27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: The remote host is a Checkpoint Firewall version AI R55.<br />

Solution: Ensure that the firewall is configured in a manner consistent with corporate and security<br />

policies.<br />

CVE Not available<br />

Trojan/Backdoor - JS.Scob.Trojan/Download.Ject Detection<br />

<strong>PVS</strong> ID: 1229 FAMILY: Backdoors RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host has a backdoor installed\n\nThe remote web server is<br />

infected with JS.Scob.Trojan or Download.Ject Trojan. This Trojan installs malicious code<br />

on all web pages and infects clients as they browse the server. Specifically, the Trojan's<br />

dropper sets it as the document footer for all pages served.<br />

Solution: Stop the IIS server and use an Antivirus product to remove the Trojan. Consider<br />

re-installing the operating system.<br />

CVE Not available<br />

Policy - GATOR Software Detection<br />

<strong>PVS</strong> ID: 1230 FAMILY: Backdoors<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11998<br />

Description: Synopsis :\n\nThe remote host is running client software which may be considered<br />

questionable\n\nThe remote host is using the GATOR program. You should ensure that the<br />

user intended to install GATOR (it is sometimes silently installed) and that the use of<br />

GATOR matches your corporate mandates and security policies.<br />

Solution: Uninstall the program manually.<br />

CVE Not available<br />

Policy - ALEXA Software Detection<br />

<strong>PVS</strong> ID: 1231 FAMILY: Backdoors RISK: INFO NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running client software which may be considered<br />

questionable\n\nThe remote host is using the ALEXA program. This software is bundled by<br />

default with Internet Explorer 6. This software transmits the complete URL of the search<br />

results to both 'msn.com' and 'alexa.com', thus potentially violating the privacy of the<br />

remote user. You should ensure that the user intended to install ALEXA and that the use of<br />

ALEXA matches your corporate mandates and security policies.<br />

Solution: Remove the software manually.<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 313

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!