27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

'.cnf' File Detection<br />

occurrences.<br />

CVE Not available<br />

<strong>PVS</strong> ID: 4662 FAMILY: Data Leakage RISK: INFO NESSUS ID:Not Available<br />

Description: The remote web server is hosting .cnf files. As an example, consider the following file<br />

%P\nDistributing such files over the web can be done, but the webmaster should make sure<br />

that they do not contain confidential data. '.cnf' files are typically configuration files that<br />

may contain information regarding application version, physical path and more.<br />

Solution: Ensure that confidential data is not present within the '.cnf' file. Note: <strong>PVS</strong> only reports on<br />

the first occurence of this item on a web server. Parse your entire web source for similar<br />

occurrences.<br />

CVE Not available<br />

Possible Social <strong>Security</strong> Number in Cookie<br />

<strong>PVS</strong> ID: 4663 FAMILY: Data Leakage RISK: INFO NESSUS ID:Not Available<br />

Description: The remote web client sent a cookie with what appears to be an embedded Social<br />

<strong>Security</strong> Number. You should manually verify that confidential data is not being<br />

leaked from the network. The observed cookie was: \n %L<br />

Solution: Ensure that confidential data is not passed within plaintext cookies. Note: <strong>PVS</strong> only reports<br />

on the first occurence of this item on a web server. Parse your entire web source for similar<br />

occurrences.<br />

'.log' File Detection<br />

CVE Not available<br />

<strong>PVS</strong> ID: 4664 FAMILY: Data Leakage RISK: INFO NESSUS ID:Not Available<br />

Description: The remote web server is hosting .log files. As an example, consider the following file<br />

%P\nDistributing such files over the web can be done, but the webmaster should make sure<br />

that they do not contain confidential data. '.log' files are typically log files that may contain<br />

information regarding local applications and settings.<br />

Solution: Ensure that confidential data is not present within the '.log' file. Note: <strong>PVS</strong> only reports on<br />

the first occurence of this item on a web server. Parse your entire web source for similar<br />

occurrences.<br />

'.conf' File Detection<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 4665 FAMILY: Data Leakage RISK: INFO NESSUS ID:Not Available<br />

Family Internet Services 1223

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!