Nessus
[Top] [All Lists]

Re: no rating of finding ms-sql-s has account sa with password sa

To: Nessus@list.nessus.org
Subject: Re: no rating of finding ms-sql-s has account sa with password sa
From: "George A. Theall" <theall@tenablesecurity.com>
Date: Wed, 06 Jun 2007 10:41:12 -0400
Cc:
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: Nessus@list.nessus.org
In-reply-to: <466662DD.2050501@xs4all.nl>
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
References: <466662DD.2050501@xs4all.nl>
Sender: nessus-bounces@list.nessus.org
User-agent: Thunderbird 2.0.0.0 (X11/20070326)
On 06/06/07 03:31, Oskar wrote:

|ms-sql-s (1433/tcp)|10862|Security Hole|The following accounts were
...
It has no rating, how come, as this particular finding allows me to take full control of everything on the SQL server with osql.exe.

Hi Oskar. I just committed a change so this plugin will use the new report format, with a CVSS score. Thanks for the heads up!


George
--
theall@tenablesecurity.com
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>