27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Trojan/Backdoor Detection - Conficker Detection<br />

<strong>PVS</strong> ID: 4977 FAMILY: Backdoors RISK: HIGH NESSUS ID:36036<br />

Description: Synopsis :\n\nThe remote host has been compromised and is running a 'backdoor'<br />

program.\n\nThe remote host seems to be infected by the Conficker worm. This worm has<br />

several capabilities that allow an attacker to execute arbitrary code on the remote operating<br />

system. The remote host might also be attempting to propagate the worm to third-party<br />

hosts.<br />

realtime<br />

Solution: Update your antivirus and perform a full scan of the remote operating system.<br />

CVE Not available<br />

Trojan/Backdoor Detection - Conficker Detection<br />

<strong>PVS</strong> ID: 4978 FAMILY: Backdoors RISK: HIGH NESSUS ID:36036<br />

Description: Synopsis :\n\nThe remote host has been compromised and is running a 'backdoor'<br />

program.\n\nThe remote host seems to be infected by the Conficker worm. This worm has<br />

several capabilities that allow an attacker to execute arbitrary code on the remote operating<br />

system. The remote host might also be attempting to propagate the worm to third-party<br />

hosts.<br />

realtime<br />

Solution: Update your antivirus and perform a full scan of the remote operating system.<br />

CVE Not available<br />

Serv-U < 8.0.0.1 Multiple Vulnerabilities (DoS, Traversal)<br />

<strong>PVS</strong> ID: 4979 FAMILY: FTP Servers RISK: HIGH NESSUS ID:36035<br />

Description: Synopsis : \n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running Serv-U File Server, an FTP server for Windows. The reported version is: \n %L<br />

\n\nThis version of Serv-U is earlier than 8.0.0.1 and is reportedly affected by the following<br />

issues : \n\n - A directory traversal vulnerability enables an authenticated remote attacker to<br />

create directories outside his or her home directory. (CVE-2009-1031)\n\n - An<br />

authenticated remote attacker can cause the FTP service to become saturated for a long<br />

period of time using a long series of 'SMNT' commands without an argument. During this<br />

time, new connections would not be allowed. (CVE-2009-0967)<br />

Solution: Upgrade to version 8.0.0.1 or higher.<br />

CVE-2009-1031<br />

Firefox < 3.0.8 Multiple Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1315

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!