Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Problem with plugin 18502 reporting Windows SMB flaw |
|---|---|
| Date: | Wed, 29 Jun 2005 09:37:52 -0400 |
seems to me there are a lot of false posititives....I am still proving to my security people that I installed the required Oracle patches that plugin 18034 checks for....In our case it seems that the code isn't smart enough to determine if the patch was applied. It only looks at the version number for the database....and the patches don't change the version number, so possibly your false positive is similar. -----Original Message----- From: nessus-bounces@list.nessus.org [mailto:nessus-bounces@list.nessus.org]On Behalf Of Miles B.L. Sent: Tuesday, June 28, 2005 8:52 AM To: nessus@list.nessus.org Subject: Problem with plugin 18502 reporting Windows SMB flaw Hello, I recently scanned a windows 2003 server (SP1) with Nessus and it reported it was vulnerable to the Server Message Block (SMB) implementation flaw as described in MS05-027 and tested for by plugin 18502. On checking with the system adminstrator, he confirmed the system had the patch (896422) described in MS05-027 applied and that the Mircrosoft Baseline security analyser confirmed the system was not vulnerable. My conclusion - either the patch doesn't resolve the vulnerability (unlikely) or the plugin has reported a false positive for some reason (more likely)? Has anyone else come across this problem? How do we report this to someone to check and fix? Thanks, Brevan Miles Information and Systems Security Co-ordinator, Information Systems Services, The University of Southampton, _______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus _______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | more "local tests" ?, Michel Arboi |
|---|---|
| Next by Date: | Re: Problem with plugin 18502 reporting Windows SMB flaw, Renaud Deraison |
| Previous by Thread: | Re: Problem with plugin 18502 reporting Windows SMB flaw, Nicolas Pouvesle |
| Next by Thread: | Re: Problem with plugin 18502 reporting Windows SMB flaw, Renaud Deraison |
| Indexes: | [Date] [Thread] [Top] [All Lists] |