>
<br>
The portmapper allows to get the port number of each RPC service<br>
running on the remote host either by sending multiple lookup<br>
requests or by sending a DUMP request.<br>
<br>
Risk factor : <br>
<br>
None<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=10223">10223</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_111_tcp"></a>sunrpc (111/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
An ONC RPC service is running on the remote host.<br>
<br>
Description :<br>
<br>
By sending a DUMP request to the portmapper it was possible to<br>
enumerate the ONC RPC services running on the remote port.<br>
Using this information it is possible to connect and bind to<br>
each service by sending an RPC request to the remote port.<br>
<br>
Risk factor :<br>
<br>
None<br>
<br>
Plugin output :<br>
<br>
The following RPC services are available on TCP port 111 :<br>
<br>
- program: 100000 (portmapper), version: 2<br>
<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=11111">11111</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_697_tcp"></a>uuidgen (697/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
An ONC RPC service is running on the remote host.<br>
<br>
Description :<br>
<br>
By sending a DUMP request to the portmapper it was possible to<br>
enumerate the ONC RPC services running on the remote port.<br>
Using this information it is possible to connect and bind to<br>
each service by sending an RPC request to the remote port.<br>
<br>
Risk factor :<br>
<br>
None<br>
<br>
Plugin output :<br>
<br>
The following RPC services are available on TCP port 697 :<br>
<br>
- program: 100024 (status), version: 1<br>
<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=11111">11111</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_3306_tcp"></a>mysql (3306/tcp)</td>
<td class=default width="80%">A MySQL server seems to be running on this port but it<br>
rejects connection from the Nessus scanner.<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=17975">17975</a></td></tr>
<tr>
<td valign=top class=default width="10%">Informational</td>
<td valign=top class=default width="10%"><a name="hermes4_pucp_edu_pe_3306_tcp"></a>mysql (3306/tcp)</td>
<td class=default width="80%"><br>
Synopsis :<br>
<br>
A database server is listening on the remote port. <br>
<br>
Description :<br>
<br>
The remote host is running MySQL, an open-source database server. The<br>
remote database access is restricted and configured to reject access<br>
from not allowed IPs. Therefore it was not possible to extract its<br>
version number. <br>
<br>
Risk factor :<br>
<br>
None<br>
Nessus ID : <a href="http://cgi.nessus.org/nessus_id.php3?id=10719">10719</a></td></tr>
</td></tr></tbody></table></td></tr></tbody></table>
<hr>
<i>This file was generated by <a href="http://www.nessus.org">Nessus</a>, <i>the</i> security scanner.</i>
</BODY>
</HTML>