Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: Plugin 19408 - MS05-039 - and Windows Server 2003

Subject: Re: Plugin 19408 - MS05-039 - and Windows Server 2003
Date: Thu, 18 Aug 2005 17:56:11 +0200

On Aug 18, 2005, at 17:50, Chris Lyon wrote:

On 8/17/05, Renaud Deraison <deraison@nessus.org> wrote:


On Aug 17, 2005, at 19:49, Chad I. Uretsky wrote:


I just ran a scan against a Win2K3 box I have, checking for the
MS05-039 vulnerability.  I have not yet patched the box, and so I
expected it to show up as vulnerable.

It won't show up as vulnerable, as the pipe which is needed to access
the PNP service is not available over a NULL session (while it is on
Win2K). The good news is that a worm can not do a blind attack
either, as credentials are needed on this platform.


Even if you supply the login information?

If you supply the correct login information, the plugin 19402 will complain about the missing patch.



-- Renaud _______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>