Nessus
[Top] [All Lists]

Re: Plugin ID : 10930 Question

To: Nessus <nessus@list.nessus.org>
Subject: Re: Plugin ID : 10930 Question
From: "George A. Theall" <theall@tenablesecurity.com>
Date: Wed, 22 Nov 2006 12:28:54 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: nessus@list.nessus.org
In-reply-to: <112020061455.16678.4561C1CD00043EAA0000412622058863609D0A9B0A03020E900006@comcast.net>
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
References: <112020061455.16678.4561C1CD00043EAA0000412622058863609D0A9B0A03020E900006@comcast.net>
Sender: nessus-bounces@list.nessus.org
User-agent: Thunderbird 1.5.0.8 (X11/20061110)
On Mon, Nov 20, 2006 at 02:55:09PM +0000, jfvanmeter@comcast.net wrote:

I have some concerns with a scan of a  Windows 2003 SP1 Server
running McAfee ePolicy Orchestrtor client 3.5.5.438 the version of
Nessus used is 3.0.3 Build W334 with plug ins update today (Nov 20).
...
It looks like plug in 10930 tries to enumerate a Apache < 2.0.44
CVE-2003-0016 - Apache before 2.0.44, when running on unpatched
Windows 9x and Me operating systems

Actually, that plugin doesn't look at any banners but tries to kill the host itself.

Can anyone show/point me to a way that I can verify this manually? I
believe this is a false postive, but I believe ePolicy Orchestrtor
using some version of Apache I would like to find out. The server
doesn't crash continuously

It probably is a false-positive given what you say about the target environment. Does the machine crash when you run it?

Also, are you able to re-run this plugin against EPO? If so, would you take a packet capture while doing it and send me privately the results. I'm interested only in packets going between that particular service and nessusd. [If using tcpdump, please specify "-s 0" to fully capture packets.]


George
--
theall@tenablesecurity.com
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>