27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Solution: No solution is known at this time.<br />

CVE-2005-0291<br />

Ocean12 ASP Calendar Administrative Interface Access<br />

<strong>PVS</strong> ID: 2540 FAMILY: Web Servers RISK: HIGH NESSUS ID:15974<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows for the bypassing of<br />

authentication.\n\nThe remote host is running Ocean12 ASP Calendar, a web<br />

based\napplication written in ASP.\n\nThere is a flaw in the remote software that may<br />

allow anyone\nto execute admnistrative commands on the remote host by requesting\nthe<br />

page /admin/main.asp.\n\nAn attacker may exploit this flaw to deface the remote site<br />

without\nany credentials.\n<br />

Solution: No solution is known at this time.<br />

CVE-2004-1400<br />

Microsoft Anti-Spyware Detection<br />

<strong>PVS</strong> ID: 2541 FAMILY: Generic RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host passes information across the network in an insecure<br />

manner.\n\nThe remote host is running the Microsoft Anti-Spyware tool. Further, the<br />

administrators have not disabled the default 'Spyware Community' feature. The Spyware<br />

Community feature allows Microsoft to centrally track information regarding infected files,<br />

versions, locations, and more. When a file is flagged as being spyware, the remote host will<br />

automatically send this information (via the Internet) to Microsoft servers.<br />

Solution: Ensure that the 'Spyware Community' feature is in alignment with corporate policies and<br />

procedures.<br />

Tor Tunnel Detection<br />

CVE Not available<br />

<strong>PVS</strong> ID: 2542 FAMILY: Backdoors<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: The remote client just started a Tor tunnel for routing network traffic over the Tor Tunnel<br />

network. The Tor tunnel allows users to run applications such as peer-to-peer clients,<br />

instant messaging and web browsers over a single encrypted tunnel. Tor also tunnels and<br />

encrypts the DNS requests associated with such applications. By sending traffic over the<br />

Tor network, users can bypass corporate policies, firewalls, and guidelines.<br />

Solution: Ensure that the usage of the Tor network is in alignment with corporate polices and<br />

guidelines.<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 647

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!