27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVS pserver CVSROOT Passwd File Arbitrary Code Execution<br />

<strong>PVS</strong> ID: 1181 FAMILY: Generic RISK: HIGH NESSUS ID:11970<br />

Description: Synopsis :\n\nAn attacker may execute arbitrary commands on the remote system\n\nThe<br />

remote CVS server, according to its version number, might allow an attacker to execute<br />

arbitrary commands on the remote system as cvs does not drop root privileges properly.<br />

Solution: Upgrade to most recent version of CVS<br />

Witty Worm Detection<br />

CVE Not available<br />

<strong>PVS</strong> ID: 1182 FAMILY: Generic RISK: HIGH NESSUS ID:11214<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow\n\nThe remote host is<br />

vulnerable to a series of remote vulnerabilities to the ISS IDS engine. In addition, network<br />

traffic seems to indicate that the machine was compromised by a worm (Witty) which<br />

spreads via these ISS vulnerabilities.<br />

Solution: The Witty worm corrupts the victim's hard drive. The victim Operating System must be<br />

reinstalled.<br />

CVE-2004-0362<br />

Policy - iroffer Software Detection<br />

<strong>PVS</strong> ID: 1183 FAMILY: Backdoors RISK: INFO NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running client software which may be considered<br />

questionable\n\nThe remote system appears to have iroffer. This program allows the<br />

machine to be used as an IRC fileserver. Iroffer and such bots are most common in warez<br />

and illegal file transfer agents.<br />

Solution: Locate and eliminate the application serving this traffic.<br />

CVE Not available<br />

Policy - iroffer Software Detection<br />

<strong>PVS</strong> ID: 1184 FAMILY: Backdoors RISK: INFO NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running client software which may be considered<br />

questionable\n\nThe remote system appears to have iroffer. This program allows the<br />

machine to be used as an IRC fileserver. Iroffer and such bots are most common in warez<br />

and illegal file transfer agents.<br />

Solution: Locate and eliminate the application serving this traffic.<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 301

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!