| List of hosts | ||
|
||
|
||
|
||
|
||
|
||
|
| 192.168.62.1 | ||||||||||||||||||||||
|
||||||||||||||||||||||
| Port general (0/udp) | [-/+] |
| Traceroute Information | |
|
Synopsis: It was possible to obtain traceroute information. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Nessus Scan Information | |
|
Synopsis: Information about the Nessus scan. Description: – The version of the plugin set Risk factor: Solution: Plugin output: Nessus version : 4.4.1 Plugin ID: |
|
| Open Port Re-check | |
|
Synopsis: Previously open ports are now closed. Description: There are numerous possible causes for this failure : This might be an availability problem related to the following reasons : In any case, the audit of the remote host might be incomplete and may Risk factor: Solution: Plugin output: Plugin ID: |
|
| OS Identification Failed | |
|
Synopsis: It was not possible to guess the remote operating system Description: Risk factor: Solution: Plugin output: HTTP:!:Server: Allegro-Software-RomPager/4.10 Plugin ID: |
|
| Ethernet Card Manufacturer Detection | |
|
Synopsis: The manufacturer can be deduced from the Ethernet OUI. Description: Risk factor: See also: See also: Solution: Plugin output: 00:10:a7:28:1c:a9 : UNEX TECHNOLOGY CORPORATION Plugin ID: |
|
| IP Forwarding Enabled | |
|
Synopsis: The remote host has IP forwarding enabled. Description: Unless the remote host is a router, it is recommended that you disable IP Risk factor: CVSS Base Score:3.2 Solution: echo 0 > /proc/sys/net/ipv4/ip_forward On Windows, set the key ‘IPEnableRouter’ to 0 under HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameter On Mac OS X, you can disable IP forwarding by executing the command : sysctl -w net.inet.ip.forwarding=0 For other systems, check with your vendor. Plugin ID: CVE: |
|
| ICMP Timestamp Request Remote Date Disclosure | |
|
Synopsis: It is possible to determine the exact time set on the remote host. Description: This may help an attacker to defeat all time-based authentication Risk factor: Solution: Plugin output: Plugin ID: CVE: Other references: |
|
| Port ssdp (1900/udp) | [-/+] |
| Universal Plug and Play (UPnP) Protocol Detection | |
|
Synopsis: The remote device supports UPnP. Description: Keep in mind that it could help an intruder discover your network Risk factor: See also: See also: See also: Solution: Plugin output: HTTP/1.1 200 OK Plugin ID: |
|
| Port dns (53/udp) | [-/+] |
| DNS Server Cache Snooping Remote Information Disclosure | |
|
Synopsis: The remote DNS server is vulnerable to cache snooping attacks. Description: This may allow a remote attacker to determine which domains have For instance, if an attacker was interested in whether your company Note: If this is an internal DNS server not accessable to outside Risk factor: CVSS Base Score:5.0 See also: Solution: Plugin output: 192.0.43.10 Plugin ID: |
|
| DNS Server DNSSEC Aware Resolver | |
|
Synopsis: The remote DNS resolver is DNSSEC-aware. Description: Risk factor: Solution: Plugin ID: |
|
| DNS Server Detection | |
|
Synopsis: A DNS server is listening on the remote host. Description: Risk factor: See also: Solution: Plugin ID: |
|
| Port bootps? (67/udp) | [-/+] |
| DHCP Server Detection | |
|
Synopsis: The remote DHCP server may expose information about the associated network. Description: Some DHCP servers provide sensitive information such as the NIS domain It does not demonstrate any vulnerability, but a local attacker may Risk factor: CVSS Base Score:3.3 Solution: Plugin output: Master DHCP server of this network : 0.0.0.0 Plugin ID: |
|
| Port tftp (69/udp) | [-/+] |
| TFTP Daemon Detection | |
|
Synopsis: A TFTP server is listening on the remote port. Description: Risk factor: Solution: Plugin ID: |
|
| Port www (80/tcp) | [-/+] |
| UPnP Internet Gateway Device (IGD) Port Mapping Manipulation | |
|
Synopsis: It was possible to add port redirections to the remote router. Description: Nessus was able to add ‘port mappings’ that redirect ports from the A malicious Flash animation could do the same. Risk factor: CVSS Base Score:4.8 See also: See also: Solution: Plugin ID: |
|
| Web Server Generic XSS | |
|
Synopsis: The remote web server is prone to cross-site scripting attacks. Description: Risk factor: CVSS Base Score:4.3 See also: Solution: Plugin output: /<script>cross_site_scripting.nasl</script>.asp The output was : HTTP/1.1 404 Not Found <body> Plugin ID: CVE: BID: Other references: |
|
| UPnP Internet Gateway Device (IGD) Protocol Detection | |
|
Synopsis: The remote device supports the IGD protocol. Description: IGD is dangerous as it allows a remote attacker to punch holes in your Risk factor: CVSS Base Score:4.8 See also: See also: Solution: Plugin ID: |
|
| UPnP Internet Gateway Device (IGD) External IP Address Reachable | |
|
Synopsis: It was possible to read the external IP addres of the remote router. Description: Nessus was able to get the external IP address of the device. Risk factor: See also: Solution: Plugin output: Plugin ID: |
|
| Web Server UPnP Detection | |
|
Synopsis: The remote web server provides UPnP information. Description: Risk factor: See also: Solution: Plugin output: deviceType:urn:schemas-upnp-org:device:InternetGatewayDevice:1 Plugin ID: |
|
| HTTP Server Type and Version | |
|
Synopsis: A web server is running on the remote host. Description: Risk factor: Solution: Plugin output: Allegro-Software-RomPager/4.10 Plugin ID: |
|
| HTTP Methods Allowed (per directory) | |
|
Synopsis: This plugin determines which HTTP methods are allowed on various CGI directories. Description: As this list may be incomplete, the plugin also tests – if ‘Thorough Note that the plugin output is only informational and does not Risk factor: Solution: Plugin output: – HTTP methods HEAD POST GET are allowed on : / Plugin ID: |
|
| Service Detection | |
|
Synopsis: The remote service could be identified. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Port www (8080/tcp) | [-/+] |
| Web Server Generic XSS | |
|
Synopsis: The remote web server is prone to cross-site scripting attacks. Description: Risk factor: CVSS Base Score:4.3 See also: Solution: Plugin output: /<script>cross_site_scripting.nasl</script>.asp The output was : HTTP/1.1 404 Not Found <body> Plugin ID: CVE: BID: Other references: |
|
| HTTP Server Type and Version | |
|
Synopsis: A web server is running on the remote host. Description: Risk factor: Solution: Plugin output: Allegro-Software-RomPager/4.10 Plugin ID: |
|
| HTTP Methods Allowed (per directory) | |
|
Synopsis: This plugin determines which HTTP methods are allowed on various CGI directories. Description: As this list may be incomplete, the plugin also tests – if ‘Thorough Note that the plugin output is only informational and does not Risk factor: Solution: Plugin output: – HTTP methods HEAD POST GET are allowed on : / Plugin ID: |
|
| Service Detection | |
|
Synopsis: The remote service could be identified. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| 192.168.62.2 | |||||||||||||||||||||||
|
|||||||||||||||||||||||
| Port general (0/udp) | [-/+] |
| Traceroute Information | |
|
Synopsis: It was possible to obtain traceroute information. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Nessus Scan Information | |
|
Synopsis: Information about the Nessus scan. Description: – The version of the plugin set Risk factor: Solution: Plugin output: Nessus version : 4.4.1 Plugin ID: |
|
| Wireless Access Point Detection | |
|
Synopsis: The remote host is a wireless access point. Description: Ensure that proper physical and logical controls are in place for its Risk factor: Solution: Plugin output: DD-WRT v Plugin ID: |
|
| Common Platform Enumeration (CPE) | |
|
Synopsis: It is possible to enumerate CPE names that matched on the remote system. Description: Note that if an official CPE is not available for the product, this Risk factor: See also: Solution: Plugin output: cpe:/o:linux:linux_kernel:2.4 Plugin ID: |
|
| Device Type | |
|
Synopsis: It is possible to guess the remote device type. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| OS Identification | |
|
Synopsis: It is possible to guess the remote operating system. Description: Risk factor: Solution: Plugin output: The remote host is running one of these operating systems : Plugin ID: |
|
| Ethernet Card Manufacturer Detection | |
|
Synopsis: The manufacturer can be deduced from the Ethernet OUI. Description: Risk factor: See also: See also: Solution: Plugin output: b0:48:7a:da:75:44 : TP-LINK TECHNOLOGIES CO., LTD. Plugin ID: |
|
| IP Forwarding Enabled | |
|
Synopsis: The remote host has IP forwarding enabled. Description: Unless the remote host is a router, it is recommended that you disable IP Risk factor: CVSS Base Score:3.2 Solution: echo 0 > /proc/sys/net/ipv4/ip_forward On Windows, set the key ‘IPEnableRouter’ to 0 under HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameter On Mac OS X, you can disable IP forwarding by executing the command : sysctl -w net.inet.ip.forwarding=0 For other systems, check with your vendor. Plugin ID: CVE: |
|
| TCP/IP Timestamps Supported | |
|
Synopsis: The remote service implements TCP timestamps. Description: Risk factor: See also: Solution: Plugin ID: |
|
| ICMP Timestamp Request Remote Date Disclosure | |
|
Synopsis: It is possible to determine the exact time set on the remote host. Description: This may help an attacker to defeat all time-based authentication Risk factor: Solution: Plugin output: Plugin ID: CVE: Other references: |
|
| Multiple Ethernet Driver Frame Padding Information Disclosure (Etherleak) | |
|
Synopsis: The remote host appears to leak memory in network packets. Description: Known as ‘Etherleak’, this information disclosure vulnerability may Risk factor: CVSS Base Score:3.3 See also: Solution: Plugin output: 0×00: 00 81 43 02 74 00 00 00 00 00 00 00 00 00 00 00 ..C.t……….. Padding observed in another frame : 0×00: 00 00 43 0A F4 00 00 00 00 00 00 00 00 00 00 00 ..C…………. Plugin ID: CVE: BID: Other references: |
|
| Port telnet (23/tcp) | [-/+] |
| Unencrypted Telnet Server | |
|
Synopsis: The remote Telnet server transmits traffic in cleartext. Description: Using Telnet over an unencrypted channel is not recommended as logins, Use of SSH is prefered nowadays as it protects credentials from Risk factor: CVSS Base Score:2.6 Solution: Plugin output: —————————— snip —————————— DD-WRT v24-sp2 std (c) 2010 NewMedia-NET GmbH Plugin ID: |
|
| Telnet Server Detection | |
|
Synopsis: A Telnet server is listening on the remote port. Description: Risk factor: Solution: Plugin output: —————————— snip —————————— DD-WRT v24-sp2 std (c) 2010 NewMedia-NET GmbH Plugin ID: |
|
| Service Detection | |
|
Synopsis: The remote service could be identified. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Port domain? (53/tcp) | [-/+] |
| Service Detection | |
|
Synopsis: The remote service could be identified. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Port www (80/tcp) | [-/+] |
| DD-WRT Info.live.htm Information Disclosure | |
|
Synopsis: The remote web server is affected by an information disclosure vulnerability. Description: Risk factor: CVSS Base Score:3.3 See also: See also: Solution: Plugin output: http://192.168.62.2/Info.live.htm Plugin ID: BID: Other references: |
|
| HyperText Transfer Protocol (HTTP) Information | |
|
Synopsis: Some information about the remote HTTP configuration can be extracted. Description: This test is informational only and does not denote any security Risk factor: Solution: Plugin output: Content-Type: text/html Plugin ID: |
|
| HTTP Server Type and Version | |
|
Synopsis: A web server is running on the remote host. Description: Risk factor: Solution: Plugin output: httpd Plugin ID: |
|
| Web Server No 404 Error Code Check | |
|
Synopsis: The remote web server does not return 404 error codes. Description: Nessus has enabled some counter measures for this. However, they Risk factor: Solution: Plugin output: Plugin ID: |
|
| Service Detection | |
|
Synopsis: The remote service could be identified. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| 192.168.62.3 | |||||||||||||||||||||||
|
|||||||||||||||||||||||
| Port general (0/udp) | [-/+] |
| Traceroute Information | |
|
Synopsis: It was possible to obtain traceroute information. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Nessus Scan Information | |
|
Synopsis: Information about the Nessus scan. Description: – The version of the plugin set Risk factor: Solution: Plugin output: Nessus version : 4.4.1 Plugin ID: |
|
| Common Platform Enumeration (CPE) | |
|
Synopsis: It is possible to enumerate CPE names that matched on the remote system. Description: Note that if an official CPE is not available for the product, this Risk factor: See also: Solution: Plugin output: cpe:/o:linux:linux_kernel:2.6 Following application CPE matched on the remote system : cpe:/a:isc:bind:dnsmasq:2 Plugin ID: |
|
| Device Type | |
|
Synopsis: It is possible to guess the remote device type. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| OS Identification | |
|
Synopsis: It is possible to guess the remote operating system. Description: Risk factor: Solution: Plugin output: Not all fingerprints could give a match – please email the following to os-signatures@nessus.org : The remote host is running Linux Kernel 2.6 Plugin ID: |
|
| Ethernet Card Manufacturer Detection | |
|
Synopsis: The manufacturer can be deduced from the Ethernet OUI. Description: Risk factor: See also: See also: Solution: Plugin output: 00:14:d1:4e:6a:c1 : TRENDnet Plugin ID: |
|
| TCP/IP Timestamps Supported | |
|
Synopsis: The remote service implements TCP timestamps. Description: Risk factor: See also: Solution: Plugin ID: |
|
| ICMP Timestamp Request Remote Date Disclosure | |
|
Synopsis: It is possible to determine the exact time set on the remote host. Description: This may help an attacker to defeat all time-based authentication Risk factor: Solution: Plugin output: Plugin ID: CVE: Other references: |
|
| Port ssdp (1900/udp) | [-/+] |
| Universal Plug and Play (UPnP) Protocol Detection | |
|
Synopsis: The remote device supports UPnP. Description: Keep in mind that it could help an intruder discover your network Risk factor: See also: See also: See also: Solution: Plugin output: HTTP/1.1 200 OK Plugin ID: |
|
| Port btx? (20005/tcp) | [-/+] |
| Port dns (53/tcp) | [-/+] |
| DNS Server BIND version Directive Remote Version Disclosure | |
|
Synopsis: It is possible to obtain the version number of the remote DNS server. Description: This version is not necessarily accurate and could even be forged, as Risk factor: Solution: Plugin output: dnsmasq-2.41 Plugin ID: Other references: |
|
| DNS Server Detection | |
|
Synopsis: A DNS server is listening on the remote host. Description: Risk factor: See also: Solution: Plugin ID: |
|
| DNS Server Detection | |
|
Synopsis: A DNS server is listening on the remote host. Description: Risk factor: See also: Solution: Plugin ID: |
|
| Port unknown (65535/tcp) | [-/+] |
| UPnP Internet Gateway Device (IGD) Port Mapping Manipulation | |
|
Synopsis: It was possible to add port redirections to the remote router. Description: Nessus was able to add ‘port mappings’ that redirect ports from the A malicious Flash animation could do the same. Risk factor: CVSS Base Score:4.8 See also: See also: Solution: Plugin ID: |
|
| UPnP Internet Gateway Device (IGD) Protocol Detection | |
|
Synopsis: The remote device supports the IGD protocol. Description: IGD is dangerous as it allows a remote attacker to punch holes in your Risk factor: CVSS Base Score:4.8 See also: See also: Solution: Plugin ID: |
|
| UPnP Internet Gateway Device (IGD) External IP Address Reachable | |
|
Synopsis: It was possible to read the external IP addres of the remote router. Description: Nessus was able to get the external IP address of the device. Risk factor: See also: Solution: Plugin output: Plugin ID: |
|
| Web Server UPnP Detection | |
|
Synopsis: The remote web server provides UPnP information. Description: Risk factor: See also: Solution: Plugin output: Plugin ID: |
|
| Port tftp (69/udp) | [-/+] |
| TFTP Traversal Arbitrary File Access | |
|
Synopsis: The remote TFTP server can be used to read arbitrary files on the remote host. Description: Risk factor: CVSS Base Score:5.0 Solution: Plugin output: root:x:0:0:root:/root:/bin/sh Plugin ID: CVE: BID: Other references: |
|
| TFTP Daemon Detection | |
|
Synopsis: A TFTP server is listening on the remote port. Description: Risk factor: Solution: Plugin ID: |
|
| Port www (80/tcp) | [-/+] |
| HNAP Detection | |
|
Synopsis: The remote device has HNAP enabled. Description: Risk factor: See also: See also: Solution: Plugin ID: |
|
| HTTP Server Type and Version | |
|
Synopsis: A web server is running on the remote host. Description: Risk factor: Solution: Plugin output: httpd Plugin ID: |
|
| Web Server No 404 Error Code Check | |
|
Synopsis: The remote web server does not return 404 error codes. Description: Nessus has enabled some counter measures for this. However, they Risk factor: Solution: Plugin output: Plugin ID: |
|
| Service Detection | |
|
Synopsis: The remote service could be identified. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| 192.168.62.56 | ||||||||||||||||||||||||
|
||||||||||||||||||||||||
| Port general (0/udp) | [-/+] |
| Traceroute Information | |
|
Synopsis: It was possible to obtain traceroute information. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Nessus Scan Information | |
|
Synopsis: Information about the Nessus scan. Description: – The version of the plugin set Risk factor: Solution: Plugin output: Nessus version : 4.4.1 Plugin ID: |
|
| Common Platform Enumeration (CPE) | |
|
Synopsis: It is possible to enumerate CPE names that matched on the remote system. Description: Note that if an official CPE is not available for the product, this Risk factor: See also: Solution: Plugin output: cpe:/o:apple:mac_os_x:10.7 Plugin ID: |
|
| Device Type | |
|
Synopsis: It is possible to guess the remote device type. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| OS Identification | |
|
Synopsis: It is possible to guess the remote operating system. Description: Risk factor: Solution: Plugin output: The remote host is running Mac OS X 10.7 Plugin ID: |
|
| Ethernet Card Manufacturer Detection | |
|
Synopsis: The manufacturer can be deduced from the Ethernet OUI. Description: Risk factor: See also: See also: Solution: Plugin output: d4:9a:20:d6:43:48 : Apple, Inc Plugin ID: |
|
| TCP/IP Timestamps Supported | |
|
Synopsis: The remote service implements TCP timestamps. Description: Risk factor: See also: Solution: Plugin ID: |
|
| Port ntp (123/udp) | [-/+] |
| Network Time Protocol (NTP) Server Detection | |
|
Synopsis: An NTP server is listening on the remote host. Description: Risk factor: Solution: Plugin ID: |
|
| Port netbios-ns (137/udp) | [-/+] |
| Windows NetBIOS / SMB Remote Host Information Disclosure | |
|
Synopsis: It is possible to obtain the network name of the remote host. Description: Note that this plugin gathers information to be used in other plugins Risk factor: Solution: Plugin output: MACBOOKPRO-4348 = Computer name The remote host has the following MAC address on its adapter : Plugin ID: |
|
| Port unknown (17500/tcp) | [-/+] |
| Dropbox Software Detection (uncredentialed check) | |
|
Synopsis: There is a file synchronization application on the remote host. Description: Risk factor: See also: Solution: Plugin output: Plugin ID: |
|
| Port mdns (5353/udp) | [-/+] |
| mDNS Detection | |
|
Synopsis: It is possible to obtain information about the remote host. Description: Risk factor: CVSS Base Score:5.0 Solution: Plugin output: – mDNS hostname : MacBookPro-de-Marc-Andre.local. – Advertised services : Plugin ID: |
|
| Port appleshare (548/tcp) | [-/+] |
| 192.168.62.68 | ||||||||||||||||||||||||
|
||||||||||||||||||||||||
| Port general (0/tcp) | [-/+] |
| Nessus Scan Information | |
|
Synopsis: Information about the Nessus scan. Description: – The version of the plugin set Risk factor: Solution: Plugin output: Nessus version : 4.4.1 Plugin ID: |
|
| Common Platform Enumeration (CPE) | |
|
Synopsis: It is possible to enumerate CPE names that matched on the remote system. Description: Note that if an official CPE is not available for the product, this Risk factor: See also: Solution: Plugin output: cpe:/o:apple:mac_os_x:10.7.2 Following application CPE matched on the remote system : cpe:/a:apple:itunes:10.5.3 Plugin ID: |
|
| Device Type | |
|
Synopsis: It is possible to guess the remote device type. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| OS Identification | |
|
Synopsis: It is possible to guess the remote operating system. Description: Risk factor: Solution: Plugin output: The remote host is running Mac OS X 10.7.2 Plugin ID: |
|
| Adobe Flash Player for Mac Installed | |
|
Synopsis: The remote Mac OS X host contains a browser enhancement for displaying multimedia content. Description: Risk factor: See also: Solution: Plugin output: Plugin ID: |
|
| Enumerate IPv4 Interfaces via SSH | |
|
Synopsis: This plugin enumerates IPv4 interfaces on a remote host. Description: Risk factor: Solution: Plugin output: – 127.0.0.1 (on interface lo0) Plugin ID: |
|
| Enumerate IPv6 Interfaces via SSH | |
|
Synopsis: This plugin enumerates IPv6 interfaces on a remote host. Description: Risk factor: Solution: Plugin output: – fe80::1 (on interface lo0) Plugin ID: |
|
| Time of Last System Startup | |
|
Synopsis: The system has been started. Description: Risk factor: Solution: Plugin output: wtmp begins Fri Jan 20 21:16 Plugin ID: |
|
| Dropbox Installed (Mac OS X) | |
|
Synopsis: There is a file synchronization application on the remote host. Description: Risk factor: See also: Solution: Plugin output: Plugin ID: |
|
| Device Hostname | |
|
Synopsis: It is possible to determine the remote system hostname. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Software Enumeration (SSH) | |
|
Synopsis: It is possible to enumerate installed software on the remote host, via SSH. Description: Risk factor: Solution: Plugin output: .SetupRegComplete Plugin ID: |
|
| Firewall Rule Enumeration | |
|
Synopsis: A firewall is configured on the remote host. Description: Risk factor: Solution: Plugin output: By running « ipfw list », Nessus was able to get the following list 65535 allow ip from any to any By running « /sbin/pfctl -s nat 2>/dev/null », Nessus was able to get the following list nat-anchor « com.apple/* » all By running « /sbin/pfctl -s rules 2>/dev/null », Nessus was able to get the following list anchor « com.apple/* » all Plugin ID: |
|
| Ethernet Card Manufacturer Detection | |
|
Synopsis: The manufacturer can be deduced from the Ethernet OUI. Description: Risk factor: See also: See also: Solution: Plugin output: 3c:07:54:09:e0:b1 : Apple, Inc. Plugin ID: |
|
| iTunes Version Detection (Mac OS X) | |
|
Synopsis: The remote Mac OS X host has a copy of iTunes installed. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Enumerate MAC Addresses via SSH | |
|
Synopsis: This plugin enumerates MAC addresses on a remote host. Description: Risk factor: Solution: Plugin output: – 3c:07:54:09:e0:b1 (interface en0) Plugin ID: |
|
| Authenticated Check: OS Name and Installed Package Enumeration | |
|
Synopsis: This plugin gathers information about the remote host via an authenticated session. Description: If using SSH, the scan should be configured with a valid SSH public Risk factor: Solution: Plugin output: Local security checks have been enabled for this host. Plugin ID: |
|
| Port ntp (123/udp) | [-/+] |
| Network Time Protocol (NTP) Server Detection | |
|
Synopsis: An NTP server is listening on the remote host. Description: Risk factor: Solution: Plugin ID: |
|
| Port nessus (1241/tcp) | [-/+] |
| SSL Certificate Cannot Be Trusted | |
|
Synopsis: The SSL certificate for this service cannot be trusted. Description: First, the top of the certificate chain sent by the server might not Second, the certificate chain may contain a certificate that is not Third, the certificate chain may contain a signature that either If the remote host is a public host in production, any break in the Risk factor: CVSS Base Score:6.4 Solution: Plugin output: |-Subject : O=Nessus Users United/OU=Nessus Certification Authority/L=New York/C=US/ST=NY/CN=Nessus Certification Authority Plugin ID: |
|
| SSL Self-Signed Certificate | |
|
Synopsis: The SSL certificate chain for this service ends in an unrecognized self-signed certificate. Description: Note that this plugin does not check for certificate chains that end Risk factor: CVSS Base Score:6.4 Solution: Plugin output: |-Subject : O=Nessus Users United/OU=Nessus Certification Authority/L=New York/C=US/ST=NY/CN=Nessus Certification Authority Plugin ID: |
|
| SSL Cipher Suites Supported | |
|
Synopsis: The remote service encrypts communications using SSL. Description: Risk factor: See also: Solution: Plugin output: High Strength Ciphers (>= 112-bit key) The fields above are : {OpenSSL ciphername} Plugin ID: |
|
| SSL Certificate Information | |
|
Synopsis: This plugin displays the SSL certificate. Description: Risk factor: Solution: Plugin output: Organization: Nessus Users United Issuer Name: Organization: Nessus Users United Serial Number: 00 A9 82 Version: 3 Signature Algorithm: SHA-1 With RSA Encryption Not Valid Before: Feb 01 14:22:09 2012 GMT Public Key Info: Algorithm: RSA Encryption Signature: 00 8B 6F 6A 84 75 5B ED 2D CC 0A B0 80 00 83 5B 52 C1 49 39 Extension: 2.16.840.1.113730.1.1 Extension: Key Usage (2.5.29.15) Plugin ID: |
|
| SSL / TLS Versions Supported | |
|
Synopsis: The remote service encrypts communications. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Nessus Server Detection | |
|
Synopsis: A Nessus daemon is listening on the remote port. Description: Also, make sure that the remote Nessus installation has been Risk factor: Solution: Plugin ID: |
|
| Service Detection | |
|
Synopsis: The remote service could be identified. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Port netbios-ns? (137/udp) | [-/+] |
| Port netbios-dgm? (138/udp) | [-/+] |
| Port unknown (17500/tcp) | [-/+] |
| Port unknown (49155/tcp) | [-/+] |
| Port unknown (51575/udp) | [-/+] |
| Port unknown (51847/udp) | [-/+] |
| Port mdns? (5353/udp) | [-/+] |
| Port appleshare (548/tcp) | [-/+] |
| Port unknown (55092/udp) | [-/+] |
| Port unknown (55652/udp) | [-/+] |
| Port unknown (63563/udp) | [-/+] |
| Port unknown (65535/udp) | [-/+] |
| Port kerberos? (88/tcp) | [-/+] |
| Kerberos Information Disclosure | |
|
Synopsis: The remote Kerberos server is leaking information. Description: Risk factor: Solution: Plugin output: Server time : 2012-02-01 14:49:53 UTC Plugin ID: |
|
| Port www (8834/tcp) | [-/+] |
| SSL Certificate Cannot Be Trusted | |
|
Synopsis: The SSL certificate for this service cannot be trusted. Description: First, the top of the certificate chain sent by the server might not Second, the certificate chain may contain a certificate that is not Third, the certificate chain may contain a signature that either If the remote host is a public host in production, any break in the Risk factor: CVSS Base Score:6.4 Solution: Plugin output: |-Subject : O=Nessus Users United/OU=Nessus Certification Authority/L=New York/C=US/ST=NY/CN=Nessus Certification Authority Plugin ID: |
|
| SSL Self-Signed Certificate | |
|
Synopsis: The SSL certificate chain for this service ends in an unrecognized self-signed certificate. Description: Note that this plugin does not check for certificate chains that end Risk factor: CVSS Base Score:6.4 Solution: Plugin output: |-Subject : O=Nessus Users United/OU=Nessus Certification Authority/L=New York/C=US/ST=NY/CN=Nessus Certification Authority Plugin ID: |
|
| SSL Cipher Suites Supported | |
|
Synopsis: The remote service encrypts communications using SSL. Description: Risk factor: See also: Solution: Plugin output: High Strength Ciphers (>= 112-bit key) The fields above are : {OpenSSL ciphername} Plugin ID: |
|
| SSL Certificate Information | |
|
Synopsis: This plugin displays the SSL certificate. Description: Risk factor: Solution: Plugin output: Organization: Nessus Users United Issuer Name: Organization: Nessus Users United Serial Number: 00 A9 82 Version: 3 Signature Algorithm: SHA-1 With RSA Encryption Not Valid Before: Feb 01 14:22:09 2012 GMT Public Key Info: Algorithm: RSA Encryption Signature: 00 8B 6F 6A 84 75 5B ED 2D CC 0A B0 80 00 83 5B 52 C1 49 39 Extension: 2.16.840.1.113730.1.1 Extension: Key Usage (2.5.29.15) Plugin ID: |
|
| HyperText Transfer Protocol (HTTP) Information | |
|
Synopsis: Some information about the remote HTTP configuration can be extracted. Description: This test is informational only and does not denote any security Risk factor: Solution: Plugin output: Date: Wed, 01 Feb 2012 14:50:22 GMT Plugin ID: |
|
| Web Server / Application favicon.ico Vendor Fingerprinting | |
|
Synopsis: The remote web server contains a graphic image that is prone to information disclosure. Description: Risk factor: Solution: Plugin output: Plugin ID: Other references: |
|
| HTTP Server Type and Version | |
|
Synopsis: A web server is running on the remote host. Description: Risk factor: Solution: Plugin output: NessusWWW Plugin ID: |
|
| SSL / TLS Versions Supported | |
|
Synopsis: The remote service encrypts communications. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Service Detection | |
|
Synopsis: The remote service could be identified. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Service Detection | |
|
Synopsis: The remote service could be identified. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| 192.168.62.75 | ||||||||||||||||||||||
|
||||||||||||||||||||||
| Port general (0/udp) | [-/+] |
| Traceroute Information | |
|
Synopsis: It was possible to obtain traceroute information. Description: Risk factor: Solution: Plugin output: Plugin ID: |
|
| Nessus Scan Information | |
|
Synopsis: Information about the Nessus scan. Description: – The version of the plugin set Risk factor: Solution: Plugin output: Nessus version : 4.4.1 Plugin ID: |
|
| Ethernet Card Manufacturer Detection | |
|
Synopsis: The manufacturer can be deduced from the Ethernet OUI. Description: Risk factor: See also: See also: Solution: Plugin output: 28:6a:ba:80:eb:49 : IEEE-SA Plugin ID: |
|
| Port mdns (5353/udp) | [-/+] |
| mDNS Detection | |
|
Synopsis: It is possible to obtain information about the remote host. Description: Risk factor: CVSS Base Score:5.0 Solution: Plugin output: – mDNS hostname : iPad-blanc-de-imusee.local. Plugin ID: |
|
