Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: Samba swat warnings in 2.2.4

Subject: Re: Samba swat warnings in 2.2.4
Date: Tue, 26 Apr 2005 08:56:30 -0400

On Apr 26, 2005, at 6:43 AM, Knut Hellebø wrote:

Regards,

I recently installed Nessus 2.2.4 on a DL360G3 running Linux (RH 7.3). The compilation went OK (as always on Linux), and to be sure I had a clean install I wiped everything prior to installing the libs/binaries/configs etc.
However, when running Nessus, every report warns me about a swat vulnerability even when samba is not installed. The warning appear as a general/icmp message saying


The remote host is affected by the vulnerability described in GLSA-200407-21 (Samba: Multiple buffer overflows)

The message has also appeared on other tested hosts as a general/tcp message.
False positive ?



If you are not scanning a Gentoo system with SSH credentials it's a bug :


1) kill your nessus daemon
2) remove desc directory (rm -rf /usr/local/lib/nessus/plugins/.desc/ )
3) restart nessus daemon

Now this vulnerability should no longer be reported.


Nicolas

_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>