Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: Administrator and Guest Accounts

Subject: Re: Administrator and Guest Accounts
Date: Fri, 11 Apr 2008 20:04:45 -0400
On Apr 11, 2008, at 3:22 PM, Adam Campbell wrote:

I am new to Nessus and am running some basic scans to get a grasp on  
it.  I have two plugins enabled(SMB blank administrator password and  
SMB guest account for all users) but I am only getting results for  
one.  If I check the log it says “required key missing” on the  
plugin that didn’t run.

In the case of these two plugins, you'll see this message in the log  
if you have optimization turned on and the plugin doesn't report a  
problem.

Here is my targeted server configuration and the nessus output.


Blank admin password and guest enabled = Results for SMB guest  
account for all users
Blank admin password and guest disabled = Results for SMB blank  
administrator password

With the "Guest only" module for local accounts, aren't network logons  
are automatically mapped to the guest account? How would you be able  
to determine if a particular local user, such as Administrator, is  
missing a password in that case?

George
-- 
theall@tenablesecurity.com



_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>