Nessus
[Top] [All Lists]

Re: Plugin 13852

To: "nessus@list.nessus.org. List" <Nessus@list.nessus.org>
Subject: Re: Plugin 13852
From: Renaud Deraison <deraison@nessus.org>
Date: Wed, 7 Mar 2007 11:02:21 +0100
Cc:
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: nessus@list.nessus.org
In-reply-to: <9B71985304C4914AACE30A5BD6A08771351C3A@sumac.cfs.le.ac.uk>
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
References: <9B71985304C4914AACE30A5BD6A08771351C3A@sumac.cfs.le.ac.uk>
Sender: nessus-bounces@list.nessus.org

On Mar 5, 2007, at 12:45 PM, Nelson, C.M. wrote:

Plugin 13852 v1.16 (tests windows task scheduler vulnerability) has
reported positive on a fully patch XP SP2 system. The problem reports
against port 1025. If I scan all ports I get the report, however, if I
ask for a scan of only port 1025 then plugin 13852 does not report.

After further investigation with Nelson, it turns out this indeed was a real vulnerability.

Just a reminder though : a lot of the MSRPC checks need to connect to port 135 to obtain the port on which the remote service is running. Which means that if you perform while trying to disable port scanning, do NOT check the option 'consider unscanned ports as closed' as it will prevent nessusd from querying port 135.



                                        -- Renaud
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>
  • Plugin 13852, Nelson, C.M.
    • Re: Plugin 13852, Renaud Deraison <=