27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack<br />

vectors.\n\nAccording to its banner, the remote host is running a version of<br />

phpBB that fails to sanitize user-supplied input. The details of several of these<br />

flaws is unknown; however, it is known that one of the vulnerabilities is an<br />

HTML injection flaw. This can enable an attacker to cause arbitrary HTML and<br />

script code to be executed in a user's browser within the context of the affected<br />

site.<br />

Solution: Upgrade to version 2.0.22 or higher.<br />

CVE-2006-6841<br />

Teredo IPv6 Client Detection<br />

<strong>PVS</strong> ID: 3875 FAMILY: Generic<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running software that should be authorized with respect to<br />

corporate policy.\n\nThe remote client is a Teredo client. Teredo allows clients to tunnel<br />

IPv6 traffic over IPv4. The protocol operates over UDP port 3544 and the RFC draft is<br />

sponsored by Microsoft. Teredo client puts the IPv6 data inside of an IPv4 packet and<br />

sends it to a gateway machine. The gateway machine then strips away the IPv4 header and<br />

delivers the IPv6 packet. Given this, Teredo can be used to circumvent firewall rules.<br />

Solution: Ensure that this sort of functionality is authorized with respect to existing policies and<br />

guidelines.<br />

Teredo Server Detection<br />

CVE Not available<br />

<strong>PVS</strong> ID: 3876 FAMILY: Generic RISK: INFO NESSUS ID:23972<br />

Description: Synopsis :\n\nA Teredo server is listening on the remote host.\n\nThe remote host is<br />

running a Teredo server. Teredo is a protocol for tunneling IPv6 over UDP and is used to<br />

enable nodes to obtain IPv6 connectivity even when they are located behind IPv4 NAT<br />

devices that have no support for IPv6. A Teredo server is a node that is connected to both<br />

IPv4 and IPv6 internets and supports a Teredo tunneling interface over which packets are<br />

received.<br />

Solution: Limit incoming traffic to this port if desired.<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Wireless Access Point (WAP) Web Server Detection<br />

<strong>PVS</strong> ID: 3877 FAMILY: Web Servers RISK: INFO NESSUS ID:11026<br />

Family Internet Services 1003

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!