· 8 years ago · Nov 09, 2017, 02:44 AM
1
2<html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></meta><title>Nessus Scan Report</title><style type="text/css" media="all">
3 UL.ulist {padding: 0 10px; line-height:25px; margin-bottom:0px; margin-top:0px;};
4 LI.list {padding: 0 10px; line-height:25px; margin-bottom:0px; margin-top:0px; list-style: disc;}
5 LI.list0 {padding: 0 10px; line-height:25px; margin-bottom:0px; margin-top:0px; list-style: disc; color:#357abd;}
6 LI.list1 {padding: 0 10px; line-height:25px; margin-bottom:0px; margin-top:0px; list-style: disc; color:#4cae4c;}
7 LI.list2 {padding: 0 10px; line-height:25px; margin-bottom:0px; margin-top:0px; list-style: disc; color:#fdc431;}
8 LI.list3 {padding: 0 10px; line-height:25px; margin-bottom:0px; margin-top:0px; list-style: disc; color:#ee9336;}
9 LI.list4 {padding: 0 10px; line-height:25px; margin-bottom:0px; margin-top:0px; list-style: disc; color:#d43f3a;}
10
11 html, body, div, span, applet, object, iframe, h1, h2, h3, h4, h5, h6, p, blockquote, pre, a, abbr, acronym, address, big, cite, code, del, dfn, em, img, ins, kbd, q, s, samp, small, strike, strong, sub, sup, tt, var, b, u, i, center, dl, dt, dd, ol, ul, li, fieldset, form, label, legend, table, caption, tbody, tfoot, thead, tr, th, td, article, aside, canvas, details, embed, figure, figcaption, footer, header, hgroup, menu, nav, output, ruby, section, summary, time, mark, audio, video {
12 margin: 0;
13 padding: 0;
14 border: 0;
15 font-size: 100%;
16 font: inherit;
17 vertical-align: baseline;
18 -webkit-text-size-adjust: none;
19 }
20
21 html, body {
22 font-family: helvetica, arial, sans-serif;
23 width: 100%;
24 color: #263645;
25 font-size: 12px;
26 background: #efefef;
27 }
28
29 a, a:visited, a:active {
30 color: #004a97;
31 }
32
33 a:hover {
34 color: #00253d;
35 }
36
37 .container_16 {
38 margin: 0 auto;
39 padding: 0 14px 14px 14px;
40 background: #fff;
41 border-top: #425363 solid 7px;
42 box-shadow: 0 2px 10px rgba(0, 0, 0, .2);
43 margin-bottom: 20px;
44 border-radius: 0 0 5px 5px;
45 }
46
47 #reportContent {
48 width: 100%;
49 }
50
51 h1.classtitle {
52 padding: 15px 0 10px 0;
53 border-bottom: 1px dotted #ccc;
54 margin: 0 0 15px 0;
55 }
56
57 h2.classtitle {
58 color: #00a5b5;
59 font-weight: normal;
60 font-size: 22px;
61 margin: 0;
62 padding: 0;
63 }
64
65 h2.date {
66 font-size: 14px;
67 color: #768591;
68 margin: 0;
69 padding: 0;
70 font-weight: normal;
71 }
72
73 .reportinfo {
74 display: block;
75 width: 100%;
76 font-size: 16px;
77 padding: 0 0 15px 0;
78 margin: 0 0 5px 0;
79 font-weight: normal;
80 border-bottom: 1px dotted #ccc;
81 }
82
83 .reportpadding {
84 padding: 15px 0 0 0 !important;
85 }
86
87 .classtoc {
88 display: block;
89 font-size: 18px;
90 color: #777779;
91 padding: 15px 0;
92 margin: 15px 0 0 0;
93 }
94
95 h1.classchapter {
96 background: #425363;
97 color: #fff;
98 font-weight: bold;
99 font-size: 16px;
100 padding: 6px 10px;
101 margin: 10px 0 0 0;
102 border-radius: 4px 4px 0 0;
103 }
104
105 h2.classsection {
106 display: block;
107 background: #425363;
108 color: #fff;
109 font-weight: bold;
110 font-size: 14px;
111 padding: 6px 10px;
112 margin: 30px 0 0 0;
113 border-radius: 4px 4px 0 0;
114 }
115
116 h2.classh1 {
117 display: block;
118 background: #efefef;
119 font-weight: bold;
120 font-size: 13px;
121 padding: 6px 10px;
122 }
123
124 .classtext {
125 font-size: 13px;
126 line-height: 18px;
127 }
128
129 div#reportContent div span.classtext {
130 padding: 6px 10px;
131 display: inline-block;
132 }
133
134 h2.classsubsection {
135 background: #768591;
136 color: #fff;
137 font-weight: bold;
138 font-size: 13px;
139 padding: 6px 10px;
140 }
141
142 .classheader h1 {
143 color: #fff;
144 font-weight: bold;
145 font-size: 15px;
146 padding: 0 10px;
147 text-align: center;
148 }
149
150 .reportinfo b {
151 font-weight: bold;
152 }
153
154 h3.classtitle {
155 color: #69737b;
156 font-size: 16px;
157 padding: 0 10px;
158 }
159
160 .classsection_sub tr, td {
161 color: #053958;
162 font-size: 13px;
163 padding: 0 10px;
164 }
165
166 td {
167 padding: 6px 10px;
168 }
169
170 h2.classsection, h2.classsection0, h2.classsection1, h2.classsection2, h2.classsection3, h2.classsection4 {
171 background: #053958;
172 color: #fff;
173 font-weight: bold;
174 font-size: 13px;
175 padding: 6px 10px;
176 margin-bottom: 0px;
177 margin-top: 10px;
178 }
179
180 .classcell4, h2.classsection4 {
181 background-color: #d43f3a;
182 }
183
184 .classcell3, h2.classsection3 {
185 background-color: #ee9336;
186 }
187
188 .classcell2, h2.classsection2 {
189 background-color: #fdc431;
190 }
191
192 .classcell1, h2.classsection1 {
193 background-color: #4cae4c;
194 }
195
196 .classcell0, h2.classsection0 {
197 background-color: #357abd;
198 }
199
200
201 #copyright {
202 display: block;
203 width: 100%;
204 text-align: center;
205 font-size: 12px;
206 color: #A9A8A9;
207 padding: 6px 0 20px 0;
208 }
209
210 #copyright a, #copyright a:visited, #copyright a:active {
211 color: #A9A8A9;
212 }
213
214 div.icon {
215 display: none;
216 }
217
218 .nopadding {
219 padding: 0 !important;
220 }
221
222 body.email h2.classh1 {
223 display: block;
224 margin: 20px 0 0 0;
225 background: #425363;
226 color: #fff;
227 font-weight: bold;
228 font-size: 14px;
229 padding: 6px 10px;
230 border-radius: 4px 4px 0 0;
231 }
232
233 body.email div#reportContent div span.classtext {
234 padding: 0;
235 display: inline;
236 }
237
238 body.email h2.tips {
239 background: #004a97 !important;
240 }
241
242 body.email h2.errors {
243 background: #c00 !important;
244 }
245
246 body.email h2.classsection {
247 display: none;
248 }
249
250 .classtoc1 a {
251 font-size: 16px;
252 }
253
254 .classtoc2 a {
255 font-size: 13px;
256 padding: 0 20px;
257 }
258
259 h2.classh2 {
260 background: #f8f8f8;
261 font-weight: bold;
262 font-size: 13px;
263 padding: 6px 10px;
264 }
265
266 .classpre {
267 display: block;
268 font-size: 13px;
269 font-family: Courier New, Courier, monospace;
270 padding: 10px;
271 color: #000;
272 }
273
274 .classh1_grey h2 {
275 background: #eaeaea;
276 color:#053958;
277 font-size: 13px;
278 padding: 0 10px;
279 margin-top:0px;
280 margin-bottom:2px;
281 }
282
283 @media only screen and (max-device-width: 480px) {
284 html, body {
285 display: block;
286 min-width: 480px;
287 background: #fff;
288 }
289
290 table {
291 table-layout: auto !important;
292 }
293
294 table td {
295 word-wrap: break-word;
296 }
297
298 table.container_16 {
299 width: 100%;
300 padding: 0 4% 20px 4%;
301 background: #fff;
302 border-top: #425363 solid 7px;
303 box-shadow: none !important;
304 margin-bottom: 20px;
305 border-radius: 0;
306 }
307
308 #copyright {
309 display: block;
310 width: 90%;
311 text-align: center;
312 font-size: 10px;
313 color: #A9A8A9;
314 padding: 5px 0 20px 0;
315 border-top: 1px dotted #ccc;
316 margin: 0 auto;
317 line-height: 16px;
318 }
319
320 .classtitle img {
321 display: block;
322 margin: 0 auto;
323 }
324 }
325</style><script type="text/javascript">
326 function toggle(divId) {
327 var divObj = document.getElementById(divId);
328 if (divObj) {
329 var displayType = divObj.style.display;
330 if (displayType == "" || displayType == "block") {
331 divObj.style.display = "none";
332 } else {
333 divObj.style.display = "block";
334 }
335 }
336 }
337
338 function ceall(flag) {
339 var divs = document.getElementsByTagName("div");
340 var i = 0;
341 for (i = 0; i < divs.length; i++) {
342 if (divs[i].getAttribute("id") != null && divs[i].getAttribute("id").match('btag-')) {
343 if (flag == 0) {
344 divs[i].style.display = "none";
345 } else {
346 divs[i].style.display = "block";
347 }
348 }
349 }
350 }
351 </script></head><body class=""><table cellpadding="0" cellspacing="0" border="0" width="100%"><tr><td align="center" valign="top" class="nopadding" style="vertical-align: top"><table cellpadding="0" cellspacing="0" border="0" width="80%" bgcolor="#FFFFFF" class="container_16"><tr><td><table xmlns="" cellpadding="0" cellspacing="0" border="0" width="100%">
352<tr><td class="nopadding"><h1 class="classtitle"><img src="data:image/gif;base64,R0lGODlh9wBEAPcAAAAAAP///z1QXwCktff3+O7v8cfM0d7h5N3g49zf4trd4Ors7ujq7Ofp6+Tm6Pf4+fX29/T19vP09fDx8pGbpJ2mrkFTYkNVZEtcak1ebE9gblJjcVVlclhodVpqd1lpdl5ue2h2gmt5hW17h3aDjnWCjXSBjHmGkXeEj4GNl4WRm4uWn4qVnoiTnJGcpY+ao46Zoo2YoaqyuamxuKiwt7a9w7S7wbO6wLi/xbe+xMTKz8LIzcHHzD5RYD9SYUJVY0VYZkVXZUdZZ0haaFFib1NkcVZndFtrd11teWJyfmJxfWFwfGRzf2d2gmZ1gWV0gGl4g299iG58h3KAi3F/inB+iXOBjHiFj3yJk3uIknqHkX+Mln6LlYSQmYmVnoiUnYeTnIaSm4uXoJiiqpagqJqkrKavtqWutaSttKOss621u7G5v6+3vc7T183S1szR1cvQ1MnO0tjc39fb3tba3dXZ3NTY29vf4tre4dnd4E5gbZSfp5OeppKdpZCbo6Grsp+psJ6or6u0ur7FyrzDyLvCx7rBxrnAxefq7OXo6uPm6OLl5+Hk5uDj5dLX2tHW2c/U1/Hz9O/x8uzu7/r9/vf8/fX7/Of2+On3+QGktQKltgSltgemtwmnuA+puRGquhSruxesvBqtvSCvviOwvy20wjC1wzK2xDW3xTq4xj26x0G7yE/AzFLBzVXCzljDz1rEz1/G0WDG0WvK1G3L1XTN13fO2HvQ2X/R2oXT3IfU3IrV3Y3W3pvb4qrg5q/i6LXl6sbr78vs8NPv8tXw89jx9Nvy9eL19/H6+/P7/AWmtgintwuouAyouBasuxmtvBuuvR2uvSSxvyaywCqzwTi4xUO8yEW9yUq+ymTI0mjJ02/M1XHN1njP2IHS2oTT25HY35ba4Z/d46Tf5afg5a7i57Hj6LPk6bnm6rvn67/o7MHp7cns783t8M/u8d3z9d/09uz4+e75+uX29+r4+fn9/fz+/v7///3+/vv8/Pr7+/n6+vj5+fb39/39/f///yH5BAEAAP8ALAAAAAD3AEQAAAj/AAMIHEiwoMGDCBMqXMiwocOHECNKnEixosWLGDNq3Mixo8ePIEOKHEmypMmTKFOqXMkSI6ZhwtS5K2YpJB4BOHM+yQdRQs6cO1oKHfpxnrhspjgNWMp0AChr3YDV43jzJ04yPa0KCEq0q1eE83TJsuXuoLxpTdOqZeYK3b2MVbXGeejTKteveL0CY9b020F6pNQKbkoqHKWLca1mKOCw7s+7eSOzvNRMLbqDxXadcwdP3rxi6nrNMpVJMClfFhNbpYKvoWOgkmOv3CWY1cRL4U7VvkRRtdU0rrVClk18ZDbBpSwKY6X202WJvn/6sMPwNc7hxbN7vCV4FcZguptq/+IFXatVDpEWWt+qvf1Hd6XThlN4DhcsVvhleTMXr6C9b8qktc1bD0VnFRbqCefeghXp0k5BuKSFjT0KHSdYJqmAgwxB64CSFjcQGWjVGgqth11BkeiQhgti8CFDG/s8FEEcZowhhguAFKJIQ/7csUYgL8BAhhqPxHiSP3isUUGQQxb50T3f0CIPQeZYMwoq4BwWQD24kPKMLJgM9Msp11iTCjRr1dKfQPAE1hQ4BWqVgVYXHJCQiQnFYUUP5gEBxiILxVEFn+ZxUMYCCC3QBwbmCXBBFnG0RtAYQ1RaKQILiWDpEBwYtIALjJr3KByScoTONOIQiFAsTVEz1UHInP8zi4dMfSLOQMe4uZQm6Tjk2yGh/oQEPwjhaZADUjQqHRn6HBTBCcr+ZAEf/RRkAxDR5uQEHQS5YBUeCy3x0xDWYputAE7M4RE8p6RCDELHqEXOQvWMgxZT2GwYgDGfNAUKPQ351gYP5rFQrIIFGSDEuTmJEEFBEYjLME5GgCuQGRPj5MMfknr7k8UJSYwTuQNhnPHGpWpUTzabdFNTQeqo5Q1ByMAzDDwUDmQPL50wNc0xAqWjSVOuBKxVGwGIYd4gBxk7kAEWZIxTCEYKlILUVwkECaEZ61FtAB7nBDJCIgtAcgCQYC2ABl93JA4zowBT0DzxMYVaAPKIIh4126z/QyAx9w5ACtAB2JLWOQwJHAA/SGg1RCIGOR3AAUFY1UMJa7gxhwF/lI3TCgMloFUJOkziTyQKsEEF1xo8HAAUVm0gAyMPPNDADjAEK0AOA4WN09gHlX12CLHPXvvtuf+EQ0jDoNXKPARp05QprxqDyiuxtGJKgEtR48tb8qDCFDUb1kNNqzknpHgACfygVQg8EeR0PkpYdUQdB/EwhFWPCDSGVYBASCNIgBPeBYABVgFBegzCDzNgKwSl8p0AgGcQ4QkEgT9R4EH4cYbKQSFlHkHGKwbQDHDkzB67KIU0ZjElhFjiHK2IzzWAhozwDMA2AQBGWm6lkPUFQA3mGUNB/5x2A6t4QBIJSUDlciIFgZjgJ0QAYUFmAEGBGMAqPFAIIz4gh259K1zjEogO7KKQRnxAAR55RyoGgApjCCQcSjmFMCYyjFUsJRTsCMA8nsEUHlqjKcnp4dEGgo8raKUHcJAfwvDxgZ/0IA8LYYNVMMWEnySBIQQYSA2sgj+FPKAgEqRgQSwYgE3+pJMJ+aRH/riUVAykHYHRxCz0BREoLcUTeUQHUzwxJV02ZR2CtArSBjIBImhFD4wRiLEeYRUuMCQfG/hJGQJABasU4iEE+4kJXOeQUIIxJyQbhFVKwM2T9GspnKBZK5bijHFMJBzsBBosmAKiewRuALII5k+GOf8QN3AtJ1OQlLH+9xMdNMR3TwjAHrQyghs0gCGJOGYZHtEshnhTIaR0gEQpehJsMMU7BLkHLzaxFGu4MSLeWMoq7gEP7jFjQ99oyifSZxAfDoSgVjmDMhGWrJ8scCE4+MkP8qEAZXGgC2uwE0KIZ54gUCEQcMgkQi4asjAKxAmNAsJT4aDKkBzjGp6wBuEKsg4+DoATvFBVQ/ChiqW4k1VLgRMx0qIO9Q2yIPloglYsgD9jGXNcmwrsppaYEwcEoAXnIkIMUDmQOkQtWj+gQg6IBcovYtSqAbCDD7L1gylMtiWYuAa+APYQ+AjOHsFgSjUEEo2+2FWYB0nEwqxihAj/GMt9atNK//SRhYmNAFMEIQRus6UBNaSMqmTDbACEyzANrEGKJsHHN0g6AGjM8SEeHQAw8GHWTPDGFU3Bxmv3iZBCmIcLxsqteYaJjxtogGE/sEFBGDGFiVlBqmCzbFXBOd8q2LerGHnHmhwyDPENYBnudEg5lhKLAMxzKb8IAG2YAo3x5oSfBlGBeUz2GIGYS70XJog+DoECwjaqBwYwSB4oUIRzoaBj+k0uf1XM4nOdYCPiiEYwIIKPcNBKFw6xBElFEQBwMOUWAfCFeLRU07sepB+NtMpjOxyAKOeEEG3Ispa3zOUtS+Ag+3DDH0ywv0LFzyCMsAEYPKAsriA3/3jKRfMNwmBlrRg0IyndhkTkwY1lDGBADTHFUi6hw6XAIgCpbQo8EGJTg8xhym0WiCEL+hF/0GEMc7JKihcyiRvAziokEIgEu3jZGTOk05/+yRU0so0BzIyQNC1GWQ5yiVl0YhYNWecAgtGOjwbAHWmZdZNhqxAORzoAaLBKCkQCAS1YZZoOKQSkSSbBRJZ6ZBExBKQxoBFauJog8NDEvAQSC1woJB676NVC4CoTpqgiAPAINqOdjBB8VDNaXGGElBlBEXxAd4iQDoNA/l2QLlilWRIkUUL8YQTlEpwgV/vJmS1yHHMPJN69GEgskIyREQ4gHcBeCioCMNdfzpvYCv8pQKYbdZdUT42yCqlD1QRiAyzgt97DFQAMAhAJEHBrIX2QTmtwipMSJAQfSsNsz3+uEApI6+EPqcWfCXKJAeRiINs4NEbaOoB2+HIA1wjAOtLyroM0GiFXPHYA4DC6nxoEH4L4AR8IUgBGecANChnjT9BwWAFYoAIwN4g+OvCTTgWABggryCRK4LiBgMHvgQh8QfTR8JwYHiO5GEDRdLaJfAoEHIG0CD48sRRkwJPBSU4Lb8xOb4UEneUEwYJWOFCDig6kHzkAAU56wM8t/CQKO5i4QNywcpzQIW050UAaJmEQSTj7JyoQyBv2SgZGtCYfc9jDh63qhp8on/kFkQT/tH4CBo2MYwChF8g0Qs+OTEDPIuxYyjQCYKEBADmlTNEETQlydoToo37mARmRQHhaEQRTwAJ94AVQkHMCwAEPk3ZWIQQlMAY0QAMukARa0QT7wGZakQQrgAYyUAFacAFaQWoPYGJCNQSbpSzksg91tntJIAYgWAEnQIJWgUYZEX+b8CoCAQuZsCb2AArkYRGtNnWjwBSXoWvdY2E4gWELwQgoeB0F4QAcoDYXAAmZpTsTEwR3wA+ThjV9QBBONzFNQIDYxg8okFt7sBHIMDTANBC9MAAZJxCzQAr7BxHyQHpdNwxMwQmWcA+h0BSvwIQC4IQLYQMBaBCT0FMTcwTq/yIQiDACUgMEcxEA/pAGkHYuKuAP8mOG0cIFD0BKl5iJ2bKJHCFoHCcQmKAJriQQxpAJcEIR3jYArlSEAyBevdYUQ8h6KOcQXJB4BNFe0ZQtRDADtjdwg+A5jRIF/EYQidAFpHhM8mUQiKCMP7EB1xQApCQQDgCN56IH08gRrTZ/BOFROyYQ2cAMxTAR6jA0A7AO8aCHA4Aa3NEUw5AQn+IC+qiPhtUTfLCP+ghcB6EPg8AFeqAVHwAGOiB8BVEHZPAEmegDSkABTGcQBcAGKFB8OEEEWVADkkcQ+bAGIpBzQVACh2B7ZgCQQlQQF5mRWsGRHvkRMTMAeTQQ5zAAqv9AIPHwDNNAWg9hDLSSDQEgdUvxDPVgD2jCFNEQG5FwB5BQB40AYDzCAArQBnmQCDPHEJGAAHZgB4yQTA6xD4tQB3XgAFC3EFvpCF4JliARhAOgdQJxD4LGQwGgDspADYvmEO2gNwNgCpbgDtQ1AHByk00BIgxymO1hOJqQlwIRM81wUgEwDprwCXejEPYADn4mOMeQDOezFNJQD/dQDWmxjh6hD3iARCeRCM24EP2AB22DmCBxDEMziAQhCwMwDS0UAOdQGaqwXQdRL6WgWpdgD8zBFHX1C2nxbh/RAAIgAyhxAkuQEDAAApnUBoUYABGABBQgEBHgmrCpEQ/2hgL/kQzSwEY++Q5cBwqwwAu+8AvkoAutII/KcAv1QAkPthTdEADJcIRNUVfL2ZzPGZ0IgQIY8GXWiTQTMARZIBA7cJ3fGWABQgrJQBDF0C/SUHYBcA+/YGCDwQmx4EbyYEf4QiGzyBTWEBLM6ZwnAZ1HV1EHKhD6ICkNaogPOhFECZcCwQ6kxwzhkDLEoAusIA3N0AygYAqyIA4tBAx8qVI1sWDi8SALYQAq8FCEBAM0gGx8NxBwoAKflKICgQZoIAl7kARH4AVu1wgtgAQg0AI7IhCMoAKMoANTkEX4cAhW4AEgIAaIIhDQKQnTCQJ8MAEDcQNrGAAvGgAxcE0VEAUC/2AFKqAAKnBnA6EGLCB8+TADUGAEUJAGbYMPOUAFH9AEgKBK/lADoAoCMQCWYDoBY5AEHtACghoAD6ACcGAHW+ABTzADBTEIVvABIfAHXVUIMaAPf5BQC2EJbrILBbGXS3EK56BWCSEM2cUUrVAT7sAXTZGfENUDKyl9AlADATACI0AQMiAAX+al4WoEGoACY5CGWvA0F8AEZoAGSwAEjiAQ1okCkYV3W2ABXfAHLfADRQABfFoEG0AFY4AFPdABC6QChneoQ+ACAdAHWAUFJ1AAHXBJA0EAQrBsBeEHFhADazAGGiACA/eLIlAGLRAET8CJV/ADKvAH0PgBlDUCRv9ABCQwBtASagHgE0+AASxABmxmCAMBAz2QAmpABkPwBF/jAkAABUSAAg2xDu44hwNxCSI6ANLwDe4ArWwCDmvUFJvwDW8BlGlBDZXgECagB2fGBRjwSeJKruYaAOg6AkCAhZL2A8qEAVfAiQGgD1XwAa1hnU+wpwGQA3cwEOKUjSdgAZIqTn4gEA6Lrw4asQzqoIhHagFQRP1TEEEQhsqEt2sgAFnKPkQbAGuwmofAHuEaBG8wEFrgAzzhs6gZCUHgseIUjg4wBCvpLXtwjAvBC7syH8EYDud0S6oAC7SwDdlwDWaVFqgwa+6QlLUCmQwxRkwTAAVgAaAbtwNRruf/CqDhOq4D8QcC8DCSpFQCUQfXaZ2vK2J3cAD5EAniy6IEMQJ6ILkPW7kSGwAzKhCR8AMGIxBJAAIHoQdO0KYEoQRH8G/7cAeN4A/MqQYC4b1fOrc+oaICAQI3FgBSgAQFsQcZIGpCEBH3AFcDwA1MJhDxcAvHOxhNcQrfIxDngK1MoQzP4RD4wAFRIBBpIABtasEBAL50K75CTMQs0AMUAJBKQ8GHKhCDwCgYkAGIp6L2OxBlMLeTa6j8e7n8pAJAQLByIABscBCDgC0eAAPUIRA+EAMIQQj7gwEaYL4qesQYLL4CsQQdPAQfAJAuwKiM4QJn8xDEqVrvYBCVMA6u/yCPaiEN3FCTAWAJJZp/4wYRP2yWRkAFA2HH4VvH5CsQRIxYfqyPc/HEC/ADI8AYBaBhViygA1EBAiCoWwyx/fu/6ysAJMICQkCwBzEBa4AF+yOx/tADL3AQDmABViCoCyB7niy3X5bBBKHHAhEEfTzK6SHIE1EP4LUUnZALaft2xeAL4IALuOANvYAOPknD5ZkWypBgEbG9ZMB2WVTBIeDMRdzM3zu3ydYICPHEhCAAnduz9evKfCoErTHLXey/DioQSpAEERAEO7cQ+uAFAsAAAXAExloQRQRJAlG3nzzEd6zB2tjBT2DAUzXIPMYNTfEMvDChPAYMXJcWnyCeEv+RAhlAAhtwZlcwBPGTD87WyRX80UTMABaQBaUSCW36xASzadpbv0OwmnLgA1ugv5Q7TJar0Hg3qAKAWOqbMH4bAARjJ+abvQGwAPdqCAKAtwGwCEYs1CEdzR1crtkoEHgQP9hcEeRQGUzRDNmADjyYEMPgDeusFqhwyBXBTAIQQAORbCWQAzIAAtEE1ONrzyAdBYPwBmawAQjCxfwEARrwAXCwAG8gAvWbAXqwB4YQCJXSpght1f07xicgA49IAPvz0XT3A09wA5CQA0aABK2xD01gAWJgCGZABB9wOhgAAm2wAHDwBG1tz9A8ENIcAPkQBT7gAnGgAzDwA4Qgaij/LRHvIFppwQzXUAvjgA7uMAzuEAzv6QrUqxbK8A13KBEooATgB6NhEAQ9gAQ1cAhLQLCTsASn+wVfQBCG8N9PEwJRYwRjwMtzsASPKBCNIAU9YAFR4AYCLhB9wAV5IAUWYAFTkACvbHQB8OCPKAJmMHApYAFAQNYwIADdjRB5kAULAwRYcN8EMAbRBARbsKd4AAUVPgUGkOEBQOAGjuAQQOQCwQWg+7eAQHgWEAIxHgBmYLIYQQ66AsNaTq2GLRIMSRFffhD58HD+cJYIIXwnoAfAO5AJ8eVhjhFvnhH2IA6CtuWDoQywcF01KhQJ0APQtuccwQ6zwJ92ngmqwAurSQfoLAEJTyAEG/Bliu4RxCAaqiCktVIK2NAN55DOkb4SciAGf8CWnT7qpF7qpn7qqJ7qqr7qrN7qrv7qsB7rsj7rtF7rtj4QAQEAOw==" width="247" height="68" border="0" alt="Nessus Report" style="display: block;"></h1></td></tr>
353<tr><td class="nopadding"><h2 class="classtitle">Nessus Scan Report</h2></td></tr>
354<tr><td class="nopadding"><h2 class="date">Sun, 05 Nov 2017 13:49:24 EST</h2></td></tr>
355<tr><td class="reportpadding"><div class="reportinfo"></div></td></tr>
356</table>
357<div id="reportContent"><span xmlns="" class="classtoc">Table Of Contents</span><table xmlns="">
358<tr><td><span class="classtoc1"><a href="#idm108222592">Vulnerabilities By Plugin</a></span></td></tr>
359<tr><td><table>
360<tr>
361<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell4"></td></tr></table></td>
362<td width="95%"><a href="#idm108223488">10203 (1) - rexecd Service Detection</a></td>
363</tr>
364<tr>
365<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell4"></td></tr></table></td>
366<td width="95%"><a href="#idm132923008">32321 (1) - Debian OpenSSH/OpenSSL Package Random Number Generator Weakness (SSL check)</a></td>
367</tr>
368<tr>
369<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell4"></td></tr></table></td>
370<td width="95%"><a href="#idm108351872">33850 (1) - Unix Operating System Unsupported Version Detection</a></td>
371</tr>
372<tr>
373<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell4"></td></tr></table></td>
374<td width="95%"><a href="#idm108324224">51988 (1) - Rogue Shell Backdoor Detection</a></td>
375</tr>
376<tr>
377<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell4"></td></tr></table></td>
378<td width="95%"><a href="#idm105322752">61708 (1) - VNC Server 'password' Password</a></td>
379</tr>
380<tr>
381<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell3"></td></tr></table></td>
382<td width="95%"><a href="#idm108186624">10205 (1) - rlogin Service Detection</a></td>
383</tr>
384<tr>
385<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell3"></td></tr></table></td>
386<td width="95%"><a href="#idm105520896">10245 (1) - rsh Service Detection</a></td>
387</tr>
388<tr>
389<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell3"></td></tr></table></td>
390<td width="95%"><a href="#idm105509376">34460 (1) - Unsupported Web Server Detection</a></td>
391</tr>
392<tr>
393<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
394<td width="95%"><a href="#idm132905600">11213 (1) - HTTP TRACE / TRACK Methods Allowed</a></td>
395</tr>
396<tr>
397<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
398<td width="95%"><a href="#idm132176896">11356 (1) - NFS Exported Share Information Disclosure</a></td>
399</tr>
400<tr>
401<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
402<td width="95%"><a href="#idm132144000">15901 (1) - SSL Certificate Expiry</a></td>
403</tr>
404<tr>
405<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
406<td width="95%"><a href="#idm133597568">20007 (1) - SSL Version 2 and 3 Protocol Detection</a></td>
407</tr>
408<tr>
409<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
410<td width="95%"><a href="#idm133575936">26928 (1) - SSL Weak Cipher Suites Supported</a></td>
411</tr>
412<tr>
413<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
414<td width="95%"><a href="#idm134191104">42256 (1) - NFS Shares World Readable</a></td>
415</tr>
416<tr>
417<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
418<td width="95%"><a href="#idm134179072">42263 (1) - Unencrypted Telnet Server</a></td>
419</tr>
420<tr>
421<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
422<td width="95%"><a href="#idm134165632">42873 (1) - SSL Medium Strength Cipher Suites Supported</a></td>
423</tr>
424<tr>
425<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
426<td width="95%"><a href="#idm132307456">45411 (1) - SSL Certificate with Wrong Hostname</a></td>
427</tr>
428<tr>
429<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
430<td width="95%"><a href="#idm132297344">51192 (1) - SSL Certificate Cannot Be Trusted</a></td>
431</tr>
432<tr>
433<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
434<td width="95%"><a href="#idm132276992">52611 (1) - SMTP Service STARTTLS Plaintext Command Injection</a></td>
435</tr>
436<tr>
437<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
438<td width="95%"><a href="#idm132876800">57582 (1) - SSL Self-Signed Certificate</a></td>
439</tr>
440<tr>
441<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
442<td width="95%"><a href="#idm132855552">57608 (1) - SMB Signing Disabled</a></td>
443</tr>
444<tr>
445<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
446<td width="95%"><a href="#idm132841472">57792 (1) - Apache HTTP Server httpOnly Cookie Information Disclosure</a></td>
447</tr>
448<tr>
449<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
450<td width="95%"><a href="#idm132807040">78479 (1) - SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)</a></td>
451</tr>
452<tr>
453<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
454<td width="95%"><a href="#idm132776320">81606 (1) - SSL/TLS EXPORT_RSA <= 512-bit Cipher Suites Supported (FREAK)</a></td>
455</tr>
456<tr>
457<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
458<td width="95%"><a href="#idp1317248">89058 (1) - SSL DROWN Attack Vulnerability (Decrypting RSA with Obsolete and Weakened eNcryption)</a></td>
459</tr>
460<tr>
461<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
462<td width="95%"><a href="#idm132742272">90317 (1) - SSH Weak Algorithms Supported</a></td>
463</tr>
464<tr>
465<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
466<td width="95%"><a href="#idm132730496">90509 (1) - Samba Badlock Vulnerability</a></td>
467</tr>
468<tr>
469<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell2"></td></tr></table></td>
470<td width="95%"><a href="#idm132696448">94437 (1) - SSL 64-bit Block Size Cipher Suites Supported (SWEET32)</a></td>
471</tr>
472<tr>
473<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell1"></td></tr></table></td>
474<td width="95%"><a href="#idm132654336">10407 (1) - X Server Detection</a></td>
475</tr>
476<tr>
477<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell1"></td></tr></table></td>
478<td width="95%"><a href="#idm132646400">31705 (1) - SSL Anonymous Cipher Suites Supported</a></td>
479</tr>
480<tr>
481<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell1"></td></tr></table></td>
482<td width="95%"><a href="#idm132610944">65821 (1) - SSL RC4 Cipher Suites Supported (Bar Mitzvah)</a></td>
483</tr>
484<tr>
485<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell1"></td></tr></table></td>
486<td width="95%"><a href="#idm134265088">70658 (1) - SSH Server CBC Mode Ciphers Enabled</a></td>
487</tr>
488<tr>
489<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell1"></td></tr></table></td>
490<td width="95%"><a href="#idm134229504">71049 (1) - SSH Weak MAC Algorithms Enabled</a></td>
491</tr>
492<tr>
493<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell1"></td></tr></table></td>
494<td width="95%"><a href="#idm134218240">83738 (1) - SSL/TLS EXPORT_DHE <= 512-bit Export Cipher Suites Supported (Logjam)</a></td>
495</tr>
496<tr>
497<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell1"></td></tr></table></td>
498<td width="95%"><a href="#idm132572416">83875 (1) - SSL/TLS Diffie-Hellman Modulus <= 1024 Bits (Logjam)</a></td>
499</tr>
500<tr>
501<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
502<td width="95%"><a href="#idm132547200">11219 (25) - Nessus SYN scanner</a></td>
503</tr>
504<tr>
505<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
506<td width="95%"><a href="#idm132514560">11111 (10) - RPC Services Enumeration</a></td>
507</tr>
508<tr>
509<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
510<td width="95%"><a href="#idm132497280">22964 (10) - Service Detection</a></td>
511</tr>
512<tr>
513<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
514<td width="95%"><a href="#idm132474752">10092 (2) - FTP Server Detection</a></td>
515</tr>
516<tr>
517<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
518<td width="95%"><a href="#idm132465920">10107 (2) - HTTP Server Type and Version</a></td>
519</tr>
520<tr>
521<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
522<td width="95%"><a href="#idm132456960">11002 (2) - DNS Server Detection</a></td>
523</tr>
524<tr>
525<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
526<td width="95%"><a href="#idm132448768">11011 (2) - Microsoft Windows SMB Service Detection</a></td>
527</tr>
528<tr>
529<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
530<td width="95%"><a href="#idm132428800">24260 (2) - HyperText Transfer Protocol (HTTP) Information</a></td>
531</tr>
532<tr>
533<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
534<td width="95%"><a href="#idm132414592">10028 (1) - DNS Server BIND version Directive Remote Version Detection</a></td>
535</tr>
536<tr>
537<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
538<td width="95%"><a href="#idm132397184">10114 (1) - ICMP Timestamp Request Remote Date Disclosure</a></td>
539</tr>
540<tr>
541<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
542<td width="95%"><a href="#idm132385280">10150 (1) - Windows NetBIOS / SMB Remote Host Information Disclosure</a></td>
543</tr>
544<tr>
545<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
546<td width="95%"><a href="#idm132371840">10223 (1) - RPC portmapper Service Detection</a></td>
547</tr>
548<tr>
549<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
550<td width="95%"><a href="#idm132355072">10263 (1) - SMTP Server Detection</a></td>
551</tr>
552<tr>
553<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
554<td width="95%"><a href="#idm132347520">10267 (1) - SSH Server Type and Version Information</a></td>
555</tr>
556<tr>
557<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
558<td width="95%"><a href="#idm132340736">10281 (1) - Telnet Server Detection</a></td>
559</tr>
560<tr>
561<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
562<td width="95%"><a href="#idm132321408">10287 (1) - Traceroute Information</a></td>
563</tr>
564<tr>
565<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
566<td width="95%"><a href="#idm131752960">10342 (1) - VNC Software Detection</a></td>
567</tr>
568<tr>
569<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
570<td width="95%"><a href="#idm131744128">10394 (1) - Microsoft Windows SMB Log In Possible</a></td>
571</tr>
572<tr>
573<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
574<td width="95%"><a href="#idm131733888">10397 (1) - Microsoft Windows SMB LanMan Pipe Server Listing Disclosure</a></td>
575</tr>
576<tr>
577<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
578<td width="95%"><a href="#idm131712384">10437 (1) - NFS Share Export List</a></td>
579</tr>
580<tr>
581<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
582<td width="95%"><a href="#idm131699840">10719 (1) - MySQL Server Detection</a></td>
583</tr>
584<tr>
585<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
586<td width="95%"><a href="#idm131690752">10785 (1) - Microsoft Windows SMB NativeLanManager Remote System Information Disclosure</a></td>
587</tr>
588<tr>
589<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
590<td width="95%"><a href="#idm131675776">10863 (1) - SSL Certificate Information</a></td>
591</tr>
592<tr>
593<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
594<td width="95%"><a href="#idm131654784">10881 (1) - SSH Protocol Versions Supported</a></td>
595</tr>
596<tr>
597<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
598<td width="95%"><a href="#idm131643392">11153 (1) - Service Detection (HELP Request)</a></td>
599</tr>
600<tr>
601<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
602<td width="95%"><a href="#idm131632768">11154 (1) - Unknown Service Detection: Banner Retrieval</a></td>
603</tr>
604<tr>
605<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
606<td width="95%"><a href="#idm131588608">11156 (1) - IRC Daemon Version Detection</a></td>
607</tr>
608<tr>
609<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
610<td width="95%"><a href="#idm131582208">11422 (1) - Web Server Unconfigured - Default Install Page Present</a></td>
611</tr>
612<tr>
613<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
614<td width="95%"><a href="#idm131565312">11424 (1) - WebDAV Detection</a></td>
615</tr>
616<tr>
617<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
618<td width="95%"><a href="#idm131554688">11819 (1) - TFTP Daemon Detection</a></td>
619</tr>
620<tr>
621<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
622<td width="95%"><a href="#idm131549056">11936 (1) - OS Identification</a></td>
623</tr>
624<tr>
625<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
626<td width="95%"><a href="#idm131524480">18261 (1) - Apache Banner Linux Distribution Disclosure</a></td>
627</tr>
628<tr>
629<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
630<td width="95%"><a href="#idm131517440">19288 (1) - VNC Server Security Type Detection</a></td>
631</tr>
632<tr>
633<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
634<td width="95%"><a href="#idm131511040">19506 (1) - Nessus Scan Information</a></td>
635</tr>
636<tr>
637<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
638<td width="95%"><a href="#idm131495168">20094 (1) - VMware Virtual Machine Detection</a></td>
639</tr>
640<tr>
641<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
642<td width="95%"><a href="#idm131480448">20108 (1) - Web Server / Application favicon.ico Vendor Fingerprinting</a></td>
643</tr>
644<tr>
645<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
646<td width="95%"><a href="#idm131471488">21186 (1) - AJP Connector Detection</a></td>
647</tr>
648<tr>
649<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
650<td width="95%"><a href="#idm131437440">21643 (1) - SSL Cipher Suites Supported</a></td>
651</tr>
652<tr>
653<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
654<td width="95%"><a href="#idm131392256">22227 (1) - RMI Registry Detection</a></td>
655</tr>
656<tr>
657<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
658<td width="95%"><a href="#idm131383424">25220 (1) - TCP/IP Timestamps Supported</a></td>
659</tr>
660<tr>
661<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
662<td width="95%"><a href="#idm131376000">25240 (1) - Samba Server Detection</a></td>
663</tr>
664<tr>
665<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
666<td width="95%"><a href="#idm131368448">26024 (1) - PostgreSQL Server Detection</a></td>
667</tr>
668<tr>
669<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
670<td width="95%"><a href="#idm131352704">35371 (1) - DNS Server hostname.bind Map Hostname Disclosure</a></td>
671</tr>
672<tr>
673<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
674<td width="95%"><a href="#idm131345664">35716 (1) - Ethernet Card Manufacturer Detection</a></td>
675</tr>
676<tr>
677<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
678<td width="95%"><a href="#idm131331456">39446 (1) - Apache Tomcat Default Error Page Version Detection</a></td>
679</tr>
680<tr>
681<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
682<td width="95%"><a href="#idm131312640">39519 (1) - Backported Security Patch Detection (FTP)</a></td>
683</tr>
684<tr>
685<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
686<td width="95%"><a href="#idm131291008">39520 (1) - Backported Security Patch Detection (SSH)</a></td>
687</tr>
688<tr>
689<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
690<td width="95%"><a href="#idm131269376">39521 (1) - Backported Security Patch Detection (WWW)</a></td>
691</tr>
692<tr>
693<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
694<td width="95%"><a href="#idm131255936">42088 (1) - SMTP Service STARTTLS Command Support</a></td>
695</tr>
696<tr>
697<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
698<td width="95%"><a href="#idm131219840">45410 (1) - SSL Certificate 'commonName' Mismatch</a></td>
699</tr>
700<tr>
701<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
702<td width="95%"><a href="#idm131211776">45590 (1) - Common Platform Enumeration (CPE)</a></td>
703</tr>
704<tr>
705<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
706<td width="95%"><a href="#idm131195008">48243 (1) - PHP Version Detection</a></td>
707</tr>
708<tr>
709<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
710<td width="95%"><a href="#idm131187840">50845 (1) - OpenSSL Detection</a></td>
711</tr>
712<tr>
713<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
714<td width="95%"><a href="#idm131179648">51891 (1) - SSL Session Resume Supported</a></td>
715</tr>
716<tr>
717<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
718<td width="95%"><a href="#idm131164928">52703 (1) - vsftpd Detection</a></td>
719</tr>
720<tr>
721<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
722<td width="95%"><a href="#idm131156352">53335 (1) - RPC portmapper (TCP)</a></td>
723</tr>
724<tr>
725<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
726<td width="95%"><a href="#idm131145984">54615 (1) - Device Type</a></td>
727</tr>
728<tr>
729<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
730<td width="95%"><a href="#idm131131264">56984 (1) - SSL / TLS Versions Supported</a></td>
731</tr>
732<tr>
733<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
734<td width="95%"><a href="#idm131124608">57041 (1) - SSL Perfect Forward Secrecy Cipher Suites Supported</a></td>
735</tr>
736<tr>
737<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
738<td width="95%"><a href="#idm131099776">62563 (1) - SSL Compression Methods Supported</a></td>
739</tr>
740<tr>
741<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
742<td width="95%"><a href="#idm131087232">65792 (1) - VNC Server Unencrypted Communication Detection</a></td>
743</tr>
744<tr>
745<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
746<td width="95%"><a href="#idm131079936">66334 (1) - Patch Report</a></td>
747</tr>
748<tr>
749<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
750<td width="95%"><a href="#idm131066240">70544 (1) - SSL Cipher Block Chaining Cipher Suites Supported</a></td>
751</tr>
752<tr>
753<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
754<td width="95%"><a href="#idm131029120">70657 (1) - SSH Algorithms and Languages Supported</a></td>
755</tr>
756<tr>
757<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
758<td width="95%"><a href="#idm130999168">72779 (1) - DNS Server Version Detection</a></td>
759</tr>
760<tr>
761<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
762<td width="95%"><a href="#idm130991488">84574 (1) - Backported Security Patch Detection (PHP)</a></td>
763</tr>
764<tr>
765<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
766<td width="95%"><a href="#idm130973952">96982 (1) - Server Message Block (SMB) Protocol Version 1 Enabled (uncredentialed check)</a></td>
767</tr>
768<tr>
769<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding classcell0"></td></tr></table></td>
770<td width="95%"><a href="#idm130954624">100871 (1) - Microsoft Windows SMB Versions Supported (remote check)</a></td>
771</tr>
772</table></td></tr>
773<tr><td><span class="classtoc1"><a href="#idm130947328">Remediations</a></span></td></tr>
774<tr><td><table><tr>
775<td width="5%"><table style="table-layout: fixed;" width="10px" height="10px"><tr><td class="nopadding "></td></tr></table></td>
776<td width="95%"><a href="#idm130947072">Suggested Remediations</a></td>
777</tr></table></td></tr>
778</table>
779<h1 xmlns="" class="classchapter" id="idm108222592">Vulnerabilities By Plugin</h1>
780<table xmlns="">
781<tr width="100%" onclick="ceall(0)" onmouseover="this.style.cursor='pointer'" title="Collapse"><td align="left" width="100%">[-] Collapse All</td></tr>
782<tr width="100%" onclick="ceall(1)" onmouseover="this.style.cursor='pointer'" title="Expand"><td align="left" width="100%">[+] Expand All</td></tr>
783</table>
784<h2 xmlns="" class="classsection4" id="idm108223488">10203 (1) - rexecd Service Detection</h2>
785<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
786 <![endif]]]-->Synopsis</h2>
787<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The rexecd service is running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
788 <![endif]]]-->Description</h2>
789<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The rexecd service is running on the remote host. This service is design to allow users of a network to execute commands remotely.<br>However, rexecd does not provide any good means of authentication, so it may be abused by an attacker to scan a third-party host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
790 <![endif]]]-->Solution</h2>
791<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Comment out the 'exec' line in /etc/inetd.conf and restart the inetd process.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
792 <![endif]]]-->Risk Factor</h2>
793<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Critical</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
794 <![endif]]]-->CVSS Base Score</h2>
795<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
796 <![endif]]]-->References</h2>
797<table xmlns="" width="100%">
798<tr>
799<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
800<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0618" target="_blank">CVE-1999-0618</a>
801</td>
802</tr>
803<tr>
804<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
805<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:9721</span></td>
806</tr>
807</table>
808<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
809 <![endif]]]-->Plugin Information: </h2>
810<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/08/31, Modification date: 2016/01/05</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
811 <![endif]]]-->Hosts</h2>
812<h2 xmlns="" class="classh2" style="color: #d43f3a">192.168.189.131 (tcp/512)</h2>
813<h2 xmlns="" class="classsection4" id="idm132923008">32321 (1) - Debian OpenSSH/OpenSSL Package Random Number Generator Weakness (SSL check)</h2>
814<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
815 <![endif]]]-->Synopsis</h2>
816<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote SSL certificate uses a weak key.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
817 <![endif]]]-->Description</h2>
818<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote x509 certificate on the remote SSL server has been generated on a Debian or Ubuntu system which contains a bug in the random number generator of its OpenSSL library. <br> <br>The problem is due to a Debian packager removing nearly all sources of entropy in the remote version of OpenSSL. <br> <br>An attacker can easily obtain the private part of the remote key and use this to decipher the remote session or set up a man in the middle attack.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
819 <![endif]]]-->See Also</h2>
820<table xmlns="" width="100%">
821<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?5d01bdab" target="_blank">http://www.nessus.org/u?5d01bdab</a>
822</td></tr>
823<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?f14f4224" target="_blank">http://www.nessus.org/u?f14f4224</a>
824</td></tr>
825</table>
826<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
827 <![endif]]]-->Solution</h2>
828<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Consider all cryptographic material generated on the remote host to be guessable. In particuliar, all SSH, SSL and OpenVPN key material should be re-generated.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
829 <![endif]]]-->Risk Factor</h2>
830<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Critical</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
831 <![endif]]]-->CVSS Base Score</h2>
832<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
833 <![endif]]]-->CVSS Temporal Score</h2>
834<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">8.3 (CVSS2#E:F/RL:OF/RC:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
835 <![endif]]]-->References</h2>
836<table xmlns="" width="100%">
837<tr>
838<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
839<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/29179" target="_blank">29179</a>
840</td>
841</tr>
842<tr>
843<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
844<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0166" target="_blank">CVE-2008-0166</a>
845</td>
846</tr>
847<tr>
848<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
849<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:45029</span></td>
850</tr>
851<tr>
852<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
853<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:45503</span></td>
854</tr>
855<tr>
856<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
857<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/310" target="_blank">CWE:310</a>
858</td>
859</tr>
860</table>
861<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
862 <![endif]]]-->Exploitable with</h2>
863<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Core Impact (true)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
864 <![endif]]]-->Plugin Information: </h2>
865<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2008/05/15, Modification date: 2015/10/07</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
866 <![endif]]]-->Hosts</h2>
867<h2 xmlns="" class="classh2" style="color: #d43f3a">192.168.189.131 (tcp/25)</h2>
868<h2 xmlns="" class="classsection4" id="idm108351872">33850 (1) - Unix Operating System Unsupported Version Detection</h2>
869<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
870 <![endif]]]-->Synopsis</h2>
871<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The operating system running on the remote host is no longer supported.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
872 <![endif]]]-->Description</h2>
873<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">According to its self-reported version number, the Unix operating system running on the remote host is no longer supported.<br> <br>Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
874 <![endif]]]-->Solution</h2>
875<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Upgrade to a version of the Unix operating system that is currently supported.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
876 <![endif]]]-->Risk Factor</h2>
877<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Critical</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
878 <![endif]]]-->CVSS v3.0 Base Score</h2>
879<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
880 <![endif]]]-->CVSS Base Score</h2>
881<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
882 <![endif]]]-->Plugin Information: </h2>
883<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2008/08/08, Modification date: 2017/07/10</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
884 <![endif]]]-->Hosts</h2>
885<h2 xmlns="" class="classh2" style="color: #d43f3a">192.168.189.131 (tcp/0)</h2>
886<span xmlns="" class="classpre"> <br>Ubuntu 8.04 support ended on 2011-05-12 (Desktop) / 2013-05-09 (Server).<br>Upgrade to Ubuntu 16.04 LTS.<br> <br>For more information, see : https://wiki.ubuntu.com/Releases<br> </span><h2 xmlns="" class="classsection4" id="idm108324224">51988 (1) - Rogue Shell Backdoor Detection</h2>
887<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
888 <![endif]]]-->Synopsis</h2>
889<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host may have been compromised.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
890 <![endif]]]-->Description</h2>
891<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A shell is listening on the remote port without any authentication being required. An attacker may use it by connecting to the remote port and sending commands directly.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
892 <![endif]]]-->Solution</h2>
893<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Verify if the remote host has been compromised, and reinstall the system if necessary.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
894 <![endif]]]-->Risk Factor</h2>
895<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Critical</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
896 <![endif]]]-->CVSS Base Score</h2>
897<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
898 <![endif]]]-->Plugin Information: </h2>
899<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2011/02/15, Modification date: 2016/06/08</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
900 <![endif]]]-->Hosts</h2>
901<h2 xmlns="" class="classh2" style="color: #d43f3a">192.168.189.131 (tcp/1524)</h2>
902<span xmlns="" class="classpre"> <br>Nessus was able to execute the command "id" using the<br>following request :<br> <br> <br> <br>This produced the following truncated output (limited to 10 lines) :<br>------------------------------ snip ------------------------------<br>root@metasploitable:/# uid=0(root) gid=0(root) groups=0(root)<br>root@metasploitable:/#<br> <br>------------------------------ snip ------------------------------</span><h2 xmlns="" class="classsection4" id="idm105322752">61708 (1) - VNC Server 'password' Password</h2>
903<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
904 <![endif]]]-->Synopsis</h2>
905<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A VNC server running on the remote host is secured with a weak password.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
906 <![endif]]]-->Description</h2>
907<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The VNC server running on the remote host is secured with a weak password. Nessus was able to login using VNC authentication and a password of 'password'. A remote, unauthenticated attacker could exploit this to take control of the system.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
908 <![endif]]]-->Solution</h2>
909<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Secure the VNC service with a strong password.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
910 <![endif]]]-->Risk Factor</h2>
911<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Critical</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
912 <![endif]]]-->CVSS Base Score</h2>
913<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
914 <![endif]]]-->Plugin Information: </h2>
915<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2012/08/29, Modification date: 2015/09/24</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
916 <![endif]]]-->Hosts</h2>
917<h2 xmlns="" class="classh2" style="color: #d43f3a">192.168.189.131 (tcp/5900)</h2>
918<span xmlns="" class="classpre"> <br>Nessus logged in using a password of "password".</span><h2 xmlns="" class="classsection3" id="idm108186624">10205 (1) - rlogin Service Detection</h2>
919<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
920 <![endif]]]-->Synopsis</h2>
921<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The rlogin service is running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
922 <![endif]]]-->Description</h2>
923<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The rlogin service is running on the remote host. This service is vulnerable since data is passed between the rlogin client and server in cleartext. A man-in-the-middle attacker can exploit this to sniff logins and passwords. Also, it may allow poorly authenticated logins without passwords. If the host is vulnerable to TCP sequence number guessing (from any network) or IP spoofing (including ARP hijacking on a local network) then it may be possible to bypass authentication.<br>Finally, rlogin is an easy way to turn file-write access into full logins through the .rhosts or rhosts.equiv files.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
924 <![endif]]]-->Solution</h2>
925<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Comment out the 'login' line in /etc/inetd.conf and restart the inetd process. Alternatively, disable this service and use SSH instead.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
926 <![endif]]]-->Risk Factor</h2>
927<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">High</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
928 <![endif]]]-->CVSS Base Score</h2>
929<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
930 <![endif]]]-->References</h2>
931<table xmlns="" width="100%">
932<tr>
933<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
934<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0651" target="_blank">CVE-1999-0651</a>
935</td>
936</tr>
937<tr>
938<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
939<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:193</span></td>
940</tr>
941</table>
942<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
943 <![endif]]]-->Exploitable with</h2>
944<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Metasploit (true)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
945 <![endif]]]-->Plugin Information: </h2>
946<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/08/30, Modification date: 2016/01/05</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
947 <![endif]]]-->Hosts</h2>
948<h2 xmlns="" class="classh2" style="color: #ee9336">192.168.189.131 (tcp/513)</h2>
949<h2 xmlns="" class="classsection3" id="idm105520896">10245 (1) - rsh Service Detection</h2>
950<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
951 <![endif]]]-->Synopsis</h2>
952<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The rsh service is running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
953 <![endif]]]-->Description</h2>
954<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The rsh service is running on the remote host. This service is vulnerable since data is passed between the rsh client and server in cleartext. A man-in-the-middle attacker can exploit this to sniff logins and passwords. Also, it may allow poorly authenticated logins without passwords. If the host is vulnerable to TCP sequence number guessing (from any network) or IP spoofing (including ARP hijacking on a local network) then it may be possible to bypass authentication.<br>Finally, rsh is an easy way to turn file-write access into full logins through the .rhosts or rhosts.equiv files.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
955 <![endif]]]-->Solution</h2>
956<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Comment out the 'rsh' line in /etc/inetd.conf and restart the inetd process. Alternatively, disable this service and use SSH instead.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
957 <![endif]]]-->Risk Factor</h2>
958<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">High</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
959 <![endif]]]-->CVSS Base Score</h2>
960<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
961 <![endif]]]-->References</h2>
962<table xmlns="" width="100%">
963<tr>
964<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
965<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0651" target="_blank">CVE-1999-0651</a>
966</td>
967</tr>
968<tr>
969<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
970<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:193</span></td>
971</tr>
972</table>
973<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
974 <![endif]]]-->Exploitable with</h2>
975<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Metasploit (true)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
976 <![endif]]]-->Plugin Information: </h2>
977<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/08/22, Modification date: 2016/01/05</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
978 <![endif]]]-->Hosts</h2>
979<h2 xmlns="" class="classh2" style="color: #ee9336">192.168.189.131 (tcp/514)</h2>
980<h2 xmlns="" class="classsection3" id="idm105509376">34460 (1) - Unsupported Web Server Detection</h2>
981<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
982 <![endif]]]-->Synopsis</h2>
983<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote web server is obsolete / unsupported.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
984 <![endif]]]-->Description</h2>
985<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">According to its version, the remote web server is obsolete and no longer maintained by its vendor or provider.<br> <br>Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
986 <![endif]]]-->Solution</h2>
987<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Remove the service if it is no longer needed. Otherwise, upgrade to a newer version if possible or switch to another server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
988 <![endif]]]-->Risk Factor</h2>
989<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">High</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
990 <![endif]]]-->CVSS v3.0 Base Score</h2>
991<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">10.0 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
992 <![endif]]]-->CVSS Base Score</h2>
993<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
994 <![endif]]]-->Plugin Information: </h2>
995<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2008/10/21, Modification date: 2017/07/26</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
996 <![endif]]]-->Hosts</h2>
997<h2 xmlns="" class="classh2" style="color: #ee9336">192.168.189.131 (tcp/8180)</h2>
998<span xmlns="" class="classpre"> <br> Product : Tomcat<br> Installed version : 5.5<br> Support ended : 2012-09-30<br> Supported versions : 8.5.x / 8.0.x / 7.0.x<br> Additional information : http://tomcat.apache.org/tomcat-55-eol.html</span><h2 xmlns="" class="classsection2" id="idm132905600">11213 (1) - HTTP TRACE / TRACK Methods Allowed</h2>
999<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1000 <![endif]]]-->Synopsis</h2>
1001<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Debugging functions are enabled on the remote web server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1002 <![endif]]]-->Description</h2>
1003<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote web server supports the TRACE and/or TRACK methods. TRACE and TRACK are HTTP methods that are used to debug web server connections.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1004 <![endif]]]-->See Also</h2>
1005<table xmlns="" width="100%">
1006<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf" target="_blank">http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf</a>
1007</td></tr>
1008<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.apacheweek.com/issues/03-01-24" target="_blank">http://www.apacheweek.com/issues/03-01-24</a>
1009</td></tr>
1010<tr><td width="100%" valign="top" class="classcell"> <a href="http://download.oracle.com/sunalerts/1000718.1.html" target="_blank">http://download.oracle.com/sunalerts/1000718.1.html</a>
1011</td></tr>
1012</table>
1013<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1014 <![endif]]]-->Solution</h2>
1015<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Disable these methods. Refer to the plugin output for more information.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1016 <![endif]]]-->Risk Factor</h2>
1017<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1018 <![endif]]]-->CVSS Base Score</h2>
1019<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1020 <![endif]]]-->CVSS Temporal Score</h2>
1021<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">4.3 (CVSS2#E:H/RL:OF/RC:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1022 <![endif]]]-->References</h2>
1023<table xmlns="" width="100%">
1024<tr>
1025<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1026<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/9506" target="_blank">9506</a>
1027</td>
1028</tr>
1029<tr>
1030<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1031<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/9561" target="_blank">9561</a>
1032</td>
1033</tr>
1034<tr>
1035<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1036<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/11604" target="_blank">11604</a>
1037</td>
1038</tr>
1039<tr>
1040<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1041<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/33374" target="_blank">33374</a>
1042</td>
1043</tr>
1044<tr>
1045<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1046<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/37995" target="_blank">37995</a>
1047</td>
1048</tr>
1049<tr>
1050<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1051<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2003-1567" target="_blank">CVE-2003-1567</a>
1052</td>
1053</tr>
1054<tr>
1055<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1056<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2004-2320" target="_blank">CVE-2004-2320</a>
1057</td>
1058</tr>
1059<tr>
1060<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1061<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0386" target="_blank">CVE-2010-0386</a>
1062</td>
1063</tr>
1064<tr>
1065<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1066<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:877</span></td>
1067</tr>
1068<tr>
1069<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1070<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:3726</span></td>
1071</tr>
1072<tr>
1073<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1074<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:5648</span></td>
1075</tr>
1076<tr>
1077<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1078<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:11408</span></td>
1079</tr>
1080<tr>
1081<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1082<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:50485</span></td>
1083</tr>
1084<tr>
1085<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1086<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">CERT:288308</span></td>
1087</tr>
1088<tr>
1089<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1090<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">CERT:867593</span></td>
1091</tr>
1092<tr>
1093<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1094<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/16" target="_blank">CWE:16</a>
1095</td>
1096</tr>
1097<tr>
1098<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1099<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/200" target="_blank">CWE:200</a>
1100</td>
1101</tr>
1102</table>
1103<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1104 <![endif]]]-->Plugin Information: </h2>
1105<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2003/01/23, Modification date: 2016/11/23</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1106 <![endif]]]-->Hosts</h2>
1107<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/80)</h2>
1108<span xmlns="" class="classpre"> <br>To disable these methods, add the following lines for each virtual<br>host in your configuration file :<br> <br> RewriteEngine on<br> RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK)<br> RewriteRule .* - [F]<br> <br>Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2<br>support disabling the TRACE method natively via the 'TraceEnable'<br>directive.<br> <br>Nessus sent the following TRACE request : <br> <br>------------------------------ snip ------------------------------<br>TRACE /Nessus1053568801.html HTTP/1.1<br>Connection: Close<br>Host: 192.168.189.131<br>Pragma: no-cache<br>User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)<br>Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*<br>Accept-Language: en<br>Accept-Charset: iso-8859-1,*,utf-8<br> <br>------------------------------ snip ------------------------------<br> <br>and received the following response from the remote server :<br> <br>------------------------------ snip ------------------------------<br>HTTP/1.1 200 OK<br>Date: Sun, 05 Nov 2017 18:41:55 GMT<br>Server: Apache/2.2.8 (Ubuntu) DAV/2<br>Keep-Alive: timeout=15, max=100<br>Connection: Keep-Alive<br>Transfer-Encoding: chunked<br>Content-Type: message/http<br> <br> <br>TRACE /Nessus1053568801.html HTTP/1.1<br>Connection: Keep-Alive<br>Host: 192.168.189.131<br>Pragma: no-cache<br>User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)<br>Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*<br>Accept-Language: en<br>Accept-Charset: iso-8859-1,*,utf-8<br> <br>------------------------------ snip ------------------------------</span><h2 xmlns="" class="classsection2" id="idm132176896">11356 (1) - NFS Exported Share Information Disclosure</h2>
1109<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1110 <![endif]]]-->Synopsis</h2>
1111<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to access NFS shares on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1112 <![endif]]]-->Description</h2>
1113<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">At least one of the NFS shares exported by the remote server could be mounted by the scanning host. An attacker may be able to leverage this to read (and possibly write) files on remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1114 <![endif]]]-->Solution</h2>
1115<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Configure NFS on the remote host so that only authorized hosts can mount its remote shares.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1116 <![endif]]]-->Risk Factor</h2>
1117<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1118 <![endif]]]-->CVSS Base Score</h2>
1119<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1120 <![endif]]]-->References</h2>
1121<table xmlns="" width="100%">
1122<tr>
1123<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1124<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0170" target="_blank">CVE-1999-0170</a>
1125</td>
1126</tr>
1127<tr>
1128<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1129<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0211" target="_blank">CVE-1999-0211</a>
1130</td>
1131</tr>
1132<tr>
1133<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1134<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0554" target="_blank">CVE-1999-0554</a>
1135</td>
1136</tr>
1137<tr>
1138<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1139<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:339</span></td>
1140</tr>
1141<tr>
1142<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1143<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:8750</span></td>
1144</tr>
1145<tr>
1146<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1147<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:11516</span></td>
1148</tr>
1149</table>
1150<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1151 <![endif]]]-->Exploitable with</h2>
1152<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Metasploit (true)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1153 <![endif]]]-->Plugin Information: </h2>
1154<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2003/03/12, Modification date: 2014/02/19</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1155 <![endif]]]-->Hosts</h2>
1156<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (udp/2049)</h2>
1157<span xmlns="" class="classpre"> <br>The following NFS shares could be mounted :<br> <br>+ /<br> + Contents of / : <br> - .<br> - ..<br> - bin<br> - boot<br> - cdrom<br> - dev<br> - etc<br> - home<br> - initrd<br> - initrd.img<br> - lib<br> - lost+found<br> - media<br> - mnt<br> - nohup.out<br> - opt<br> - proc<br> - root<br> - sbin<br> - srv<br> - sys<br> - tmp<br> - usr<br> - var<br> - vmlinuz</span><h2 xmlns="" class="classsection2" id="idm132144000">15901 (1) - SSL Certificate Expiry</h2>
1158<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1159 <![endif]]]-->Synopsis</h2>
1160<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote server's SSL certificate has already expired.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1161 <![endif]]]-->Description</h2>
1162<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin checks expiry dates of certificates associated with SSL- enabled services on the target and reports whether any have already expired.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1163 <![endif]]]-->Solution</h2>
1164<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Purchase or generate a new SSL certificate to replace the existing one.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1165 <![endif]]]-->Risk Factor</h2>
1166<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1167 <![endif]]]-->CVSS Base Score</h2>
1168<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1169 <![endif]]]-->Plugin Information: </h2>
1170<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2004/12/03, Modification date: 2016/01/08</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1171 <![endif]]]-->Hosts</h2>
1172<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1173<span xmlns="" class="classpre"> <br>The SSL certificate has already expired :<br> <br> Subject : C=XX, ST=There is no such thing outside US, L=Everywhere, O=OCOSA, OU=Office for Complication of Otherwise Simple Affairs, CN=ubuntu804-base.localdomain, emailAddress=root@ubuntu804-base.localdomain<br> Issuer : C=XX, ST=There is no such thing outside US, L=Everywhere, O=OCOSA, OU=Office for Complication of Otherwise Simple Affairs, CN=ubuntu804-base.localdomain, emailAddress=root@ubuntu804-base.localdomain<br> Not valid before : Mar 17 14:07:45 2010 GMT<br> Not valid after : Apr 16 14:07:45 2010 GMT</span><h2 xmlns="" class="classsection2" id="idm133597568">20007 (1) - SSL Version 2 and 3 Protocol Detection</h2>
1174<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1175 <![endif]]]-->Synopsis</h2>
1176<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service encrypts traffic using a protocol with known weaknesses.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1177 <![endif]]]-->Description</h2>
1178<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service accepts connections encrypted using SSL 2.0 and/or SSL 3.0. These versions of SSL are affected by several cryptographic flaws, including:<br> <br> - An insecure padding scheme with CBC ciphers.<br> <br> - Insecure session renegotiation and resumption schemes.<br> <br>An attacker can exploit these flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected service and clients.<br> <br>Although SSL/TLS has a secure means for choosing the highest supported version of the protocol (so that these versions will be used only if the client or server support nothing better), many web browsers implement this in an unsafe way that allows an attacker to downgrade a connection (such as in POODLE). Therefore, it is recommended that these protocols be disabled entirely.<br> <br>NIST has determined that SSL 3.0 is no longer acceptable for secure communications. As of the date of enforcement found in PCI DSS v3.1, any version of SSL will not meet the PCI SSC's definition of 'strong cryptography'.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1179 <![endif]]]-->See Also</h2>
1180<table xmlns="" width="100%">
1181<tr><td width="100%" valign="top" class="classcell"> <a href="https://www.schneier.com/academic/paperfiles/paper-ssl.pdf" target="_blank">https://www.schneier.com/academic/paperfiles/paper-ssl.pdf</a>
1182</td></tr>
1183<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?0bb7b67d" target="_blank">http://www.nessus.org/u?0bb7b67d</a>
1184</td></tr>
1185<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?247c4540" target="_blank">http://www.nessus.org/u?247c4540</a>
1186</td></tr>
1187<tr><td width="100%" valign="top" class="classcell"> <a href="https://www.openssl.org/~bodo/ssl-poodle.pdf" target="_blank">https://www.openssl.org/~bodo/ssl-poodle.pdf</a>
1188</td></tr>
1189<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?5d15ba70" target="_blank">http://www.nessus.org/u?5d15ba70</a>
1190</td></tr>
1191<tr><td width="100%" valign="top" class="classcell"> <a href="https://www.imperialviolet.org/2014/10/14/poodle.html" target="_blank">https://www.imperialviolet.org/2014/10/14/poodle.html</a>
1192</td></tr>
1193<tr><td width="100%" valign="top" class="classcell"> <a href="https://tools.ietf.org/html/rfc7507" target="_blank">https://tools.ietf.org/html/rfc7507</a>
1194</td></tr>
1195<tr><td width="100%" valign="top" class="classcell"> <a href="https://tools.ietf.org/html/rfc7568" target="_blank">https://tools.ietf.org/html/rfc7568</a>
1196</td></tr>
1197</table>
1198<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1199 <![endif]]]-->Solution</h2>
1200<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Consult the application's documentation to disable SSL 2.0 and 3.0.<br>Use TLS 1.1 (with approved cipher suites) or higher instead.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1201 <![endif]]]-->Risk Factor</h2>
1202<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1203 <![endif]]]-->CVSS v3.0 Base Score</h2>
1204<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1205 <![endif]]]-->CVSS Base Score</h2>
1206<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1207 <![endif]]]-->Plugin Information: </h2>
1208<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2005/10/12, Modification date: 2017/07/11</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1209 <![endif]]]-->Hosts</h2>
1210<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1211<span xmlns="" class="classpre"> <br>- SSLv2 is enabled and the server supports at least one cipher.<br> <br>- SSLv3 is enabled and the server supports at least one cipher.</span><h2 xmlns="" class="classsection2" id="idm133575936">26928 (1) - SSL Weak Cipher Suites Supported</h2>
1212<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1213 <![endif]]]-->Synopsis</h2>
1214<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service supports the use of weak SSL ciphers.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1215 <![endif]]]-->Description</h2>
1216<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports the use of SSL ciphers that offer weak encryption.<br> <br>Note: This is considerably easier to exploit if the attacker is on the same physical network.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1217 <![endif]]]-->See Also</h2>
1218<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?3a040ada" target="_blank">http://www.nessus.org/u?3a040ada</a>
1219</td></tr></table>
1220<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1221 <![endif]]]-->Solution</h2>
1222<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Reconfigure the affected application, if possible to avoid the use of weak ciphers.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1223 <![endif]]]-->Risk Factor</h2>
1224<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1225 <![endif]]]-->CVSS v3.0 Base Score</h2>
1226<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1227 <![endif]]]-->CVSS Base Score</h2>
1228<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1229 <![endif]]]-->References</h2>
1230<table xmlns="" width="100%">
1231<tr>
1232<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1233<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/326" target="_blank">CWE:326</a>
1234</td>
1235</tr>
1236<tr>
1237<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1238<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/327" target="_blank">CWE:327</a>
1239</td>
1240</tr>
1241<tr>
1242<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1243<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/720" target="_blank">CWE:720</a>
1244</td>
1245</tr>
1246<tr>
1247<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1248<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/753" target="_blank">CWE:753</a>
1249</td>
1250</tr>
1251<tr>
1252<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1253<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/803" target="_blank">CWE:803</a>
1254</td>
1255</tr>
1256<tr>
1257<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1258<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/928" target="_blank">CWE:928</a>
1259</td>
1260</tr>
1261<tr>
1262<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1263<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/934" target="_blank">CWE:934</a>
1264</td>
1265</tr>
1266</table>
1267<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1268 <![endif]]]-->Plugin Information: </h2>
1269<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2007/10/08, Modification date: 2017/09/01</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1270 <![endif]]]-->Hosts</h2>
1271<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1272<span xmlns="" class="classpre"> <br>Here is the list of weak SSL ciphers supported by the remote server :<br> <br> Low Strength Ciphers (<= 64-bit key)<br> <br> DES-CBC-MD5 Kx=RSA Au=RSA Enc=DES-CBC(56) Mac=MD5 <br> EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2-CBC(40) Mac=MD5 export <br> EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export <br> EXP-EDH-RSA-DES-CBC-SHA Kx=DH(512) Au=RSA Enc=DES-CBC(40) Mac=SHA1 export <br> EDH-RSA-DES-CBC-SHA Kx=DH Au=RSA Enc=DES-CBC(56) Mac=SHA1 <br> EXP-ADH-DES-CBC-SHA Kx=DH(512) Au=None Enc=DES-CBC(40) Mac=SHA1 export <br> EXP-ADH-RC4-MD5 Kx=DH(512) Au=None Enc=RC4(40) Mac=MD5 export <br> ADH-DES-CBC-SHA Kx=DH Au=None Enc=DES-CBC(56) Mac=SHA1 <br> EXP-DES-CBC-SHA Kx=RSA(512) Au=RSA Enc=DES-CBC(40) Mac=SHA1 export <br> EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2-CBC(40) Mac=MD5 export <br> EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export <br> DES-CBC-SHA Kx=RSA Au=RSA Enc=DES-CBC(56) Mac=SHA1 <br> <br>The fields above are :<br> <br> {OpenSSL ciphername}<br> Kx={key exchange}<br> Au={authentication}<br> Enc={symmetric encryption method}<br> Mac={message authentication code}<br> {export flag}</span><h2 xmlns="" class="classsection2" id="idm134191104">42256 (1) - NFS Shares World Readable</h2>
1273<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1274 <![endif]]]-->Synopsis</h2>
1275<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote NFS server exports world-readable shares.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1276 <![endif]]]-->Description</h2>
1277<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote NFS server is exporting one or more shares without restricting access (based on hostname, IP, or IP range).</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1278 <![endif]]]-->See Also</h2>
1279<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="http://www.tldp.org/HOWTO/NFS-HOWTO/security.html" target="_blank">http://www.tldp.org/HOWTO/NFS-HOWTO/security.html</a>
1280</td></tr></table>
1281<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1282 <![endif]]]-->Solution</h2>
1283<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Place the appropriate restrictions on all NFS shares.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1284 <![endif]]]-->Risk Factor</h2>
1285<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1286 <![endif]]]-->CVSS Base Score</h2>
1287<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1288 <![endif]]]-->References</h2>
1289<table xmlns="" width="100%"><tr>
1290<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1291<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:339</span></td>
1292</tr></table>
1293<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1294 <![endif]]]-->Plugin Information: </h2>
1295<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2009/10/26, Modification date: 2016/11/23</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1296 <![endif]]]-->Hosts</h2>
1297<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/2049)</h2>
1298<span xmlns="" class="classpre"> <br>The following shares have no access restrictions :<br> <br> / *</span><h2 xmlns="" class="classsection2" id="idm134179072">42263 (1) - Unencrypted Telnet Server</h2>
1299<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1300 <![endif]]]-->Synopsis</h2>
1301<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote Telnet server transmits traffic in cleartext.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1302 <![endif]]]-->Description</h2>
1303<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running a Telnet server over an unencrypted channel.<br> <br>Using Telnet over an unencrypted channel is not recommended as logins, passwords, and commands are transferred in cleartext. This allows a remote, man-in-the-middle attacker to eavesdrop on a Telnet session to obtain credentials or other sensitive information and to modify traffic exchanged between a client and server.<br> <br>SSH is preferred over Telnet since it protects credentials from eavesdropping and can tunnel additional data streams such as an X11 session.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1304 <![endif]]]-->Solution</h2>
1305<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Disable the Telnet service and use SSH instead.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1306 <![endif]]]-->Risk Factor</h2>
1307<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1308 <![endif]]]-->CVSS Base Score</h2>
1309<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1310 <![endif]]]-->Plugin Information: </h2>
1311<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2009/10/27, Modification date: 2015/10/21</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1312 <![endif]]]-->Hosts</h2>
1313<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/23)</h2>
1314<span xmlns="" class="classpre"> <br>Nessus collected the following banner from the remote Telnet server :<br> <br>------------------------------ snip ------------------------------<br> _ _ _ _ _ _ ____
1315<br> _ __ ___ ___| |_ __ _ ___ _ __ | | ___ (_) |_ __ _| |__ | | ___|___ \
1316<br>| '_ ` _ \ / _ \ __/ _` / __| '_ \| |/ _ \| | __/ _` | '_ \| |/ _ \ __) |
1317<br>| | | | | | __/ || (_| \__ \ |_) | | (_) | | || (_| | |_) | | __// __/
1318<br>|_| |_| |_|\___|\__\__,_|___/ .__/|_|\___/|_|\__\__,_|_.__/|_|\___|_____|
1319<br> |_|
1320<br>
1321<br>
1322<br>Warning: Never expose this VM to an untrusted network!
1323<br>
1324<br>Contact: msfdev[at]metasploit.com
1325<br>
1326<br>Login with msfadmin/msfadmin to get started
1327<br>
1328<br>
1329<br>metasploitable login: <br>------------------------------ snip ------------------------------</span><h2 xmlns="" class="classsection2" id="idm134165632">42873 (1) - SSL Medium Strength Cipher Suites Supported</h2>
1330<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1331 <![endif]]]-->Synopsis</h2>
1332<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service supports the use of medium strength SSL ciphers.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1333 <![endif]]]-->Description</h2>
1334<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.<br> <br>Note that it is considerably easier to circumvent medium strength encryption if the attacker is on the same physical network.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1335 <![endif]]]-->See Also</h2>
1336<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="https://www.openssl.org/blog/blog/2016/08/24/sweet32/" target="_blank">https://www.openssl.org/blog/blog/2016/08/24/sweet32/</a>
1337</td></tr></table>
1338<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1339 <![endif]]]-->Solution</h2>
1340<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Reconfigure the affected application if possible to avoid use of medium strength ciphers.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1341 <![endif]]]-->Risk Factor</h2>
1342<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1343 <![endif]]]-->CVSS v3.0 Base Score</h2>
1344<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1345 <![endif]]]-->CVSS Base Score</h2>
1346<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1347 <![endif]]]-->Plugin Information: </h2>
1348<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2009/11/23, Modification date: 2017/09/01</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1349 <![endif]]]-->Hosts</h2>
1350<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1351<span xmlns="" class="classpre"> <br>Here is the list of medium strength SSL ciphers supported by the remote server :<br> <br> Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)<br> <br> DES-CBC3-MD5 Kx=RSA Au=RSA Enc=3DES-CBC(168) Mac=MD5 <br> EDH-RSA-DES-CBC3-SHA Kx=DH Au=RSA Enc=3DES-CBC(168) Mac=SHA1 <br> ADH-DES-CBC3-SHA Kx=DH Au=None Enc=3DES-CBC(168) Mac=SHA1 <br> DES-CBC3-SHA Kx=RSA Au=RSA Enc=3DES-CBC(168) Mac=SHA1 <br> <br>The fields above are :<br> <br> {OpenSSL ciphername}<br> Kx={key exchange}<br> Au={authentication}<br> Enc={symmetric encryption method}<br> Mac={message authentication code}<br> {export flag}</span><h2 xmlns="" class="classsection2" id="idm132307456">45411 (1) - SSL Certificate with Wrong Hostname</h2>
1352<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1353 <![endif]]]-->Synopsis</h2>
1354<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The SSL certificate for this service is for a different host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1355 <![endif]]]-->Description</h2>
1356<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The 'commonName' (CN) attribute of the SSL certificate presented for this service is for a different machine.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1357 <![endif]]]-->Solution</h2>
1358<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Purchase or generate a proper certificate for this service.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1359 <![endif]]]-->Risk Factor</h2>
1360<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1361 <![endif]]]-->CVSS v3.0 Base Score</h2>
1362<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1363 <![endif]]]-->CVSS Base Score</h2>
1364<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1365 <![endif]]]-->Plugin Information: </h2>
1366<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2010/04/03, Modification date: 2017/06/05</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1367 <![endif]]]-->Hosts</h2>
1368<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1369<span xmlns="" class="classpre"> <br>The identities known by Nessus are :<br> <br> 192.168.189.131<br> 192.168.189.131<br> <br>The Common Name in the certificate is :<br> <br> ubuntu804-base.localdomain</span><h2 xmlns="" class="classsection2" id="idm132297344">51192 (1) - SSL Certificate Cannot Be Trusted</h2>
1370<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1371 <![endif]]]-->Synopsis</h2>
1372<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The SSL certificate for this service cannot be trusted.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1373 <![endif]]]-->Description</h2>
1374<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :<br> <br> - First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known public certificate authority.<br> <br> - Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.<br> <br> - Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a signing algorithm that Nessus either does not support or does not recognize.<br> <br>If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-the-middle attacks against the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1375 <![endif]]]-->See Also</h2>
1376<table xmlns="" width="100%">
1377<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.itu.int/rec/T-REC-X.509/en" target="_blank">http://www.itu.int/rec/T-REC-X.509/en</a>
1378</td></tr>
1379<tr><td width="100%" valign="top" class="classcell"> <a href="https://en.wikipedia.org/wiki/X.509" target="_blank">https://en.wikipedia.org/wiki/X.509</a>
1380</td></tr>
1381</table>
1382<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1383 <![endif]]]-->Solution</h2>
1384<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Purchase or generate a proper certificate for this service.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1385 <![endif]]]-->Risk Factor</h2>
1386<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1387 <![endif]]]-->CVSS v3.0 Base Score</h2>
1388<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1389 <![endif]]]-->CVSS Base Score</h2>
1390<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1391 <![endif]]]-->Plugin Information: </h2>
1392<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2010/12/15, Modification date: 2017/05/18</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1393 <![endif]]]-->Hosts</h2>
1394<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1395<span xmlns="" class="classpre"> <br>The following certificate was part of the certificate chain<br>sent by the remote host, but it has expired :<br> <br>|-Subject : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple Affairs/CN=ubuntu804-base.localdomain/E=root@ubuntu804-base.localdomain<br>|-Not After : Apr 16 14:07:45 2010 GMT<br> <br>The following certificate was at the top of the certificate<br>chain sent by the remote host, but it is signed by an unknown<br>certificate authority :<br> <br>|-Subject : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple Affairs/CN=ubuntu804-base.localdomain/E=root@ubuntu804-base.localdomain<br>|-Issuer : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple Affairs/CN=ubuntu804-base.localdomain/E=root@ubuntu804-base.localdomain</span><h2 xmlns="" class="classsection2" id="idm132276992">52611 (1) - SMTP Service STARTTLS Plaintext Command Injection</h2>
1396<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1397 <![endif]]]-->Synopsis</h2>
1398<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote mail service allows plaintext command injection while negotiating an encrypted communications channel.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1399 <![endif]]]-->Description</h2>
1400<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote SMTP service contains a software flaw in its STARTTLS implementation that could allow a remote, unauthenticated attacker to inject commands during the plaintext protocol phase that will be executed during the ciphertext protocol phase. <br> <br>Successful exploitation could allow an attacker to steal a victim's email or associated SASL (Simple Authentication and Security Layer) credentials.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1401 <![endif]]]-->See Also</h2>
1402<table xmlns="" width="100%">
1403<tr><td width="100%" valign="top" class="classcell"> <a href="https://tools.ietf.org/html/rfc2487" target="_blank">https://tools.ietf.org/html/rfc2487</a>
1404</td></tr>
1405<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/archive/1/516901/30/0/threaded" target="_blank">http://www.securityfocus.com/archive/1/516901/30/0/threaded</a>
1406</td></tr>
1407</table>
1408<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1409 <![endif]]]-->Solution</h2>
1410<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Contact the vendor to see if an update is available.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1411 <![endif]]]-->Risk Factor</h2>
1412<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1413 <![endif]]]-->CVSS Base Score</h2>
1414<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">4.0 (CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1415 <![endif]]]-->CVSS Temporal Score</h2>
1416<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">3.5 (CVSS2#E:ND/RL:OF/RC:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1417 <![endif]]]-->References</h2>
1418<table xmlns="" width="100%">
1419<tr>
1420<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1421<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/46767" target="_blank">46767</a>
1422</td>
1423</tr>
1424<tr>
1425<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1426<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-0411" target="_blank">CVE-2011-0411</a>
1427</td>
1428</tr>
1429<tr>
1430<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1431<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1430" target="_blank">CVE-2011-1430</a>
1432</td>
1433</tr>
1434<tr>
1435<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1436<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1431" target="_blank">CVE-2011-1431</a>
1437</td>
1438</tr>
1439<tr>
1440<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1441<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1432" target="_blank">CVE-2011-1432</a>
1442</td>
1443</tr>
1444<tr>
1445<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1446<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1506" target="_blank">CVE-2011-1506</a>
1447</td>
1448</tr>
1449<tr>
1450<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1451<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-2165" target="_blank">CVE-2011-2165</a>
1452</td>
1453</tr>
1454<tr>
1455<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1456<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:71020</span></td>
1457</tr>
1458<tr>
1459<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1460<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:71021</span></td>
1461</tr>
1462<tr>
1463<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1464<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:71854</span></td>
1465</tr>
1466<tr>
1467<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1468<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:71946</span></td>
1469</tr>
1470<tr>
1471<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1472<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:73251</span></td>
1473</tr>
1474<tr>
1475<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1476<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:75014</span></td>
1477</tr>
1478<tr>
1479<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1480<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:75256</span></td>
1481</tr>
1482<tr>
1483<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1484<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">CERT:555316</span></td>
1485</tr>
1486</table>
1487<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1488 <![endif]]]-->Plugin Information: </h2>
1489<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2011/03/10, Modification date: 2017/06/12</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1490 <![endif]]]-->Hosts</h2>
1491<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1492<span xmlns="" class="classpre"> <br>Nessus sent the following two commands in a single packet :<br> <br> STARTTLS\r\nRSET\r\n<br> <br>And the server sent the following two responses :<br> <br> 220 2.0.0 Ready to start TLS<br> 250 2.0.0 Ok</span><h2 xmlns="" class="classsection2" id="idm132876800">57582 (1) - SSL Self-Signed Certificate</h2>
1493<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1494 <![endif]]]-->Synopsis</h2>
1495<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The SSL certificate chain for this service ends in an unrecognized self-signed certificate.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1496 <![endif]]]-->Description</h2>
1497<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host. <br> <br>Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1498 <![endif]]]-->Solution</h2>
1499<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Purchase or generate a proper certificate for this service.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1500 <![endif]]]-->Risk Factor</h2>
1501<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1502 <![endif]]]-->CVSS Base Score</h2>
1503<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1504 <![endif]]]-->Plugin Information: </h2>
1505<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2012/01/17, Modification date: 2016/12/14</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1506 <![endif]]]-->Hosts</h2>
1507<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1508<span xmlns="" class="classpre"> <br>The following certificate was found at the top of the certificate<br>chain sent by the remote host, but is self-signed and was not<br>found in the list of known certificate authorities :<br> <br>|-Subject : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple Affairs/CN=ubuntu804-base.localdomain/E=root@ubuntu804-base.localdomain</span><h2 xmlns="" class="classsection2" id="idm132855552">57608 (1) - SMB Signing Disabled</h2>
1509<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1510 <![endif]]]-->Synopsis</h2>
1511<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Signing is not required on the remote SMB server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1512 <![endif]]]-->Description</h2>
1513<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Signing is not required on the remote SMB server. An unauthenticated, remote attacker can exploit this to conduct man-in-the-middle attacks against the SMB server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1514 <![endif]]]-->See Also</h2>
1515<table xmlns="" width="100%">
1516<tr><td width="100%" valign="top" class="classcell"> <a href="https://support.microsoft.com/en-us/kb/887429" target="_blank">https://support.microsoft.com/en-us/kb/887429</a>
1517</td></tr>
1518<tr><td width="100%" valign="top" class="classcell"> <a href="http://technet.microsoft.com/en-us/library/cc731957.aspx" target="_blank">http://technet.microsoft.com/en-us/library/cc731957.aspx</a>
1519</td></tr>
1520<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?74b80723" target="_blank">http://www.nessus.org/u?74b80723</a>
1521</td></tr>
1522<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html" target="_blank">http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html</a>
1523</td></tr>
1524<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?a3cac4ea" target="_blank">http://www.nessus.org/u?a3cac4ea</a>
1525</td></tr>
1526</table>
1527<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1528 <![endif]]]-->Solution</h2>
1529<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Enforce message signing in the host's configuration. On Windows, this is found in the policy setting 'Microsoft network server: Digitally sign communications (always)'. On Samba, the setting is called 'server signing'. See the 'see also' links for further details.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1530 <![endif]]]-->Risk Factor</h2>
1531<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1532 <![endif]]]-->CVSS Base Score</h2>
1533<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1534 <![endif]]]-->CVSS Temporal Score</h2>
1535<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">3.7 (CVSS2#E:U/RL:OF/RC:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1536 <![endif]]]-->Plugin Information: </h2>
1537<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2012/01/19, Modification date: 2016/12/09</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1538 <![endif]]]-->Hosts</h2>
1539<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/445)</h2>
1540<h2 xmlns="" class="classsection2" id="idm132841472">57792 (1) - Apache HTTP Server httpOnly Cookie Information Disclosure</h2>
1541<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1542 <![endif]]]-->Synopsis</h2>
1543<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The web server running on the remote host is affected by an information disclosure vulnerability.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1544 <![endif]]]-->Description</h2>
1545<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The version of Apache HTTP Server running on the remote host is affected by an information disclosure vulnerability. Sending a request with HTTP headers long enough to exceed the server limit causes the web server to respond with an HTTP 400. By default, the offending HTTP header and value are displayed on the 400 error page. When used in conjunction with other attacks (e.g., cross-site scripting), this could result in the compromise of httpOnly cookies.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1546 <![endif]]]-->See Also</h2>
1547<table xmlns="" width="100%">
1548<tr><td width="100%" valign="top" class="classcell"> <a href="http://fd.the-wildcat.de/apache_e36a9cf46c.php" target="_blank">http://fd.the-wildcat.de/apache_e36a9cf46c.php</a>
1549</td></tr>
1550<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?e005199a" target="_blank">http://www.nessus.org/u?e005199a</a>
1551</td></tr>
1552<tr><td width="100%" valign="top" class="classcell"> <a href="http://httpd.apache.org/security/vulnerabilities_22.html" target="_blank">http://httpd.apache.org/security/vulnerabilities_22.html</a>
1553</td></tr>
1554<tr><td width="100%" valign="top" class="classcell"> <a href="http://svn.apache.org/viewvc?view=revision&revision=1235454" target="_blank">http://svn.apache.org/viewvc?view=revision&revision=1235454</a>
1555</td></tr>
1556</table>
1557<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1558 <![endif]]]-->Solution</h2>
1559<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Upgrade to Apache version 2.0.65 / 2.2.22 or later.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1560 <![endif]]]-->Risk Factor</h2>
1561<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1562 <![endif]]]-->CVSS Base Score</h2>
1563<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1564 <![endif]]]-->CVSS Temporal Score</h2>
1565<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">3.4 (CVSS2#E:POC/RL:OF/RC:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1566 <![endif]]]-->References</h2>
1567<table xmlns="" width="100%">
1568<tr>
1569<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1570<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/51706" target="_blank">51706</a>
1571</td>
1572</tr>
1573<tr>
1574<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1575<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0053" target="_blank">CVE-2012-0053</a>
1576</td>
1577</tr>
1578<tr>
1579<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1580<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:78556</span></td>
1581</tr>
1582<tr>
1583<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1584<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">EDB-ID:18442</span></td>
1585</tr>
1586</table>
1587<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1588 <![endif]]]-->Plugin Information: </h2>
1589<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2012/02/02, Modification date: 2017/04/28</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1590 <![endif]]]-->Hosts</h2>
1591<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/80)</h2>
1592<span xmlns="" class="classpre"> <br>Nessus verified this by sending a request with a long Cookie header :<br> <br>GET / HTTP/1.1
1593<br>Host: 192.168.189.131
1594<br>Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1
1595<br>Accept-Language: en
1596<br>Connection: Close
1597<br>Cookie: z9=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA...<br>User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
1598<br>Pragma: no-cache
1599<br>Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*<br> <br>Which caused the Cookie header to be displayed in the default error page<br>(the response shown below has been truncated) :<br> <br><!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><br><html><head><br><title>400 Bad Request</title><br></head><body><br><h1>Bad Request</h1><br><p>Your browser sent a request that this server could not understand.<br /><br>Size of a request header field exceeds server limit.<br /><br><pre><br>Cookie: z9=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA...<br> </span><h2 xmlns="" class="classsection2" id="idm132807040">78479 (1) - SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)</h2>
1600<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1601 <![endif]]]-->Synopsis</h2>
1602<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to obtain sensitive information from the remote host with SSL/TLS-enabled services.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1603 <![endif]]]-->Description</h2>
1604<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is affected by a man-in-the-middle (MitM) information disclosure vulnerability known as POODLE. The vulnerability is due to the way SSL 3.0 handles padding bytes when decrypting messages encrypted using block ciphers in cipher block chaining (CBC) mode.<br>MitM attackers can decrypt a selected byte of a cipher text in as few as 256 tries if they are able to force a victim application to repeatedly send the same data over newly created SSL 3.0 connections.<br> <br>As long as a client and service both support SSLv3, a connection can be 'rolled back' to SSLv3, even if TLSv1 or newer is supported by the client and service.<br> <br>The TLS Fallback SCSV mechanism prevents 'version rollback' attacks without impacting legacy clients; however, it can only protect connections when the client and service support the mechanism. Sites that cannot disable SSLv3 immediately should enable this mechanism.<br> <br>This is a vulnerability in the SSLv3 specification, not in any particular SSL implementation. Disabling SSLv3 is the only way to completely mitigate the vulnerability.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1605 <![endif]]]-->See Also</h2>
1606<table xmlns="" width="100%">
1607<tr><td width="100%" valign="top" class="classcell"> <a href="https://www.imperialviolet.org/2014/10/14/poodle.html" target="_blank">https://www.imperialviolet.org/2014/10/14/poodle.html</a>
1608</td></tr>
1609<tr><td width="100%" valign="top" class="classcell"> <a href="https://www.openssl.org/~bodo/ssl-poodle.pdf" target="_blank">https://www.openssl.org/~bodo/ssl-poodle.pdf</a>
1610</td></tr>
1611<tr><td width="100%" valign="top" class="classcell"> <a href="https://tools.ietf.org/html/draft-ietf-tls-downgrade-scsv-00" target="_blank">https://tools.ietf.org/html/draft-ietf-tls-downgrade-scsv-00</a>
1612</td></tr>
1613</table>
1614<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1615 <![endif]]]-->Solution</h2>
1616<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Disable SSLv3.<br> <br>Services that must support SSLv3 should enable the TLS Fallback SCSV mechanism until SSLv3 can be disabled.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1617 <![endif]]]-->Risk Factor</h2>
1618<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1619 <![endif]]]-->CVSS Base Score</h2>
1620<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1621 <![endif]]]-->CVSS Temporal Score</h2>
1622<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">3.7 (CVSS2#E:ND/RL:OF/RC:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1623 <![endif]]]-->References</h2>
1624<table xmlns="" width="100%">
1625<tr>
1626<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1627<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/70574" target="_blank">70574</a>
1628</td>
1629</tr>
1630<tr>
1631<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1632<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3566" target="_blank">CVE-2014-3566</a>
1633</td>
1634</tr>
1635<tr>
1636<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1637<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:113251</span></td>
1638</tr>
1639<tr>
1640<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1641<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">CERT:577193</span></td>
1642</tr>
1643</table>
1644<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1645 <![endif]]]-->Plugin Information: </h2>
1646<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2014/10/15, Modification date: 2016/11/30</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1647 <![endif]]]-->Hosts</h2>
1648<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1649<span xmlns="" class="classpre"> <br>Nessus determined that the remote server supports SSLv3 with at least one CBC <br>cipher suite, indicating that this server is vulnerable.<br> <br>It appears that TLSv1 or newer is supported on the server. However, the <br>Fallback SCSV mechanism is not supported, allowing connections to be "rolled <br>back" to SSLv3.</span><h2 xmlns="" class="classsection2" id="idm132776320">81606 (1) - SSL/TLS EXPORT_RSA <= 512-bit Cipher Suites Supported (FREAK)</h2>
1650<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1651 <![endif]]]-->Synopsis</h2>
1652<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports a set of weak ciphers.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1653 <![endif]]]-->Description</h2>
1654<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports EXPORT_RSA cipher suites with keys less than or equal to 512 bits. An attacker can factor a 512-bit RSA modulus in a short amount of time.<br> <br>A man-in-the middle attacker may be able to downgrade the session to use EXPORT_RSA cipher suites (e.g. CVE-2015-0204). Thus, it is recommended to remove support for weak cipher suites.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1655 <![endif]]]-->See Also</h2>
1656<table xmlns="" width="100%">
1657<tr><td width="100%" valign="top" class="classcell"> <a href="https://www.smacktls.com/#freak" target="_blank">https://www.smacktls.com/#freak</a>
1658</td></tr>
1659<tr><td width="100%" valign="top" class="classcell"> <a href="https://www.openssl.org/news/secadv/20150108.txt" target="_blank">https://www.openssl.org/news/secadv/20150108.txt</a>
1660</td></tr>
1661<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?b78da2c4" target="_blank">http://www.nessus.org/u?b78da2c4</a>
1662</td></tr>
1663</table>
1664<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1665 <![endif]]]-->Solution</h2>
1666<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Reconfigure the service to remove support for EXPORT_RSA cipher suites.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1667 <![endif]]]-->Risk Factor</h2>
1668<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1669 <![endif]]]-->CVSS Base Score</h2>
1670<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1671 <![endif]]]-->CVSS Temporal Score</h2>
1672<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">4.1 (CVSS2#E:F/RL:OF/RC:ND)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1673 <![endif]]]-->References</h2>
1674<table xmlns="" width="100%">
1675<tr>
1676<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1677<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/71936" target="_blank">71936</a>
1678</td>
1679</tr>
1680<tr>
1681<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1682<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0204" target="_blank">CVE-2015-0204</a>
1683</td>
1684</tr>
1685<tr>
1686<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1687<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:116794</span></td>
1688</tr>
1689<tr>
1690<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1691<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">CERT:243585</span></td>
1692</tr>
1693</table>
1694<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1695 <![endif]]]-->Plugin Information: </h2>
1696<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2015/03/04, Modification date: 2016/05/12</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1697 <![endif]]]-->Hosts</h2>
1698<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1699<span xmlns="" class="classpre"> <br>EXPORT_RSA cipher suites supported by the remote server :<br> <br> Low Strength Ciphers (<= 64-bit key)<br> <br> EXP-DES-CBC-SHA Kx=RSA(512) Au=RSA Enc=DES-CBC(40) Mac=SHA1 export <br> EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2-CBC(40) Mac=MD5 export <br> EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export <br> <br>The fields above are :<br> <br> {OpenSSL ciphername}<br> Kx={key exchange}<br> Au={authentication}<br> Enc={symmetric encryption method}<br> Mac={message authentication code}<br> {export flag}</span><h2 xmlns="" class="classsection2" id="idp1317248">89058 (1) - SSL DROWN Attack Vulnerability (Decrypting RSA with Obsolete and Weakened eNcryption)</h2>
1700<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1701 <![endif]]]-->Synopsis</h2>
1702<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host may be affected by a vulnerability that allows a remote attacker to potentially decrypt captured TLS traffic.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1703 <![endif]]]-->Description</h2>
1704<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports SSLv2 and therefore may be affected by a vulnerability that allows a cross-protocol Bleichenbacher padding oracle attack known as DROWN (Decrypting RSA with Obsolete and Weakened eNcryption). This vulnerability exists due to a flaw in the Secure Sockets Layer Version 2 (SSLv2) implementation, and it allows captured TLS traffic to be decrypted. A man-in-the-middle attacker can exploit this to decrypt the TLS connection by utilizing previously captured traffic and weak cryptography along with a series of specially crafted connections to an SSLv2 server that uses the same private key.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1705 <![endif]]]-->See Also</h2>
1706<table xmlns="" width="100%">
1707<tr><td width="100%" valign="top" class="classcell"> <a href="https://drownattack.com/" target="_blank">https://drownattack.com/</a>
1708</td></tr>
1709<tr><td width="100%" valign="top" class="classcell"> <a href="https://drownattack.com/drown-attack-paper.pdf" target="_blank">https://drownattack.com/drown-attack-paper.pdf</a>
1710</td></tr>
1711</table>
1712<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1713 <![endif]]]-->Solution</h2>
1714<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Disable SSLv2 and export grade cryptography cipher suites. Ensure that private keys are not used anywhere with server software that supports SSLv2 connections.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1715 <![endif]]]-->Risk Factor</h2>
1716<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1717 <![endif]]]-->CVSS Base Score</h2>
1718<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">4.0 (CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1719 <![endif]]]-->CVSS Temporal Score</h2>
1720<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">3.8 (CVSS2#E:F/RL:ND/RC:ND)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1721 <![endif]]]-->References</h2>
1722<table xmlns="" width="100%">
1723<tr>
1724<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1725<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/83733" target="_blank">83733</a>
1726</td>
1727</tr>
1728<tr>
1729<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1730<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-0800" target="_blank">CVE-2016-0800</a>
1731</td>
1732</tr>
1733<tr>
1734<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1735<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:135149</span></td>
1736</tr>
1737<tr>
1738<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1739<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">CERT:583776</span></td>
1740</tr>
1741</table>
1742<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1743 <![endif]]]-->Plugin Information: </h2>
1744<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2016/03/01, Modification date: 2016/07/19</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1745 <![endif]]]-->Hosts</h2>
1746<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1747<span xmlns="" class="classpre"> <br>The remote host is affected by SSL DROWN and supports the following<br>vulnerable cipher suites :<br> <br> Low Strength Ciphers (<= 64-bit key)<br> <br> DES-CBC-MD5 Kx=RSA Au=RSA Enc=DES-CBC(56) Mac=MD5 <br> EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2-CBC(40) Mac=MD5 export <br> EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export <br> <br> High Strength Ciphers (>= 112-bit key)<br> <br> RC4-MD5 Kx=RSA Au=RSA Enc=RC4(128) Mac=MD5 <br> <br>The fields above are :<br> <br> {OpenSSL ciphername}<br> Kx={key exchange}<br> Au={authentication}<br> Enc={symmetric encryption method}<br> Mac={message authentication code}<br> {export flag}</span><h2 xmlns="" class="classsection2" id="idm132742272">90317 (1) - SSH Weak Algorithms Supported</h2>
1748<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1749 <![endif]]]-->Synopsis</h2>
1750<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote SSH server is configured to allow weak encryption algorithms or no algorithm at all.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1751 <![endif]]]-->Description</h2>
1752<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Nessus has detected that the remote SSH server is configured to use the Arcfour stream cipher or no cipher at all. RFC 4253 advises against using Arcfour due to an issue with weak keys.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1753 <![endif]]]-->See Also</h2>
1754<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="https://tools.ietf.org/html/rfc4253#section-6.3" target="_blank">https://tools.ietf.org/html/rfc4253#section-6.3</a>
1755</td></tr></table>
1756<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1757 <![endif]]]-->Solution</h2>
1758<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Contact the vendor or consult product documentation to remove the weak ciphers.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1759 <![endif]]]-->Risk Factor</h2>
1760<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1761 <![endif]]]-->CVSS Base Score</h2>
1762<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1763 <![endif]]]-->Plugin Information: </h2>
1764<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2016/04/04, Modification date: 2016/12/14</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1765 <![endif]]]-->Hosts</h2>
1766<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/22)</h2>
1767<span xmlns="" class="classpre"> <br>The following weak server-to-client encryption algorithms are supported : <br> <br> arcfour<br> arcfour128<br> arcfour256<br> <br>The following weak client-to-server encryption algorithms are supported : <br> <br> arcfour<br> arcfour128<br> arcfour256</span><h2 xmlns="" class="classsection2" id="idm132730496">90509 (1) - Samba Badlock Vulnerability</h2>
1768<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1769 <![endif]]]-->Synopsis</h2>
1770<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An SMB server running on the remote host is affected by the Badlock vulnerability.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1771 <![endif]]]-->Description</h2>
1772<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The version of Samba, a CIFS/SMB server for Linux and Unix, running on the remote host is affected by a flaw, known as Badlock, that exists in the Security Account Manager (SAM) and Local Security Authority (Domain Policy) (LSAD) protocols due to improper authentication level negotiation over Remote Procedure Call (RPC) channels. A man-in-the-middle attacker who is able to able to intercept the traffic between a client and a server hosting a SAM database can exploit this flaw to force a downgrade of the authentication level, which allows the execution of arbitrary Samba network calls in the context of the intercepted user, such as viewing or modifying sensitive security data in the Active Directory (AD) database or disabling critical services.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1773 <![endif]]]-->See Also</h2>
1774<table xmlns="" width="100%">
1775<tr><td width="100%" valign="top" class="classcell"> <a href="http://badlock.org" target="_blank">http://badlock.org</a>
1776</td></tr>
1777<tr><td width="100%" valign="top" class="classcell"> <a href="https://www.samba.org/samba/security/CVE-2016-2118.html" target="_blank">https://www.samba.org/samba/security/CVE-2016-2118.html</a>
1778</td></tr>
1779</table>
1780<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1781 <![endif]]]-->Solution</h2>
1782<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Upgrade to Samba version 4.2.11 / 4.3.8 / 4.4.2 or later.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1783 <![endif]]]-->Risk Factor</h2>
1784<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1785 <![endif]]]-->CVSS Base Score</h2>
1786<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1787 <![endif]]]-->CVSS Temporal Score</h2>
1788<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.6 (CVSS2#E:F/RL:OF/RC:ND)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1789 <![endif]]]-->References</h2>
1790<table xmlns="" width="100%">
1791<tr>
1792<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1793<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/86002" target="_blank">86002</a>
1794</td>
1795</tr>
1796<tr>
1797<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1798<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2118" target="_blank">CVE-2016-2118</a>
1799</td>
1800</tr>
1801<tr>
1802<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1803<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:136339</span></td>
1804</tr>
1805<tr>
1806<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1807<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">CERT:813296</span></td>
1808</tr>
1809</table>
1810<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1811 <![endif]]]-->Plugin Information: </h2>
1812<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2016/04/13, Modification date: 2016/07/25</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1813 <![endif]]]-->Hosts</h2>
1814<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/445)</h2>
1815<span xmlns="" class="classpre"> <br>Nessus detected that the Samba Badlock patch has not been applied.</span><h2 xmlns="" class="classsection2" id="idm132696448">94437 (1) - SSL 64-bit Block Size Cipher Suites Supported (SWEET32)</h2>
1816<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1817 <![endif]]]-->Synopsis</h2>
1818<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service supports the use of 64-bit block ciphers.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1819 <![endif]]]-->Description</h2>
1820<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports the use of a block cipher with 64-bit blocks in one or more cipher suites. It is, therefore, affected by a vulnerability, known as SWEET32, due to the use of weak 64-bit block ciphers. A man-in-the-middle attacker who has sufficient resources can exploit this vulnerability, via a 'birthday' attack, to detect a collision that leaks the XOR between the fixed secret and a known plaintext, allowing the disclosure of the secret text, such as secure HTTPS cookies, and possibly resulting in the hijacking of an authenticated session.<br> <br>Proof-of-concepts have shown that attackers can recover authentication cookies from an HTTPS session in as little as 30 hours.<br> <br>Note that the ability to send a large number of requests over the same TLS connection between the client and server is an important requirement for carrying out this attack. If the number of requests allowed for a single connection were limited, this would mitigate the vulnerability. However, Nessus has not checked for such a mitigation.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1821 <![endif]]]-->See Also</h2>
1822<table xmlns="" width="100%">
1823<tr><td width="100%" valign="top" class="classcell"> <a href="https://sweet32.info" target="_blank">https://sweet32.info</a>
1824</td></tr>
1825<tr><td width="100%" valign="top" class="classcell"> <a href="https://www.openssl.org/blog/blog/2016/08/24/sweet32/" target="_blank">https://www.openssl.org/blog/blog/2016/08/24/sweet32/</a>
1826</td></tr>
1827</table>
1828<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1829 <![endif]]]-->Solution</h2>
1830<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Reconfigure the affected application, if possible, to avoid use of all 64-bit block ciphers. Alternatively, place limitations on the number of requests that are allowed to be processed over the same TLS connection to mitigate this vulnerability.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1831 <![endif]]]-->Risk Factor</h2>
1832<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Medium</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1833 <![endif]]]-->CVSS v3.0 Base Score</h2>
1834<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1835 <![endif]]]-->CVSS v3.0 Temporal Score</h2>
1836<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.1 (CVSS:3.0/E:F/RL:X/RC:X)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1837 <![endif]]]-->CVSS Base Score</h2>
1838<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1839 <![endif]]]-->CVSS Temporal Score</h2>
1840<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">4.8 (CVSS2#E:F/RL:ND/RC:ND)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1841 <![endif]]]-->References</h2>
1842<table xmlns="" width="100%">
1843<tr>
1844<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1845<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/92630" target="_blank">92630</a>
1846</td>
1847</tr>
1848<tr>
1849<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1850<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/92631" target="_blank">92631</a>
1851</td>
1852</tr>
1853<tr>
1854<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1855<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2183" target="_blank">CVE-2016-2183</a>
1856</td>
1857</tr>
1858<tr>
1859<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1860<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6329" target="_blank">CVE-2016-6329</a>
1861</td>
1862</tr>
1863<tr>
1864<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1865<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:143387</span></td>
1866</tr>
1867<tr>
1868<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1869<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:143388</span></td>
1870</tr>
1871</table>
1872<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1873 <![endif]]]-->Plugin Information: </h2>
1874<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2016/11/01, Modification date: 2017/01/24</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1875 <![endif]]]-->Hosts</h2>
1876<h2 xmlns="" class="classh2" style="color: #fdc431">192.168.189.131 (tcp/25)</h2>
1877<span xmlns="" class="classpre"> <br>List of 64-bit block cipher suites supported by the remote server :<br> <br> Low Strength Ciphers (<= 64-bit key)<br> <br> EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2-CBC(40) Mac=MD5 export <br> EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2-CBC(40) Mac=MD5 export <br> <br> Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)<br> <br> EDH-RSA-DES-CBC3-SHA Kx=DH Au=RSA Enc=3DES-CBC(168) Mac=SHA1 <br> ADH-DES-CBC3-SHA Kx=DH Au=None Enc=3DES-CBC(168) Mac=SHA1 <br> DES-CBC3-SHA Kx=RSA Au=RSA Enc=3DES-CBC(168) Mac=SHA1 <br> <br> High Strength Ciphers (>= 112-bit key)<br> <br> RC2-CBC-MD5 Kx=RSA Au=RSA Enc=RC2-CBC(128) Mac=MD5 <br> <br>The fields above are :<br> <br> {OpenSSL ciphername}<br> Kx={key exchange}<br> Au={authentication}<br> Enc={symmetric encryption method}<br> Mac={message authentication code}<br> {export flag}</span><h2 xmlns="" class="classsection1" id="idm132654336">10407 (1) - X Server Detection</h2>
1878<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1879 <![endif]]]-->Synopsis</h2>
1880<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An X11 server is listening on the remote host</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1881 <![endif]]]-->Description</h2>
1882<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running an X11 server. X11 is a client-server protocol that can be used to display graphical applications running on a given host on a remote client. <br> <br>Since the X11 traffic is not ciphered, it is possible for an attacker to eavesdrop on the connection.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1883 <![endif]]]-->Solution</h2>
1884<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Restrict access to this port. If the X11 client/server facility is not used, disable TCP support in X11 entirely (-nolisten tcp).</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1885 <![endif]]]-->Risk Factor</h2>
1886<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Low</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1887 <![endif]]]-->CVSS Base Score</h2>
1888<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">2.6 (CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1889 <![endif]]]-->Plugin Information: </h2>
1890<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2000/05/12, Modification date: 2013/01/25</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1891 <![endif]]]-->Hosts</h2>
1892<h2 xmlns="" class="classh2" style="color: #4cae4c">192.168.189.131 (tcp/6000)</h2>
1893<span xmlns="" class="classpre"> <br>X11 Version : 11.0</span><h2 xmlns="" class="classsection1" id="idm132646400">31705 (1) - SSL Anonymous Cipher Suites Supported</h2>
1894<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1895 <![endif]]]-->Synopsis</h2>
1896<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service supports the use of anonymous SSL ciphers.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1897 <![endif]]]-->Description</h2>
1898<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports the use of anonymous SSL ciphers. While this enables an administrator to set up a service that encrypts traffic without having to generate and configure SSL certificates, it offers no way to verify the remote host's identity and renders the service vulnerable to a man-in-the-middle attack.<br> <br>Note: This is considerably easier to exploit if the attacker is on the same physical network.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1899 <![endif]]]-->See Also</h2>
1900<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?3a040ada" target="_blank">http://www.nessus.org/u?3a040ada</a>
1901</td></tr></table>
1902<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1903 <![endif]]]-->Solution</h2>
1904<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Reconfigure the affected application if possible to avoid use of weak ciphers.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1905 <![endif]]]-->Risk Factor</h2>
1906<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Low</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1907 <![endif]]]-->CVSS v3.0 Base Score</h2>
1908<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1909 <![endif]]]-->CVSS Base Score</h2>
1910<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">2.6 (CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1911 <![endif]]]-->CVSS Temporal Score</h2>
1912<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">2.3 (CVSS2#E:ND/RL:OF/RC:C)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1913 <![endif]]]-->References</h2>
1914<table xmlns="" width="100%">
1915<tr>
1916<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1917<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/28482" target="_blank">28482</a>
1918</td>
1919</tr>
1920<tr>
1921<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1922<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-1858" target="_blank">CVE-2007-1858</a>
1923</td>
1924</tr>
1925<tr>
1926<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1927<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:34882</span></td>
1928</tr>
1929</table>
1930<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1931 <![endif]]]-->Plugin Information: </h2>
1932<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2008/03/28, Modification date: 2017/07/05</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1933 <![endif]]]-->Hosts</h2>
1934<h2 xmlns="" class="classh2" style="color: #4cae4c">192.168.189.131 (tcp/25)</h2>
1935<span xmlns="" class="classpre"> <br>The following is a list of SSL anonymous ciphers supported by the remote server :<br> <br> Low Strength Ciphers (<= 64-bit key)<br> <br> EXP-ADH-DES-CBC-SHA Kx=DH(512) Au=None Enc=DES-CBC(40) Mac=SHA1 export <br> EXP-ADH-RC4-MD5 Kx=DH(512) Au=None Enc=RC4(40) Mac=MD5 export <br> ADH-DES-CBC-SHA Kx=DH Au=None Enc=DES-CBC(56) Mac=SHA1 <br> <br> Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)<br> <br> ADH-DES-CBC3-SHA Kx=DH Au=None Enc=3DES-CBC(168) Mac=SHA1 <br> <br> High Strength Ciphers (>= 112-bit key)<br> <br> ADH-AES128-SHA Kx=DH Au=None Enc=AES-CBC(128) Mac=SHA1 <br> ADH-AES256-SHA Kx=DH Au=None Enc=AES-CBC(256) Mac=SHA1 <br> ADH-RC4-MD5 Kx=DH Au=None Enc=RC4(128) Mac=MD5 <br> <br>The fields above are :<br> <br> {OpenSSL ciphername}<br> Kx={key exchange}<br> Au={authentication}<br> Enc={symmetric encryption method}<br> Mac={message authentication code}<br> {export flag}</span><h2 xmlns="" class="classsection1" id="idm132610944">65821 (1) - SSL RC4 Cipher Suites Supported (Bar Mitzvah)</h2>
1936<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1937 <![endif]]]-->Synopsis</h2>
1938<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service supports the use of the RC4 cipher.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1939 <![endif]]]-->Description</h2>
1940<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports the use of RC4 in one or more cipher suites.<br>The RC4 cipher is flawed in its generation of a pseudo-random stream of bytes so that a wide variety of small biases are introduced into the stream, decreasing its randomness.<br> <br>If plaintext is repeatedly encrypted (e.g., HTTP cookies), and an attacker is able to obtain many (i.e., tens of millions) ciphertexts, the attacker may be able to derive the plaintext.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1941 <![endif]]]-->See Also</h2>
1942<table xmlns="" width="100%">
1943<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?217a3666" target="_blank">http://www.nessus.org/u?217a3666</a>
1944</td></tr>
1945<tr><td width="100%" valign="top" class="classcell"> <a href="http://cr.yp.to/talks/2013.03.12/slides.pdf" target="_blank">http://cr.yp.to/talks/2013.03.12/slides.pdf</a>
1946</td></tr>
1947<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.isg.rhul.ac.uk/tls/" target="_blank">http://www.isg.rhul.ac.uk/tls/</a>
1948</td></tr>
1949<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.imperva.com/docs/HII_Attacking_SSL_when_using_RC4.pdf" target="_blank">http://www.imperva.com/docs/HII_Attacking_SSL_when_using_RC4.pdf</a>
1950</td></tr>
1951</table>
1952<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1953 <![endif]]]-->Solution</h2>
1954<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Reconfigure the affected application, if possible, to avoid use of RC4 ciphers. Consider using TLS 1.2 with AES-GCM suites subject to browser and web server support.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1955 <![endif]]]-->Risk Factor</h2>
1956<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Low</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1957 <![endif]]]-->CVSS Base Score</h2>
1958<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">2.6 (CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1959 <![endif]]]-->CVSS Temporal Score</h2>
1960<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">2.2 (CVSS2#E:F/RL:TF/RC:ND)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1961 <![endif]]]-->References</h2>
1962<table xmlns="" width="100%">
1963<tr>
1964<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1965<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/58796" target="_blank">58796</a>
1966</td>
1967</tr>
1968<tr>
1969<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
1970<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/73684" target="_blank">73684</a>
1971</td>
1972</tr>
1973<tr>
1974<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1975<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2566" target="_blank">CVE-2013-2566</a>
1976</td>
1977</tr>
1978<tr>
1979<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
1980<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-2808" target="_blank">CVE-2015-2808</a>
1981</td>
1982</tr>
1983<tr>
1984<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1985<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:91162</span></td>
1986</tr>
1987<tr>
1988<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
1989<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:117855</span></td>
1990</tr>
1991</table>
1992<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1993 <![endif]]]-->Plugin Information: </h2>
1994<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2013/04/05, Modification date: 2016/12/14</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1995 <![endif]]]-->Hosts</h2>
1996<h2 xmlns="" class="classh2" style="color: #4cae4c">192.168.189.131 (tcp/25)</h2>
1997<span xmlns="" class="classpre"> <br>List of RC4 cipher suites supported by the remote server :<br> <br> Low Strength Ciphers (<= 64-bit key)<br> <br> EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export <br> EXP-ADH-RC4-MD5 Kx=DH(512) Au=None Enc=RC4(40) Mac=MD5 export <br> EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export <br> <br> High Strength Ciphers (>= 112-bit key)<br> <br> RC4-MD5 Kx=RSA Au=RSA Enc=RC4(128) Mac=MD5 <br> ADH-RC4-MD5 Kx=DH Au=None Enc=RC4(128) Mac=MD5 <br> RC4-MD5 Kx=RSA Au=RSA Enc=RC4(128) Mac=MD5 <br> RC4-SHA Kx=RSA Au=RSA Enc=RC4(128) Mac=SHA1 <br> <br>The fields above are :<br> <br> {OpenSSL ciphername}<br> Kx={key exchange}<br> Au={authentication}<br> Enc={symmetric encryption method}<br> Mac={message authentication code}<br> {export flag}</span><h2 xmlns="" class="classsection1" id="idm134265088">70658 (1) - SSH Server CBC Mode Ciphers Enabled</h2>
1998<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
1999 <![endif]]]-->Synopsis</h2>
2000<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The SSH server is configured to use Cipher Block Chaining.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2001 <![endif]]]-->Description</h2>
2002<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The SSH server is configured to support Cipher Block Chaining (CBC) encryption. This may allow an attacker to recover the plaintext message from the ciphertext. <br> <br>Note that this plugin only checks for the options of the SSH server and does not check for vulnerable software versions.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2003 <![endif]]]-->Solution</h2>
2004<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Contact the vendor or consult product documentation to disable CBC mode cipher encryption, and enable CTR or GCM cipher mode encryption.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2005 <![endif]]]-->Risk Factor</h2>
2006<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Low</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2007 <![endif]]]-->CVSS Base Score</h2>
2008<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">2.6 (CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2009 <![endif]]]-->CVSS Temporal Score</h2>
2010<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">2.6 (CVSS2#E:ND/RL:ND/RC:ND)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2011 <![endif]]]-->References</h2>
2012<table xmlns="" width="100%">
2013<tr>
2014<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
2015<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/32319" target="_blank">32319</a>
2016</td>
2017</tr>
2018<tr>
2019<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
2020<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5161" target="_blank">CVE-2008-5161</a>
2021</td>
2022</tr>
2023<tr>
2024<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2025<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:50035</span></td>
2026</tr>
2027<tr>
2028<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2029<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:50036</span></td>
2030</tr>
2031<tr>
2032<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2033<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">CERT:958563</span></td>
2034</tr>
2035<tr>
2036<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2037<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/200" target="_blank">CWE:200</a>
2038</td>
2039</tr>
2040</table>
2041<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2042 <![endif]]]-->Plugin Information: </h2>
2043<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2013/10/28, Modification date: 2016/05/12</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2044 <![endif]]]-->Hosts</h2>
2045<h2 xmlns="" class="classh2" style="color: #4cae4c">192.168.189.131 (tcp/22)</h2>
2046<span xmlns="" class="classpre"> <br>The following client-to-server Cipher Block Chaining (CBC) algorithms<br>are supported : <br> <br> 3des-cbc<br> aes128-cbc<br> aes192-cbc<br> aes256-cbc<br> blowfish-cbc<br> cast128-cbc<br> rijndael-cbc@lysator.liu.se<br> <br>The following server-to-client Cipher Block Chaining (CBC) algorithms<br>are supported : <br> <br> 3des-cbc<br> aes128-cbc<br> aes192-cbc<br> aes256-cbc<br> blowfish-cbc<br> cast128-cbc<br> rijndael-cbc@lysator.liu.se</span><h2 xmlns="" class="classsection1" id="idm134229504">71049 (1) - SSH Weak MAC Algorithms Enabled</h2>
2047<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2048 <![endif]]]-->Synopsis</h2>
2049<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote SSH server is configured to allow MD5 and 96-bit MAC algorithms.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2050 <![endif]]]-->Description</h2>
2051<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote SSH server is configured to allow either MD5 or 96-bit MAC algorithms, both of which are considered weak.<br> <br>Note that this plugin only checks for the options of the SSH server, and it does not check for vulnerable software versions.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2052 <![endif]]]-->Solution</h2>
2053<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Contact the vendor or consult product documentation to disable MD5 and 96-bit MAC algorithms.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2054 <![endif]]]-->Risk Factor</h2>
2055<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Low</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2056 <![endif]]]-->CVSS Base Score</h2>
2057<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">2.6 (CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2058 <![endif]]]-->Plugin Information: </h2>
2059<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2013/11/22, Modification date: 2016/12/14</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2060 <![endif]]]-->Hosts</h2>
2061<h2 xmlns="" class="classh2" style="color: #4cae4c">192.168.189.131 (tcp/22)</h2>
2062<span xmlns="" class="classpre"> <br>The following client-to-server Message Authentication Code (MAC) algorithms<br>are supported : <br> <br> hmac-md5<br> hmac-md5-96<br> hmac-sha1-96<br> <br>The following server-to-client Message Authentication Code (MAC) algorithms<br>are supported : <br> <br> hmac-md5<br> hmac-md5-96<br> hmac-sha1-96</span><h2 xmlns="" class="classsection1" id="idm134218240">83738 (1) - SSL/TLS EXPORT_DHE <= 512-bit Export Cipher Suites Supported (Logjam)</h2>
2063<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2064 <![endif]]]-->Synopsis</h2>
2065<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports a set of weak ciphers.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2066 <![endif]]]-->Description</h2>
2067<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports EXPORT_DHE cipher suites with keys less than or equal to 512 bits. Through cryptanalysis, a third party can find the shared secret in a short amount of time.<br> <br>A man-in-the middle attacker may be able to downgrade the session to use EXPORT_DHE cipher suites. Thus, it is recommended to remove support for weak cipher suites.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2068 <![endif]]]-->See Also</h2>
2069<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="https://weakdh.org/" target="_blank">https://weakdh.org/</a>
2070</td></tr></table>
2071<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2072 <![endif]]]-->Solution</h2>
2073<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Reconfigure the service to remove support for EXPORT_DHE cipher suites.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2074 <![endif]]]-->Risk Factor</h2>
2075<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Low</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2076 <![endif]]]-->CVSS Base Score</h2>
2077<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">2.6 (CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2078 <![endif]]]-->CVSS Temporal Score</h2>
2079<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">2.2 (CVSS2#E:F/RL:TF/RC:ND)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2080 <![endif]]]-->References</h2>
2081<table xmlns="" width="100%">
2082<tr>
2083<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
2084<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/74733" target="_blank">74733</a>
2085</td>
2086</tr>
2087<tr>
2088<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
2089<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4000" target="_blank">CVE-2015-4000</a>
2090</td>
2091</tr>
2092<tr>
2093<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2094<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:122331</span></td>
2095</tr>
2096</table>
2097<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2098 <![endif]]]-->Plugin Information: </h2>
2099<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2015/05/21, Modification date: 2016/06/16</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2100 <![endif]]]-->Hosts</h2>
2101<h2 xmlns="" class="classh2" style="color: #4cae4c">192.168.189.131 (tcp/25)</h2>
2102<span xmlns="" class="classpre"> <br>EXPORT_DHE cipher suites supported by the remote server :<br> <br> Low Strength Ciphers (<= 64-bit key)<br> <br> EXP-EDH-RSA-DES-CBC-SHA Kx=DH(512) Au=RSA Enc=DES-CBC(40) Mac=SHA1 export <br> EXP-ADH-DES-CBC-SHA Kx=DH(512) Au=None Enc=DES-CBC(40) Mac=SHA1 export <br> EXP-ADH-RC4-MD5 Kx=DH(512) Au=None Enc=RC4(40) Mac=MD5 export <br> <br>The fields above are :<br> <br> {OpenSSL ciphername}<br> Kx={key exchange}<br> Au={authentication}<br> Enc={symmetric encryption method}<br> Mac={message authentication code}<br> {export flag}</span><h2 xmlns="" class="classsection1" id="idm132572416">83875 (1) - SSL/TLS Diffie-Hellman Modulus <= 1024 Bits (Logjam)</h2>
2103<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2104 <![endif]]]-->Synopsis</h2>
2105<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host allows SSL/TLS connections with one or more Diffie-Hellman moduli less than or equal to 1024 bits.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2106 <![endif]]]-->Description</h2>
2107<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host allows SSL/TLS connections with one or more Diffie-Hellman moduli less than or equal to 1024 bits. Through cryptanalysis, a third party may be able to find the shared secret in a short amount of time (depending on modulus size and attacker resources). This may allow an attacker to recover the plaintext or potentially violate the integrity of connections.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2108 <![endif]]]-->See Also</h2>
2109<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="http://weakdh.org/" target="_blank">http://weakdh.org/</a>
2110</td></tr></table>
2111<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2112 <![endif]]]-->Solution</h2>
2113<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Reconfigure the service to use a unique Diffie-Hellman moduli of 2048 bits or greater.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2114 <![endif]]]-->Risk Factor</h2>
2115<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Low</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2116 <![endif]]]-->CVSS Base Score</h2>
2117<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">2.6 (CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N)</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2118 <![endif]]]-->References</h2>
2119<table xmlns="" width="100%">
2120<tr>
2121<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">BID</span></td>
2122<td width="70%" valign="top" class="classcell"> <a href="http://www.securityfocus.com/bid/74733" target="_blank">74733</a>
2123</td>
2124</tr>
2125<tr>
2126<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
2127<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4000" target="_blank">CVE-2015-4000</a>
2128</td>
2129</tr>
2130<tr>
2131<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2132<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:122331</span></td>
2133</tr>
2134</table>
2135<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2136 <![endif]]]-->Plugin Information: </h2>
2137<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2015/05/28, Modification date: 2016/06/16</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2138 <![endif]]]-->Hosts</h2>
2139<h2 xmlns="" class="classh2" style="color: #4cae4c">192.168.189.131 (tcp/25)</h2>
2140<span xmlns="" class="classpre"> <br>Vulnerable connection combinations :<br> <br> SSL/TLS version : TLSv1.0<br> Cipher suite : TLS1_CK_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA<br> Diffie-Hellman MODP size (bits) : 512<br> Logjam attack difficulty : Easy (could be carried out by individuals)<br> <br> SSL/TLS version : SSLv3<br> Cipher suite : TLS1_CK_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA<br> Diffie-Hellman MODP size (bits) : 512<br> Logjam attack difficulty : Easy (could be carried out by individuals)</span><h2 xmlns="" class="classsection0" id="idm132547200">11219 (25) - Nessus SYN scanner</h2>
2141<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2142 <![endif]]]-->Synopsis</h2>
2143<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to determine which TCP ports are open.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2144 <![endif]]]-->Description</h2>
2145<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target. <br> <br>Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave unclosed connections on the remote target, if the network is loaded.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2146 <![endif]]]-->Solution</h2>
2147<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Protect your target with an IP filter.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2148 <![endif]]]-->Risk Factor</h2>
2149<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2150 <![endif]]]-->Plugin Information: </h2>
2151<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2009/02/04, Modification date: 2017/05/22</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2152 <![endif]]]-->Hosts</h2>
2153<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/21)</h2>
2154<span xmlns="" class="classpre">Port 21/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/22)</h2>
2155<span xmlns="" class="classpre">Port 22/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/23)</h2>
2156<span xmlns="" class="classpre">Port 23/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
2157<span xmlns="" class="classpre">Port 25/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/53)</h2>
2158<span xmlns="" class="classpre">Port 53/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/80)</h2>
2159<span xmlns="" class="classpre">Port 80/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/111)</h2>
2160<span xmlns="" class="classpre">Port 111/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/139)</h2>
2161<span xmlns="" class="classpre">Port 139/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/445)</h2>
2162<span xmlns="" class="classpre">Port 445/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/512)</h2>
2163<span xmlns="" class="classpre">Port 512/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/513)</h2>
2164<span xmlns="" class="classpre">Port 513/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/514)</h2>
2165<span xmlns="" class="classpre">Port 514/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/1099)</h2>
2166<span xmlns="" class="classpre">Port 1099/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/1524)</h2>
2167<span xmlns="" class="classpre">Port 1524/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/2049)</h2>
2168<span xmlns="" class="classpre">Port 2049/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/2121)</h2>
2169<span xmlns="" class="classpre">Port 2121/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/3306)</h2>
2170<span xmlns="" class="classpre">Port 3306/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/3632)</h2>
2171<span xmlns="" class="classpre">Port 3632/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/5432)</h2>
2172<span xmlns="" class="classpre">Port 5432/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/5900)</h2>
2173<span xmlns="" class="classpre">Port 5900/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/6000)</h2>
2174<span xmlns="" class="classpre">Port 6000/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/6667)</h2>
2175<span xmlns="" class="classpre">Port 6667/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/8009)</h2>
2176<span xmlns="" class="classpre">Port 8009/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/8180)</h2>
2177<span xmlns="" class="classpre">Port 8180/tcp was found to be open</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/8787)</h2>
2178<span xmlns="" class="classpre">Port 8787/tcp was found to be open</span><h2 xmlns="" class="classsection0" id="idm132514560">11111 (10) - RPC Services Enumeration</h2>
2179<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2180 <![endif]]]-->Synopsis</h2>
2181<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An ONC RPC service is running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2182 <![endif]]]-->Description</h2>
2183<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">By sending a DUMP request to the portmapper, it was possible to enumerate the ONC RPC services running on the remote port. Using this information, it is possible to connect and bind to each service by sending an RPC request to the remote port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2184 <![endif]]]-->Solution</h2>
2185<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2186 <![endif]]]-->Risk Factor</h2>
2187<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2188 <![endif]]]-->Plugin Information: </h2>
2189<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2002/08/24, Modification date: 2011/05/24</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2190 <![endif]]]-->Hosts</h2>
2191<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/111)</h2>
2192<span xmlns="" class="classpre"> <br>The following RPC services are available on TCP port 111 :<br> <br> - program: 100000 (portmapper), version: 2</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/111)</h2>
2193<span xmlns="" class="classpre"> <br>The following RPC services are available on UDP port 111 :<br> <br> - program: 100000 (portmapper), version: 2</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/2049)</h2>
2194<span xmlns="" class="classpre"> <br>The following RPC services are available on TCP port 2049 :<br> <br> - program: 100003 (nfs), version: 2<br> - program: 100003 (nfs), version: 3<br> - program: 100003 (nfs), version: 4</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/2049)</h2>
2195<span xmlns="" class="classpre"> <br>The following RPC services are available on UDP port 2049 :<br> <br> - program: 100003 (nfs), version: 2<br> - program: 100003 (nfs), version: 3<br> - program: 100003 (nfs), version: 4</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/37103)</h2>
2196<span xmlns="" class="classpre"> <br>The following RPC services are available on TCP port 37103 :<br> <br> - program: 100021 (nlockmgr), version: 1<br> - program: 100021 (nlockmgr), version: 3<br> - program: 100021 (nlockmgr), version: 4</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/42330)</h2>
2197<span xmlns="" class="classpre"> <br>The following RPC services are available on UDP port 42330 :<br> <br> - program: 100021 (nlockmgr), version: 1<br> - program: 100021 (nlockmgr), version: 3<br> - program: 100021 (nlockmgr), version: 4</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/46044)</h2>
2198<span xmlns="" class="classpre"> <br>The following RPC services are available on TCP port 46044 :<br> <br> - program: 100024 (status), version: 1</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/48790)</h2>
2199<span xmlns="" class="classpre"> <br>The following RPC services are available on TCP port 48790 :<br> <br> - program: 100005 (mountd), version: 1<br> - program: 100005 (mountd), version: 2<br> - program: 100005 (mountd), version: 3</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/58120)</h2>
2200<span xmlns="" class="classpre"> <br>The following RPC services are available on UDP port 58120 :<br> <br> - program: 100005 (mountd), version: 1<br> - program: 100005 (mountd), version: 2<br> - program: 100005 (mountd), version: 3</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/58445)</h2>
2201<span xmlns="" class="classpre"> <br>The following RPC services are available on UDP port 58445 :<br> <br> - program: 100024 (status), version: 1</span><h2 xmlns="" class="classsection0" id="idm132497280">22964 (10) - Service Detection</h2>
2202<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2203 <![endif]]]-->Synopsis</h2>
2204<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service could be identified.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2205 <![endif]]]-->Description</h2>
2206<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2207 <![endif]]]-->Solution</h2>
2208<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2209 <![endif]]]-->Risk Factor</h2>
2210<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2211 <![endif]]]-->Plugin Information: </h2>
2212<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2007/08/19, Modification date: 2017/07/07</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2213 <![endif]]]-->Hosts</h2>
2214<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/21)</h2>
2215<span xmlns="" class="classpre">An FTP server is running on this port.</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/22)</h2>
2216<span xmlns="" class="classpre">An SSH server is running on this port.</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/23)</h2>
2217<span xmlns="" class="classpre">A telnet server is running on this port.</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
2218<span xmlns="" class="classpre">An SMTP server is running on this port.</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/80)</h2>
2219<span xmlns="" class="classpre">A web server is running on this port.</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/1524)</h2>
2220<span xmlns="" class="classpre">A shell server (Metasploitable) is running on this port.</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/2121)</h2>
2221<span xmlns="" class="classpre">An FTP server is running on this port.</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/5900)</h2>
2222<span xmlns="" class="classpre">A vnc server is running on this port.</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/6667)</h2>
2223<span xmlns="" class="classpre">An IRC server is running on this port.</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/8180)</h2>
2224<span xmlns="" class="classpre">A web server is running on this port.</span><h2 xmlns="" class="classsection0" id="idm132474752">10092 (2) - FTP Server Detection</h2>
2225<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2226 <![endif]]]-->Synopsis</h2>
2227<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An FTP server is listening on a remote port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2228 <![endif]]]-->Description</h2>
2229<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to obtain the banner of the remote FTP server by connecting to a remote port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2230 <![endif]]]-->Solution</h2>
2231<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2232 <![endif]]]-->Risk Factor</h2>
2233<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2234 <![endif]]]-->Plugin Information: </h2>
2235<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/10/12, Modification date: 2016/05/04</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2236 <![endif]]]-->Hosts</h2>
2237<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/21)</h2>
2238<span xmlns="" class="classpre"> <br>The remote FTP banner is :<br> <br>220 (vsFTPd 2.3.4)
2239</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/2121)</h2>
2240<span xmlns="" class="classpre"> <br>The remote FTP banner is :<br> <br>220 ProFTPD 1.3.1 Server (Debian) [::ffff:192.168.189.131]
2241</span><h2 xmlns="" class="classsection0" id="idm132465920">10107 (2) - HTTP Server Type and Version</h2>
2242<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2243 <![endif]]]-->Synopsis</h2>
2244<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A web server is running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2245 <![endif]]]-->Description</h2>
2246<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin attempts to determine the type and the version of the remote web server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2247 <![endif]]]-->Solution</h2>
2248<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2249 <![endif]]]-->Risk Factor</h2>
2250<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2251 <![endif]]]-->Plugin Information: </h2>
2252<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2000/01/04, Modification date: 2016/02/19</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2253 <![endif]]]-->Hosts</h2>
2254<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/80)</h2>
2255<span xmlns="" class="classpre">The remote web server type is :<br> <br>Apache/2.2.8 (Ubuntu) DAV/2<br> <br>You can set the directive 'ServerTokens Prod' to limit the information<br>emanating from the server in its response headers.</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/8180)</h2>
2256<span xmlns="" class="classpre">The remote web server type is :<br> <br>Coyote HTTP/1.1 Connector</span><h2 xmlns="" class="classsection0" id="idm132456960">11002 (2) - DNS Server Detection</h2>
2257<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2258 <![endif]]]-->Synopsis</h2>
2259<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A DNS server is listening on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2260 <![endif]]]-->Description</h2>
2261<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service is a Domain Name System (DNS) server, which provides a mapping between hostnames and IP addresses.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2262 <![endif]]]-->See Also</h2>
2263<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="https://en.wikipedia.org/wiki/Domain_Name_System" target="_blank">https://en.wikipedia.org/wiki/Domain_Name_System</a>
2264</td></tr></table>
2265<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2266 <![endif]]]-->Solution</h2>
2267<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Disable this service if it is not needed or restrict access to internal hosts only if the service is available externally.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2268 <![endif]]]-->Risk Factor</h2>
2269<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2270 <![endif]]]-->Plugin Information: </h2>
2271<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2003/02/13, Modification date: 2017/05/16</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2272 <![endif]]]-->Hosts</h2>
2273<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/53)</h2>
2274<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/53)</h2>
2275<h2 xmlns="" class="classsection0" id="idm132448768">11011 (2) - Microsoft Windows SMB Service Detection</h2>
2276<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2277 <![endif]]]-->Synopsis</h2>
2278<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A file / print sharing service is listening on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2279 <![endif]]]-->Description</h2>
2280<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers, etc between nodes on a network.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2281 <![endif]]]-->Solution</h2>
2282<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2283 <![endif]]]-->Risk Factor</h2>
2284<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2285 <![endif]]]-->Plugin Information: </h2>
2286<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2002/06/05, Modification date: 2015/06/02</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2287 <![endif]]]-->Hosts</h2>
2288<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/139)</h2>
2289<span xmlns="" class="classpre"> <br>An SMB server is running on this port.</span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/445)</h2>
2290<span xmlns="" class="classpre"> <br>A CIFS server is running on this port.</span><h2 xmlns="" class="classsection0" id="idm132428800">24260 (2) - HyperText Transfer Protocol (HTTP) Information</h2>
2291<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2292 <![endif]]]-->Synopsis</h2>
2293<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Some information about the remote HTTP configuration can be extracted.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2294 <![endif]]]-->Description</h2>
2295<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive and HTTP pipelining are enabled, etc... <br> <br>This test is informational only and does not denote any security problem.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2296 <![endif]]]-->Solution</h2>
2297<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2298 <![endif]]]-->Risk Factor</h2>
2299<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2300 <![endif]]]-->Plugin Information: </h2>
2301<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2007/01/30, Modification date: 2011/05/31</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2302 <![endif]]]-->Hosts</h2>
2303<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/80)</h2>
2304<span xmlns="" class="classpre"> <br>Protocol version : HTTP/1.1<br>SSL : no<br>Keep-Alive : yes<br>Options allowed : (Not implemented)<br>Headers :<br> <br> Date: Sun, 05 Nov 2017 18:41:54 GMT<br> Server: Apache/2.2.8 (Ubuntu) DAV/2<br> X-Powered-By: PHP/5.2.4-2ubuntu5.10<br> Content-Length: 891<br> Keep-Alive: timeout=15, max=100<br> Connection: Keep-Alive<br> Content-Type: text/html<br> </span><h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/8180)</h2>
2305<span xmlns="" class="classpre"> <br>Protocol version : HTTP/1.1<br>SSL : no<br>Keep-Alive : no<br>Options allowed : GET, HEAD, POST, PUT, DELETE, TRACE, OPTIONS<br>Headers :<br> <br> Server: Apache-Coyote/1.1<br> Content-Type: text/html;charset=ISO-8859-1<br> Date: Sun, 05 Nov 2017 18:41:53 GMT<br> Connection: close<br> </span><h2 xmlns="" class="classsection0" id="idm132414592">10028 (1) - DNS Server BIND version Directive Remote Version Detection</h2>
2306<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2307 <![endif]]]-->Synopsis</h2>
2308<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to obtain the version number of the remote DNS server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2309 <![endif]]]-->Description</h2>
2310<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running BIND or another DNS server that reports its version number when it receives a special request for the text 'version.bind' in the domain 'chaos'. <br> <br>This version is not necessarily accurate and could even be forged, as some DNS servers send the information based on a configuration file.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2311 <![endif]]]-->Solution</h2>
2312<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to hide the version number of BIND by using the 'version' directive in the 'options' section in named.conf.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2313 <![endif]]]-->Risk Factor</h2>
2314<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2315 <![endif]]]-->References</h2>
2316<table xmlns="" width="100%"><tr>
2317<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2318<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:23</span></td>
2319</tr></table>
2320<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2321 <![endif]]]-->Plugin Information: </h2>
2322<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/10/12, Modification date: 2015/11/18</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2323 <![endif]]]-->Hosts</h2>
2324<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/53)</h2>
2325<span xmlns="" class="classpre"> <br> Version : 9.4.2</span><h2 xmlns="" class="classsection0" id="idm132397184">10114 (1) - ICMP Timestamp Request Remote Date Disclosure</h2>
2326<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2327 <![endif]]]-->Synopsis</h2>
2328<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to determine the exact time set on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2329 <![endif]]]-->Description</h2>
2330<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host answers to an ICMP timestamp request. This allows an attacker to know the date that is set on the targeted machine, which may assist an unauthenticated, remote attacker in defeating time-based authentication protocols.<br> <br>Timestamps returned from machines running Windows Vista / 7 / 2008 / 2008 R2 are deliberately incorrect, but usually within 1000 seconds of the actual system time.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2331 <![endif]]]-->Solution</h2>
2332<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Filter out the ICMP timestamp requests (13), and the outgoing ICMP timestamp replies (14).</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2333 <![endif]]]-->Risk Factor</h2>
2334<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2335 <![endif]]]-->References</h2>
2336<table xmlns="" width="100%">
2337<tr>
2338<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
2339<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0524" target="_blank">CVE-1999-0524</a>
2340</td>
2341</tr>
2342<tr>
2343<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2344<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:94</span></td>
2345</tr>
2346<tr>
2347<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2348<td width="70%" valign="top" class="classcell"> <a href="http://cwe.mitre.org/data/definitions/200" target="_blank">CWE:200</a>
2349</td>
2350</tr>
2351</table>
2352<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2353 <![endif]]]-->Plugin Information: </h2>
2354<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/08/01, Modification date: 2012/06/18</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2355 <![endif]]]-->Hosts</h2>
2356<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (icmp/0)</h2>
2357<span xmlns="" class="classpre">The difference between the local and remote clocks is 80 seconds.</span><h2 xmlns="" class="classsection0" id="idm132385280">10150 (1) - Windows NetBIOS / SMB Remote Host Information Disclosure</h2>
2358<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2359 <![endif]]]-->Synopsis</h2>
2360<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It was possible to obtain the network name of the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2361 <![endif]]]-->Description</h2>
2362<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is listening on UDP port 137 or TCP port 445, and replies to NetBIOS nbtscan or SMB requests.<br> <br>Note that this plugin gathers information to be used in other plugins, but does not itself generate a report.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2363 <![endif]]]-->Solution</h2>
2364<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2365 <![endif]]]-->Risk Factor</h2>
2366<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2367 <![endif]]]-->Plugin Information: </h2>
2368<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/10/12, Modification date: 2017/09/27</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2369 <![endif]]]-->Hosts</h2>
2370<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/137)</h2>
2371<span xmlns="" class="classpre">The following 7 NetBIOS names have been gathered :<br> <br> METASPLOITABLE = Computer name<br> METASPLOITABLE = Messenger Service<br> METASPLOITABLE = File Server Service<br> __MSBROWSE__ = Master Browser<br> WORKGROUP = Workgroup / Domain name<br> WORKGROUP = Master Browser<br> WORKGROUP = Browser Service Elections<br> <br>This SMB server seems to be a Samba server - its MAC address is NULL.</span><h2 xmlns="" class="classsection0" id="idm132371840">10223 (1) - RPC portmapper Service Detection</h2>
2372<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2373 <![endif]]]-->Synopsis</h2>
2374<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An ONC RPC portmapper is running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2375 <![endif]]]-->Description</h2>
2376<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The RPC portmapper is running on this port.<br> <br>The portmapper allows someone to get the port number of each RPC service running on the remote host by sending either multiple lookup requests or a DUMP request.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2377 <![endif]]]-->Solution</h2>
2378<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2379 <![endif]]]-->Risk Factor</h2>
2380<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2381 <![endif]]]-->References</h2>
2382<table xmlns="" width="100%"><tr>
2383<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
2384<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0632" target="_blank">CVE-1999-0632</a>
2385</td>
2386</tr></table>
2387<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2388 <![endif]]]-->Plugin Information: </h2>
2389<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/08/19, Modification date: 2014/02/19</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2390 <![endif]]]-->Hosts</h2>
2391<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/111)</h2>
2392<h2 xmlns="" class="classsection0" id="idm132355072">10263 (1) - SMTP Server Detection</h2>
2393<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2394 <![endif]]]-->Synopsis</h2>
2395<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An SMTP server is listening on the remote port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2396 <![endif]]]-->Description</h2>
2397<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running a mail (SMTP) server on this port. <br> <br>Since SMTP servers are the targets of spammers, it is recommended you disable it if you do not use it.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2398 <![endif]]]-->Solution</h2>
2399<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Disable this service if you do not use it, or filter incoming traffic to this port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2400 <![endif]]]-->Risk Factor</h2>
2401<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2402 <![endif]]]-->Plugin Information: </h2>
2403<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/10/12, Modification date: 2011/03/11</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2404 <![endif]]]-->Hosts</h2>
2405<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
2406<span xmlns="" class="classpre"> <br>Remote SMTP server banner :<br> <br>220 metasploitable.localdomain ESMTP Postfix (Ubuntu)
2407</span><h2 xmlns="" class="classsection0" id="idm132347520">10267 (1) - SSH Server Type and Version Information</h2>
2408<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2409 <![endif]]]-->Synopsis</h2>
2410<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An SSH server is listening on this port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2411 <![endif]]]-->Description</h2>
2412<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to obtain information about the remote SSH server by sending an empty authentication request.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2413 <![endif]]]-->Solution</h2>
2414<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2415 <![endif]]]-->Risk Factor</h2>
2416<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2417 <![endif]]]-->Plugin Information: </h2>
2418<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/10/12, Modification date: 2017/05/30</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2419 <![endif]]]-->Hosts</h2>
2420<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/22)</h2>
2421<span xmlns="" class="classpre"> <br>SSH version : SSH-2.0-OpenSSH_4.7p1 Debian-8ubuntu1<br>SSH supported authentication : publickey,password</span><h2 xmlns="" class="classsection0" id="idm132340736">10281 (1) - Telnet Server Detection</h2>
2422<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2423 <![endif]]]-->Synopsis</h2>
2424<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A Telnet server is listening on the remote port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2425 <![endif]]]-->Description</h2>
2426<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running a Telnet server, a remote terminal server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2427 <![endif]]]-->Solution</h2>
2428<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Disable this service if you do not use it.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2429 <![endif]]]-->Risk Factor</h2>
2430<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2431 <![endif]]]-->Plugin Information: </h2>
2432<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/10/12, Modification date: 2014/01/29</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2433 <![endif]]]-->Hosts</h2>
2434<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/23)</h2>
2435<span xmlns="" class="classpre">Here is the banner from the remote Telnet server :<br> <br>------------------------------ snip ------------------------------<br> _ _ _ _ _ _ ____
2436<br> _ __ ___ ___| |_ __ _ ___ _ __ | | ___ (_) |_ __ _| |__ | | ___|___ \
2437<br>| '_ ` _ \ / _ \ __/ _` / __| '_ \| |/ _ \| | __/ _` | '_ \| |/ _ \ __) |
2438<br>| | | | | | __/ || (_| \__ \ |_) | | (_) | | || (_| | |_) | | __// __/
2439<br>|_| |_| |_|\___|\__\__,_|___/ .__/|_|\___/|_|\__\__,_|_.__/|_|\___|_____|
2440<br> |_|
2441<br>
2442<br>
2443<br>Warning: Never expose this VM to an untrusted network!
2444<br>
2445<br>Contact: msfdev[at]metasploit.com
2446<br>
2447<br>Login with msfadmin/msfadmin to get started
2448<br>
2449<br>
2450<br>metasploitable login: <br>------------------------------ snip ------------------------------</span><h2 xmlns="" class="classsection0" id="idm132321408">10287 (1) - Traceroute Information</h2>
2451<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2452 <![endif]]]-->Synopsis</h2>
2453<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It was possible to obtain traceroute information.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2454 <![endif]]]-->Description</h2>
2455<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Makes a traceroute to the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2456 <![endif]]]-->Solution</h2>
2457<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2458 <![endif]]]-->Risk Factor</h2>
2459<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2460 <![endif]]]-->Plugin Information: </h2>
2461<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 1999/11/27, Modification date: 2017/08/22</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2462 <![endif]]]-->Hosts</h2>
2463<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/0)</h2>
2464<span xmlns="" class="classpre">For your information, here is the traceroute from 192.168.189.130 to 192.168.189.131 : <br>192.168.189.130<br>192.168.189.131<br> <br>Hop Count: 1</span><h2 xmlns="" class="classsection0" id="idm131752960">10342 (1) - VNC Software Detection</h2>
2465<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2466 <![endif]]]-->Synopsis</h2>
2467<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running a remote display software (VNC).</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2468 <![endif]]]-->Description</h2>
2469<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running VNC (Virtual Network Computing), which uses the RFB (Remote Framebuffer) protocol to provide remote access to graphical user interfaces and thus permits a console on the remote host to be displayed on another.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2470 <![endif]]]-->See Also</h2>
2471<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="https://en.wikipedia.org/wiki/Vnc" target="_blank">https://en.wikipedia.org/wiki/Vnc</a>
2472</td></tr></table>
2473<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2474 <![endif]]]-->Solution</h2>
2475<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Make sure use of this software is done in accordance with your organization's security policy and filter incoming traffic to this port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2476 <![endif]]]-->Risk Factor</h2>
2477<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2478 <![endif]]]-->Plugin Information: </h2>
2479<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2000/03/07, Modification date: 2017/06/12</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2480 <![endif]]]-->Hosts</h2>
2481<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/5900)</h2>
2482<span xmlns="" class="classpre"> <br>The highest RFB protocol version supported by the server is :<br> <br> 3.3</span><h2 xmlns="" class="classsection0" id="idm131744128">10394 (1) - Microsoft Windows SMB Log In Possible</h2>
2483<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2484 <![endif]]]-->Synopsis</h2>
2485<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It was possible to log into the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2486 <![endif]]]-->Description</h2>
2487<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running a Microsoft Windows operating system or Samba, a CIFS/SMB server for Unix. It was possible to log into it using one of the following accounts :<br> <br>- NULL session<br>- Guest account<br>- Supplied credentials</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2488 <![endif]]]-->See Also</h2>
2489<table xmlns="" width="100%">
2490<tr><td width="100%" valign="top" class="classcell"> <a href="http://support.microsoft.com/kb/143474" target="_blank">http://support.microsoft.com/kb/143474</a>
2491</td></tr>
2492<tr><td width="100%" valign="top" class="classcell"> <a href="http://support.microsoft.com/kb/246261" target="_blank">http://support.microsoft.com/kb/246261</a>
2493</td></tr>
2494</table>
2495<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2496 <![endif]]]-->Solution</h2>
2497<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2498 <![endif]]]-->Risk Factor</h2>
2499<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2500 <![endif]]]-->Plugin Information: </h2>
2501<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2000/05/09, Modification date: 2017/01/19</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2502 <![endif]]]-->Hosts</h2>
2503<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/445)</h2>
2504<span xmlns="" class="classpre">- NULL sessions are enabled on the remote host.</span><h2 xmlns="" class="classsection0" id="idm131733888">10397 (1) - Microsoft Windows SMB LanMan Pipe Server Listing Disclosure</h2>
2505<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2506 <![endif]]]-->Synopsis</h2>
2507<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to obtain network information.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2508 <![endif]]]-->Description</h2>
2509<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It was possible to obtain the browse list of the remote Windows system by sending a request to the LANMAN pipe. The browse list is the list of the nearest Windows systems of the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2510 <![endif]]]-->Solution</h2>
2511<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2512 <![endif]]]-->Risk Factor</h2>
2513<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2514 <![endif]]]-->References</h2>
2515<table xmlns="" width="100%"><tr>
2516<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2517<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:300</span></td>
2518</tr></table>
2519<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2520 <![endif]]]-->Plugin Information: </h2>
2521<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2000/05/09, Modification date: 2015/01/12</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2522 <![endif]]]-->Hosts</h2>
2523<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/445)</h2>
2524<span xmlns="" class="classpre"> <br>Here is the browse list of the remote host : <br> <br>METASPLOITABLE ( os : 0.0 )</span><h2 xmlns="" class="classsection0" id="idm131712384">10437 (1) - NFS Share Export List</h2>
2525<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2526 <![endif]]]-->Synopsis</h2>
2527<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote NFS server exports a list of shares.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2528 <![endif]]]-->Description</h2>
2529<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin retrieves the list of NFS exported shares.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2530 <![endif]]]-->See Also</h2>
2531<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="http://www.tldp.org/HOWTO/NFS-HOWTO/security.html" target="_blank">http://www.tldp.org/HOWTO/NFS-HOWTO/security.html</a>
2532</td></tr></table>
2533<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2534 <![endif]]]-->Solution</h2>
2535<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Ensure each share is intended to be exported.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2536 <![endif]]]-->Risk Factor</h2>
2537<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2538 <![endif]]]-->References</h2>
2539<table xmlns="" width="100%">
2540<tr>
2541<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">CVE</span></td>
2542<td width="70%" valign="top" class="classcell"> <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0554" target="_blank">CVE-1999-0554</a>
2543</td>
2544</tr>
2545<tr>
2546<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2547<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:339</span></td>
2548</tr>
2549</table>
2550<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2551 <![endif]]]-->Plugin Information: </h2>
2552<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2000/06/07, Modification date: 2015/11/18</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2553 <![endif]]]-->Hosts</h2>
2554<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/2049)</h2>
2555<span xmlns="" class="classpre"> <br>Here is the export list of 192.168.189.131 :<br> <br> / *</span><h2 xmlns="" class="classsection0" id="idm131699840">10719 (1) - MySQL Server Detection</h2>
2556<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2557 <![endif]]]-->Synopsis</h2>
2558<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A database server is listening on the remote port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2559 <![endif]]]-->Description</h2>
2560<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running MySQL, an open source database server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2561 <![endif]]]-->Solution</h2>
2562<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2563 <![endif]]]-->Risk Factor</h2>
2564<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2565 <![endif]]]-->Plugin Information: </h2>
2566<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2001/08/13, Modification date: 2013/01/07</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2567 <![endif]]]-->Hosts</h2>
2568<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/3306)</h2>
2569<span xmlns="" class="classpre"> <br>Version : 5.0.51a-3ubuntu5<br>Protocol : 10<br>Server Status : SERVER_STATUS_AUTOCOMMIT<br>Server Capabilities : <br> CLIENT_LONG_FLAG (Get all column flags)<br> CLIENT_CONNECT_WITH_DB (One can specify db on connect)<br> CLIENT_COMPRESS (Can use compression protocol)<br> CLIENT_PROTOCOL_41 (New 4.1 protocol)<br> CLIENT_SSL (Switch to SSL after handshake)<br> CLIENT_TRANSACTIONS (Client knows about transactions)<br> CLIENT_SECURE_CONNECTION (New 4.1 authentication)</span><h2 xmlns="" class="classsection0" id="idm131690752">10785 (1) - Microsoft Windows SMB NativeLanManager Remote System Information Disclosure</h2>
2570<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2571 <![endif]]]-->Synopsis</h2>
2572<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It was possible to obtain information about the remote operating system.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2573 <![endif]]]-->Description</h2>
2574<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Nessus was able to obtain the remote operating system name and version (Windows and/or Samba) by sending an authentication request to port 139 or 445. Note that this plugin requires SMB1 to be enabled on the host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2575 <![endif]]]-->Solution</h2>
2576<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2577 <![endif]]]-->Risk Factor</h2>
2578<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2579 <![endif]]]-->Plugin Information: </h2>
2580<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2001/10/17, Modification date: 2017/02/21</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2581 <![endif]]]-->Hosts</h2>
2582<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/445)</h2>
2583<span xmlns="" class="classpre">The remote Operating System is : Unix<br>The remote native LAN manager is : Samba 3.0.20-Debian<br>The remote SMB Domain Name is : METASPLOITABLE</span><h2 xmlns="" class="classsection0" id="idm131675776">10863 (1) - SSL Certificate Information</h2>
2584<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2585 <![endif]]]-->Synopsis</h2>
2586<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin displays the SSL certificate.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2587 <![endif]]]-->Description</h2>
2588<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2589 <![endif]]]-->Solution</h2>
2590<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2591 <![endif]]]-->Risk Factor</h2>
2592<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2593 <![endif]]]-->Plugin Information: </h2>
2594<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2008/05/19, Modification date: 2015/12/30</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2595 <![endif]]]-->Hosts</h2>
2596<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
2597<span xmlns="" class="classpre">Subject Name: <br> <br>Country: XX<br>State/Province: There is no such thing outside US<br>Locality: Everywhere<br>Organization: OCOSA<br>Organization Unit: Office for Complication of Otherwise Simple Affairs<br>Common Name: ubuntu804-base.localdomain<br>Email Address: root@ubuntu804-base.localdomain<br> <br>Issuer Name: <br> <br>Country: XX<br>State/Province: There is no such thing outside US<br>Locality: Everywhere<br>Organization: OCOSA<br>Organization Unit: Office for Complication of Otherwise Simple Affairs<br>Common Name: ubuntu804-base.localdomain<br>Email Address: root@ubuntu804-base.localdomain<br> <br>Serial Number: 00 FA F9 3A 4C 7F B6 B9 CC <br> <br>Version: 1<br> <br>Signature Algorithm: SHA-1 With RSA Encryption<br> <br>Not Valid Before: Mar 17 14:07:45 2010 GMT<br>Not Valid After: Apr 16 14:07:45 2010 GMT<br> <br>Public Key Info: <br> <br>Algorithm: RSA Encryption<br>Key Length: 1024 bits<br>Public Key: 00 D6 B4 13 36 33 9A 95 71 7B 1B DE 7C 83 75 DA 71 B1 3C A9 <br> 7F FE AD 64 1B 77 E9 4F AE BE CA D4 F8 CB EF AE BB 43 79 24 <br> 73 FF 3C E5 9E 3B 6D FC C8 B1 AC FA 4C 4D 5E 9B 4C 99 54 0B <br> D7 A8 4A 50 BA A9 DE 1D 1F F4 E4 6B 02 A3 F4 6B 45 CD 4C AF <br> 8D 89 62 33 8F 65 BB 36 61 9F C4 2C 73 C1 4E 2E A0 A8 14 4E <br> 98 70 46 61 BB D1 B9 31 DF 8C 99 EE 75 6B 79 3C 40 A0 AE 97 <br> 00 90 9D DC 99 0D 33 A4 B5 <br>Exponent: 01 00 01 <br> <br>Signature Length: 128 bytes / 1024 bits<br>Signature: 00 92 A4 B4 B8 14 55 63 25 51 4A 0B C3 2A 22 CF 3A F8 17 6A <br> 0C CF 66 AA A7 65 2F 48 6D CD E3 3E 5C 9F 77 6C D4 44 54 1F <br> 1E 84 4F 8E D4 8D DD AC 2D 88 09 21 A8 DA 56 2C A9 05 3C 49 <br> 68 35 19 75 0C DA 53 23 88 88 19 2D 74 26 C1 22 65 EE 11 68 <br> 83 6A 53 4A 9C 27 CB A0 B4 E9 8D 29 0C B2 3C 18 5C 67 CC 53 <br> A6 1E 30 D0 AA 26 7B 1E AE 40 B9 29 01 6C 2E BC A2 19 94 7C <br> 15 6E 8D 30 38 F6 CA 2E 75 <br> <br>Fingerprints : <br> <br>SHA-256 Fingerprint: E7 A7 FA 0D 63 E4 57 C7 C4 A5 9B 38 B7 08 49 C6 A7 0B DA 6F <br> 83 0C 7A F1 E3 2D EE 43 6D E8 13 CC <br>SHA-1 Fingerprint: ED 09 30 88 70 66 03 BF D5 DC 23 73 99 B4 98 DA 2D 4D 31 C6 <br>MD5 Fingerprint: DC D9 AD 90 6C 8F 2F 73 74 AF 38 3B 25 40 88 28 <br> </span><h2 xmlns="" class="classsection0" id="idm131654784">10881 (1) - SSH Protocol Versions Supported</h2>
2598<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2599 <![endif]]]-->Synopsis</h2>
2600<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A SSH server is running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2601 <![endif]]]-->Description</h2>
2602<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin determines the versions of the SSH protocol supported by the remote SSH daemon.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2603 <![endif]]]-->Solution</h2>
2604<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2605 <![endif]]]-->Risk Factor</h2>
2606<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2607 <![endif]]]-->Plugin Information: </h2>
2608<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2002/03/06, Modification date: 2017/05/30</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2609 <![endif]]]-->Hosts</h2>
2610<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/22)</h2>
2611<span xmlns="" class="classpre">The remote SSH daemon supports the following versions of the<br>SSH protocol :<br> <br> - 1.99<br> - 2.0</span><h2 xmlns="" class="classsection0" id="idm131643392">11153 (1) - Service Detection (HELP Request)</h2>
2612<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2613 <![endif]]]-->Synopsis</h2>
2614<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service could be identified.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2615 <![endif]]]-->Description</h2>
2616<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It was possible to identify the remote service by its banner or by looking at the error message it sends when it receives a 'HELP'<br>request.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2617 <![endif]]]-->Solution</h2>
2618<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2619 <![endif]]]-->Risk Factor</h2>
2620<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2621 <![endif]]]-->Plugin Information: </h2>
2622<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2002/11/18, Modification date: 2017/06/08</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2623 <![endif]]]-->Hosts</h2>
2624<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/3306)</h2>
2625<span xmlns="" class="classpre">A MySQL server is running on this port.</span><h2 xmlns="" class="classsection0" id="idm131632768">11154 (1) - Unknown Service Detection: Banner Retrieval</h2>
2626<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2627 <![endif]]]-->Synopsis</h2>
2628<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">There is an unknown service running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2629 <![endif]]]-->Description</h2>
2630<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Nessus was unable to identify a service on the remote host even though it returned a banner of some type.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2631 <![endif]]]-->Solution</h2>
2632<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2633 <![endif]]]-->Risk Factor</h2>
2634<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2635 <![endif]]]-->Plugin Information: </h2>
2636<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2002/11/18, Modification date: 2016/03/24</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2637 <![endif]]]-->Hosts</h2>
2638<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/8787)</h2>
2639<span xmlns="" class="classpre"> <br>If you know what this service is and think the banner could be used to<br>identify it, please send a description of the service along with the<br>following output to svc-signatures@nessus.org :<br> <br> Port : 8787<br> Type : get_http<br> Banner : <br>0x0000: 00 00 00 03 04 08 46 00 00 03 A1 04 08 6F 3A 16 ......F......o:.<br> 0x0010: 44 52 62 3A 3A 44 52 62 43 6F 6E 6E 45 72 72 6F DRb::DRbConnErro<br> 0x0020: 72 07 3A 07 62 74 5B 17 22 2F 2F 75 73 72 2F 6C r.:.bt[."//usr/l<br> 0x0030: 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F ib/ruby/1.8/drb/<br> 0x0040: 64 72 62 2E 72 62 3A 35 37 33 3A 69 6E 20 60 6C drb.rb:573:in `l<br> 0x0050: 6F 61 64 27 22 37 2F 75 73 72 2F 6C 69 62 2F 72 oad'"7/usr/lib/r<br> 0x0060: 75 62 79 2F 31 2E 38 2F 64 72 62 2F 64 72 62 2E uby/1.8/drb/drb.<br> 0x0070: 72 62 3A 36 31 32 3A 69 6E 20 60 72 65 63 76 5F rb:612:in `recv_<br> 0x0080: 72 65 71 75 65 73 74 27 22 37 2F 75 73 72 2F 6C request'"7/usr/l<br> 0x0090: 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F ib/ruby/1.8/drb/<br> 0x00A0: 64 72 62 2E 72 62 3A 39 31 31 3A 69 6E 20 60 72 drb.rb:911:in `r<br> 0x00B0: 65 63 76 5F 72 65 71 75 65 73 74 27 22 3C 2F 75 ecv_request'"</u<br> 0x00C0: 73 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F sr/lib/ruby/1.8/<br> 0x00D0: 64 72 62 2F 64 72 62 2E 72 62 3A 31 35 33 30 3A drb/drb.rb:1530:<br> 0x00E0: 69 6E 20 60 69 6E 69 74 5F 77 69 74 68 5F 63 6C in `init_with_cl<br> 0x00F0: 69 65 6E 74 27 22 39 2F 75 73 72 2F 6C 69 62 2F ient'"9/usr/lib/<br> 0x0100: 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F 64 72 62 ruby/1.8/drb/drb<br> 0x0110: 2E 72 62 3A 31 35 34 32 3A 69 6E 20 60 73 65 74 .rb:1542:in `set<br> 0x0120: 75 70 5F 6D 65 73 73 61 67 65 27 22 33 2F 75 73 up_message'"3/us<br> 0x0130: 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 r/lib/ruby/1.8/d<br> 0x0140: 72 62 2F 64 72 62 2E 72 62 3A 31 34 39 34 3A 69 rb/drb.rb:1494:i<br> 0x0150: 6E 20 60 70 65 72 66 6F 72 6D 27 22 35 2F 75 73 n `perform'"5/us<br> 0x0160: 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 r/lib/ruby/1.8/d<br> 0x0170: 72 62 2F 64 72 62 2E 72 62 3A 31 35 38 39 3A 69 rb/drb.rb:1589:i<br> 0x0180: 6E 20 60 6D 61 69 6E 5F 6C 6F 6F 70 27 22 30 2F n `main_loop'"0/<br> 0x0190: 75 73 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 usr/lib/ruby/1.8<br> 0x01A0: 2F 64 72 62 2F 64 72 62 2E 72 62 3A 31 35 38 35 /drb/drb.rb:1585<br> 0x01B0: 3A 69 6E 20 60 6C 6F 6F 70 27 22 35 2F 75 73 72 :in `loop'"5/usr<br> 0x01C0: 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 72 /lib/ruby/1.8/dr<br> 0x01D0: 62 2F 64 72 62 2E 72 62 3A 31 35 38 35 3A 69 6E b/drb.rb:1585:in<br> 0x01E0: 20 60 6D 61 69 6E 5F 6C 6F 6F 70 27 22 31 2F 75 `main_loop'"1/u<br> 0x01F0: 73 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F sr/lib/ruby/1.8/<br> 0x0200: 64 72 62 2F 64 72 62 2E 72 62 3A 31 35 38 31 3A drb/drb.rb:1581:<br> 0x0210: 69 6E 20 60 73 74 61 72 74 27 22 35 2F 75 73 72 in `start'"5/usr<br> 0x0220: 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 72 /lib/ruby/1.8/dr<br> 0x0230: 62 2F 64 72 62 2E 72 62 3A 31 35 38 31 3A 69 6E b/drb.rb:1581:in<br> 0x0240: 20 60 6D 61 69 6E 5F 6C 6F 6F 70 27 22 2F 2F 75 `main_loop'"//u<br> 0x0250: 73 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F sr/lib/ruby/1.8/<br> 0x0260: 64 72 62 2F 64 72 62 2E 72 62 3A 31 34 33 30 3A drb/drb.rb:1430:<br> 0x0270: 69 6E 20 60 72 75 6E 27 22 31 2F 75 73 72 2F 6C in `run'"1/usr/l<br> 0x0280: 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F ib/ruby/1.8/drb/<br> 0x0290: 64 72 62 2E 72 62 3A 31 34 32 37 3A 69 6E 20 60 drb.rb:1427:in `<br> 0x02A0: 73 74 61 72 74 27 22 2F 2F 75 73 72 2F 6C 69 62 start'"//usr/lib<br> 0x02B0: 2F 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F 64 72 /ruby/1.8/drb/dr<br> 0x02C0: 62 2E 72 62 3A 31 34 32 37 3A 69 6E 20 60 72 75 b.rb:1427:in `ru<br> 0x02D0: 6E 27 22 36 2F 75 73 72 2F 6C 69 62 2F 72 75 62 n'"6/usr/lib/rub<br> 0x02E0: 79 2F 31 2E 38 2F 64 72 62 2F 64 72 62 2E 72 62 y/1.8/drb/drb.rb<br> 0x02F0: 3A 31 33 34 37 3A 69 6E 20 60 69 6E 69 74 69 61 :1347:in `initia<br> 0x0300: 6C 69 7A 65 27 22 2F 2F 75 73 72 2F 6C 69 62 2F lize'"//usr/lib/<br> 0x0310: 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F 64 72 62 ruby/1.8/drb/drb<br> 0x0320: 2E 72 62 3A 31 36 32 37 3A 69 6E 20 60 6E 65 77 .rb:1627:in `new<br> 0x0330: 27 22 39 2F 75 73 72 2F 6C 69 62 2F 72 75 62 79 '"9/usr/lib/ruby<br> 0x0340: 2F 31 2E 38 2F 64 72 62 2F 64 72 62 2E 72 62 3A /1.8/drb/drb.rb:<br> 0x0350: 31 36 32 37 3A 69 6E 20 60 73 74 61 72 74 5F 73 1627:in `start_s<br> 0x0360: 65 72 76 69 63 65 27 22 25 2F 75 73 72 2F 73 62 ervice'"%/usr/sb<br> 0x0370: 69 6E 2F 64 72 75 62 79 5F 74 69 6D 65 73 65 72 in/druby_timeser<br> 0x0380: 76 65 72 2E 72 62 3A 31 32 3A 09 6D 65 73 67 22 ver.rb:12:.mesg"<br> 0x0390: 20 74 6F 6F 20 6C 61 72 67 65 20 70 61 63 6B 65 too large packe<br> 0x03A0: 74 20 31 31 39 35 37 32 35 38 35 36 t 1195725856 <br> </span><h2 xmlns="" class="classsection0" id="idm131588608">11156 (1) - IRC Daemon Version Detection</h2>
2640<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2641 <![endif]]]-->Synopsis</h2>
2642<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is an IRC server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2643 <![endif]]]-->Description</h2>
2644<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin determines the version of the IRC daemon.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2645 <![endif]]]-->Solution</h2>
2646<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2647 <![endif]]]-->Risk Factor</h2>
2648<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2649 <![endif]]]-->Plugin Information: </h2>
2650<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2002/11/19, Modification date: 2016/01/08</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2651 <![endif]]]-->Hosts</h2>
2652<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/6667)</h2>
2653<span xmlns="" class="classpre">The IRC server version is : Unreal3.2.8.1. FhiXOoE [*=2309]
2654</span><h2 xmlns="" class="classsection0" id="idm131582208">11422 (1) - Web Server Unconfigured - Default Install Page Present</h2>
2655<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2656 <![endif]]]-->Synopsis</h2>
2657<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote web server is not configured or is improperly configured.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2658 <![endif]]]-->Description</h2>
2659<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote web server uses its default welcome page. Therefore, it's probable that this server is not used at all or is serving content that is meant to be hidden.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2660 <![endif]]]-->Solution</h2>
2661<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Disable this service if you do not use it.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2662 <![endif]]]-->Risk Factor</h2>
2663<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2664 <![endif]]]-->References</h2>
2665<table xmlns="" width="100%"><tr>
2666<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2667<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:3233</span></td>
2668</tr></table>
2669<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2670 <![endif]]]-->Plugin Information: </h2>
2671<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2003/03/20, Modification date: 2016/03/09</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2672 <![endif]]]-->Hosts</h2>
2673<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/8180)</h2>
2674<span xmlns="" class="classpre"> <br>The default welcome page is from Tomcat.</span><h2 xmlns="" class="classsection0" id="idm131565312">11424 (1) - WebDAV Detection</h2>
2675<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2676 <![endif]]]-->Synopsis</h2>
2677<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote server is running with WebDAV enabled.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2678 <![endif]]]-->Description</h2>
2679<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">WebDAV is an industry standard extension to the HTTP specification.<br>It adds a capability for authorized users to remotely add and manage the content of a web server.<br> <br>If you do not use this extension, you should disable it.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2680 <![endif]]]-->Solution</h2>
2681<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">http://support.microsoft.com/default.aspx?kbid=241520</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2682 <![endif]]]-->Risk Factor</h2>
2683<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2684 <![endif]]]-->Plugin Information: </h2>
2685<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2003/03/20, Modification date: 2011/03/14</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2686 <![endif]]]-->Hosts</h2>
2687<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/80)</h2>
2688<h2 xmlns="" class="classsection0" id="idm131554688">11819 (1) - TFTP Daemon Detection</h2>
2689<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2690 <![endif]]]-->Synopsis</h2>
2691<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A TFTP server is listening on the remote port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2692 <![endif]]]-->Description</h2>
2693<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running a TFTP (Trivial File Transfer Protocol) daemon. TFTP is often used by routers and diskless hosts to retrieve their configuration. It can also be used by worms to propagate.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2694 <![endif]]]-->Solution</h2>
2695<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Disable this service if you do not use it.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2696 <![endif]]]-->Risk Factor</h2>
2697<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2698 <![endif]]]-->Plugin Information: </h2>
2699<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2003/08/13, Modification date: 2016/02/22</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2700 <![endif]]]-->Hosts</h2>
2701<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/69)</h2>
2702<h2 xmlns="" class="classsection0" id="idm131549056">11936 (1) - OS Identification</h2>
2703<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2704 <![endif]]]-->Synopsis</h2>
2705<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to guess the remote operating system.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2706 <![endif]]]-->Description</h2>
2707<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Using a combination of remote probes (e.g., TCP/IP, SMB, HTTP, NTP, SNMP, etc.), it is possible to guess the name of the remote operating system in use. It is also possible sometimes to guess the version of the operating system.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2708 <![endif]]]-->Solution</h2>
2709<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2710 <![endif]]]-->Risk Factor</h2>
2711<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2712 <![endif]]]-->Plugin Information: </h2>
2713<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2003/12/09, Modification date: 2017/08/29</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2714 <![endif]]]-->Hosts</h2>
2715<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/0)</h2>
2716<span xmlns="" class="classpre"> <br>Remote operating system : Linux Kernel 2.6 on Ubuntu 8.04 (gutsy)<br>Confidence level : 95<br>Method : HTTP<br> <br>Not all fingerprints could give a match. If you think some or all of<br>the following could be used to identify the host's operating system,<br>please email them to os-signatures@nessus.org. Be sure to include a<br>brief description of the host itself, such as the actual operating<br>system or product / model names.<br> <br>SSH:SSH-2.0-OpenSSH_4.7p1 Debian-8ubuntu1<br>SinFP:<br> P1:B10113:F0x12:W5840:O0204ffff:M1460:<br> P2:B10113:F0x12:W5792:O0204ffff0402080affffffff4445414401030305:M1460:<br> P3:B10120:F0x04:W0:O0:M0<br> P4:61102_7_p=3306<br>SMTP:!:220 metasploitable.localdomain ESMTP Postfix (Ubuntu)<br>SSLcert:!:i/CN:ubuntu804-base.localdomaini/O:OCOSAi/OU:Office for Complication of Otherwise Simple Affairss/CN:ubuntu804-base.localdomains/O:OCOSAs/OU:Office for Complication of Otherwise Simple Affairs<br>ed093088706603bfd5dc237399b498da2d4d31c6<br> <br> <br> <br>The remote host is running Linux Kernel 2.6 on Ubuntu 8.04 (gutsy)</span><h2 xmlns="" class="classsection0" id="idm131524480">18261 (1) - Apache Banner Linux Distribution Disclosure</h2>
2717<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2718 <![endif]]]-->Synopsis</h2>
2719<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The name of the Linux distribution running on the remote host was found in the banner of the web server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2720 <![endif]]]-->Description</h2>
2721<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Nessus was able to extract the banner of the Apache web server and determine which Linux distribution the remote host is running.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2722 <![endif]]]-->Solution</h2>
2723<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">If you do not wish to display this information, edit 'httpd.conf' and set the directive 'ServerTokens Prod' and restart Apache.<br>n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2724 <![endif]]]-->Risk Factor</h2>
2725<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2726 <![endif]]]-->Plugin Information: </h2>
2727<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2005/05/15, Modification date: 2017/03/13</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2728 <![endif]]]-->Hosts</h2>
2729<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/0)</h2>
2730<span xmlns="" class="classpre"> <br>The Linux distribution detected was : <br> - Ubuntu 8.04 (gutsy)</span><h2 xmlns="" class="classsection0" id="idm131517440">19288 (1) - VNC Server Security Type Detection</h2>
2731<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2732 <![endif]]]-->Synopsis</h2>
2733<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A VNC server is running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2734 <![endif]]]-->Description</h2>
2735<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This script checks the remote VNC server protocol version and the available 'security types'.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2736 <![endif]]]-->Solution</h2>
2737<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2738 <![endif]]]-->Risk Factor</h2>
2739<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2740 <![endif]]]-->Plugin Information: </h2>
2741<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2005/07/22, Modification date: 2014/03/12</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2742 <![endif]]]-->Hosts</h2>
2743<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/5900)</h2>
2744<span xmlns="" class="classpre"> <br>The remote VNC server chose security type #2 (VNC authentication)</span><h2 xmlns="" class="classsection0" id="idm131511040">19506 (1) - Nessus Scan Information</h2>
2745<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2746 <![endif]]]-->Synopsis</h2>
2747<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin displays information about the Nessus scan.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2748 <![endif]]]-->Description</h2>
2749<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin displays, for each tested host, information about the scan itself :<br> <br> - The version of the plugin set.<br> - The type of scanner (Nessus or Nessus Home).<br> - The version of the Nessus Engine.<br> - The port scanner(s) used.<br> - The port range scanned.<br> - Whether credentialed or third-party patch management checks are possible.<br> - The date of the scan.<br> - The duration of the scan.<br> - The number of hosts scanned in parallel.<br> - The number of checks done in parallel.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2750 <![endif]]]-->Solution</h2>
2751<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2752 <![endif]]]-->Risk Factor</h2>
2753<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2754 <![endif]]]-->Plugin Information: </h2>
2755<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2005/08/26, Modification date: 2017/10/26</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2756 <![endif]]]-->Hosts</h2>
2757<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/0)</h2>
2758<span xmlns="" class="classpre">Information about this scan : <br> <br>Nessus version : 6.11.2<br>Plugin feed version : 201711031815<br>Scanner edition used : Nessus<br>Scan type : Normal<br>Scan policy used : Advanced Scan<br>Scanner IP : 192.168.189.130<br>Port scanner(s) : nessus_syn_scanner <br>Port range : default<br>Thorough tests : no<br>Experimental tests : no<br>Paranoia level : 1<br>Report verbosity : 1<br>Safe checks : yes<br>Optimize the test : yes<br>Credentialed checks : no<br>Patch management checks : None<br>CGI scanning : disabled<br>Web application tests : disabled<br>Max hosts : 100<br>Max checks : 5<br>Recv timeout : 5<br>Backports : Detected<br>Allow post-scan editing: Yes<br>Scan Start Date : 2017/11/5 13:41 EST<br>Scan duration : 498 sec</span><h2 xmlns="" class="classsection0" id="idm131495168">20094 (1) - VMware Virtual Machine Detection</h2>
2759<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2760 <![endif]]]-->Synopsis</h2>
2761<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is a VMware virtual machine.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2762 <![endif]]]-->Description</h2>
2763<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">According to the MAC address of its network adapter, the remote host is a VMware virtual machine.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2764 <![endif]]]-->Solution</h2>
2765<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Since it is physically accessible through the network, ensure that its configuration matches your organization's security policy.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2766 <![endif]]]-->Risk Factor</h2>
2767<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2768 <![endif]]]-->Plugin Information: </h2>
2769<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2005/10/27, Modification date: 2015/10/16</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2770 <![endif]]]-->Hosts</h2>
2771<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/0)</h2>
2772<span xmlns="" class="classpre"> <br>The remote host is a VMware virtual machine.</span><h2 xmlns="" class="classsection0" id="idm131480448">20108 (1) - Web Server / Application favicon.ico Vendor Fingerprinting</h2>
2773<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2774 <![endif]]]-->Synopsis</h2>
2775<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote web server contains a graphic image that is prone to information disclosure.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2776 <![endif]]]-->Description</h2>
2777<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The 'favicon.ico' file found on the remote web server belongs to a popular web server. This may be used to fingerprint the web server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2778 <![endif]]]-->Solution</h2>
2779<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Remove the 'favicon.ico' file or create a custom one for your site.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2780 <![endif]]]-->Risk Factor</h2>
2781<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2782 <![endif]]]-->References</h2>
2783<table xmlns="" width="100%"><tr>
2784<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
2785<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:39272</span></td>
2786</tr></table>
2787<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2788 <![endif]]]-->Plugin Information: </h2>
2789<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2005/10/28, Modification date: 2014/10/14</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2790 <![endif]]]-->Hosts</h2>
2791<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/8180)</h2>
2792<span xmlns="" class="classpre"> <br> MD5 fingerprint : 4644f2d45601037b8423d45e13194c93<br> Web server : Apache Tomcat or Alfresco Community</span><h2 xmlns="" class="classsection0" id="idm131471488">21186 (1) - AJP Connector Detection</h2>
2793<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2794 <![endif]]]-->Synopsis</h2>
2795<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">There is an AJP connector listening on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2796 <![endif]]]-->Description</h2>
2797<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running an AJP (Apache JServ Protocol) connector, a service by which a standalone web server such as Apache communicates over TCP with a Java servlet container such as Tomcat.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2798 <![endif]]]-->See Also</h2>
2799<table xmlns="" width="100%">
2800<tr><td width="100%" valign="top" class="classcell"> <a href="http://tomcat.apache.org/connectors-doc/" target="_blank">http://tomcat.apache.org/connectors-doc/</a>
2801</td></tr>
2802<tr><td width="100%" valign="top" class="classcell"> <a href="http://tomcat.apache.org/connectors-doc/ajp/ajpv13a.html" target="_blank">http://tomcat.apache.org/connectors-doc/ajp/ajpv13a.html</a>
2803</td></tr>
2804</table>
2805<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2806 <![endif]]]-->Solution</h2>
2807<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2808 <![endif]]]-->Risk Factor</h2>
2809<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2810 <![endif]]]-->Plugin Information: </h2>
2811<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2006/04/05, Modification date: 2011/03/11</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2812 <![endif]]]-->Hosts</h2>
2813<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/8009)</h2>
2814<span xmlns="" class="classpre"> <br>The connector listing on this port supports the ajp13 protocol.</span><h2 xmlns="" class="classsection0" id="idm131437440">21643 (1) - SSL Cipher Suites Supported</h2>
2815<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2816 <![endif]]]-->Synopsis</h2>
2817<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service encrypts communications using SSL.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2818 <![endif]]]-->Description</h2>
2819<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2820 <![endif]]]-->See Also</h2>
2821<table xmlns="" width="100%">
2822<tr><td width="100%" valign="top" class="classcell"> <a href="https://www.openssl.org/docs/man1.1.0/apps/ciphers.html" target="_blank">https://www.openssl.org/docs/man1.1.0/apps/ciphers.html</a>
2823</td></tr>
2824<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?3a040ada" target="_blank">http://www.nessus.org/u?3a040ada</a>
2825</td></tr>
2826</table>
2827<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2828 <![endif]]]-->Solution</h2>
2829<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2830 <![endif]]]-->Risk Factor</h2>
2831<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2832 <![endif]]]-->Plugin Information: </h2>
2833<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2006/06/05, Modification date: 2017/09/01</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2834 <![endif]]]-->Hosts</h2>
2835<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
2836<span xmlns="" class="classpre"> <br>Here is the list of SSL ciphers supported by the remote server :<br>Each group is reported per SSL Version.<br> <br>SSL Version : TLSv1<br> Low Strength Ciphers (<= 64-bit key)<br> <br> EXP-EDH-RSA-DES-CBC-SHA Kx=DH(512) Au=RSA Enc=DES-CBC(40) Mac=SHA1 export <br> EDH-RSA-DES-CBC-SHA Kx=DH Au=RSA Enc=DES-CBC(56) Mac=SHA1 <br> EXP-ADH-DES-CBC-SHA Kx=DH(512) Au=None Enc=DES-CBC(40) Mac=SHA1 export <br> EXP-ADH-RC4-MD5 Kx=DH(512) Au=None Enc=RC4(40) Mac=MD5 export <br> ADH-DES-CBC-SHA Kx=DH Au=None Enc=DES-CBC(56) Mac=SHA1 <br> EXP-DES-CBC-SHA Kx=RSA(512) Au=RSA Enc=DES-CBC(40) Mac=SHA1 export <br> EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2-CBC(40) Mac=MD5 export <br> EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export <br> DES-CBC-SHA Kx=RSA Au=RSA Enc=DES-CBC(56) Mac=SHA1 <br> <br> Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)<br> <br> EDH-RSA-DES-CBC3-SHA Kx=DH Au=RSA Enc=3DES-CBC(168) Mac=SHA1 <br> ADH-DES-CBC3-SHA Kx=DH Au=None Enc=3DES-CBC(168) Mac=SHA1 <br> DES-CBC3-SHA Kx=RSA Au=RSA Enc=3DES-CBC(168) Mac=SHA1 <br> <br> High Strength Ciphers (>= 112-bit key)<br> <br> DHE-RSA-AES128-SHA Kx=DH Au=RSA Enc=AES-CBC(128) Mac=SHA1 <br> DHE-RSA-AES256-SHA Kx=DH Au=RSA Enc=AES-CBC(256) Mac=SHA1 <br> ADH-AES128-SHA Kx=DH Au=None Enc=AES-CBC(128) Mac=SHA1 <br> ADH-AES256-SHA Kx=DH Au=None Enc=AES-CBC(256) Mac=SHA1 <br> ADH-RC4-MD5 Kx=DH Au=None Enc=RC4(128) Mac=MD5 <br> AES128-SHA Kx=RSA Au=RSA Enc=AES-CBC(128) Mac=SHA1 <br> AES256-SHA Kx=RSA Au=RSA Enc=AES-CBC(256) Mac=SHA1 <br> RC4-MD5 Kx=RSA Au=RSA Enc=RC4(128) Mac=MD5 <br> RC4-SHA Kx=RSA Au=RSA Enc=RC4(128) Mac=SHA1 <br> <br> <br>SSL Version : SSLv3<br> Low Strength Ciphers (<= 64-bit key)<br> <br> EXP-EDH-RSA-DES-CBC-SHA Kx=DH(512) Au=RSA Enc=DES-CBC(40) Mac=SHA1 export <br> EDH-RSA-DES-CBC-SHA Kx=DH Au=RSA Enc=DES-CBC(56) Mac=SHA1 <br> EXP-ADH-DES-CBC-SHA Kx=DH(512) Au=None Enc=DES-CBC(40) Mac=SHA1 export <br> EXP-ADH-RC4-MD5 Kx=DH(512) Au=None Enc=RC4(40) Mac=MD5 export <br> ADH-DES-CBC-SHA Kx=DH Au=None Enc=DES-CBC(56) Mac=SHA1 <br> EXP-DES-CBC-SHA Kx=RSA(512) Au=RSA Enc=DES-CBC(40) Mac=SHA1 export <br> EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2-CBC(40) Mac=MD5 export <br> EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export <br> DES-CBC-SHA Kx=RSA Au=RSA Enc=DES-CBC(56) Mac=SHA1 <br> <br> Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)<br> <br> EDH-RSA-DES-CBC3-SHA Kx=DH Au=RSA Enc=3DES-CBC(168) Mac=SHA1 <br> ADH-DES-CBC3-SHA Kx=DH Au=None Enc=3DES-CBC(168) Mac=SHA1 <br> DES-CBC3-SHA Kx=RSA Au=RSA Enc=3DES-CBC(168) Mac=SHA1 <br> <br> High Strength Ciphers (>= 112-bit key)<br> <br> DHE-RSA-AES128-SHA Kx=DH Au=RSA Enc=AES-CBC(128) Mac=SHA1 <br> DHE-RSA-AES256-SHA Kx=DH Au=RSA Enc=AES-CBC(256) Mac=SHA1 <br> ADH-AES128-SHA Kx=DH Au=None Enc=AES-CBC(128) Mac=SHA1 <br> ADH-AES256-SHA Kx=DH Au=None Enc=AES-CBC(256) Mac=SHA1 <br> ADH-RC4-MD5 Kx=DH Au=None Enc=RC4(128) Mac=MD5 <br> AES128-SHA Kx=RSA Au=RSA Enc=AES-CBC(128) Mac=SHA1 <br> AES256-SHA Kx=RSA Au=RSA Enc=AES-CBC(256) Mac=SHA1 <br> RC4-MD5 Kx=RSA Au=RSA Enc=RC4(128) Mac=MD5 <br> RC4-SHA Kx=RSA Au=RSA Enc=RC4(128) Mac=SHA1 <br> <br> <br>SSL Version : SSLv2<br> Low Strength Ciphers (<= 64-bit key)<br> <br> DES-CBC-MD5 Kx=RSA Au=RSA Enc=DES-CBC(56) Mac=MD5 <br> EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2-CBC(40) Mac=MD5 export <br> EXP-RC4-MD5 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export <br> <br> Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)<br> <br> DES-CBC3-MD5 Kx=RSA Au=RSA Enc=3DES-CBC(168) Mac=MD5 <br> <br> High Strength Ciphers (>= 112-bit key)<br> <br> RC2-CBC-MD5 Kx=RSA Au=RSA Enc=RC2-CBC(128) Mac=MD5 <br> RC4-MD5 Kx=RSA Au=RSA Enc=RC4(128) Mac=MD5 <br> <br>The fields above are :<br> <br> {OpenSSL ciphername}<br> Kx={key exchange}<br> Au={authentication}<br> Enc={symmetric encryption method}<br> Mac={message authentication code}<br> {export flag}</span><h2 xmlns="" class="classsection0" id="idm131392256">22227 (1) - RMI Registry Detection</h2>
2837<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2838 <![endif]]]-->Synopsis</h2>
2839<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An RMI registry is listening on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2840 <![endif]]]-->Description</h2>
2841<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running an RMI registry, which acts as a bootstrap naming service for registering and retrieving remote objects with simple names in the Java Remote Method Invocation (RMI) system.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2842 <![endif]]]-->See Also</h2>
2843<table xmlns="" width="100%">
2844<tr><td width="100%" valign="top" class="classcell"> <a href="http://docs.oracle.com/javase/1.5.0/docs/guide/rmi/spec/rmiTOC.html" target="_blank">http://docs.oracle.com/javase/1.5.0/docs/guide/rmi/spec/rmiTOC.html</a>
2845</td></tr>
2846<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?eb68319f" target="_blank">http://www.nessus.org/u?eb68319f</a>
2847</td></tr>
2848</table>
2849<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2850 <![endif]]]-->Solution</h2>
2851<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2852 <![endif]]]-->Risk Factor</h2>
2853<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2854 <![endif]]]-->Plugin Information: </h2>
2855<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2006/08/16, Modification date: 2016/04/20</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2856 <![endif]]]-->Hosts</h2>
2857<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/1099)</h2>
2858<h2 xmlns="" class="classsection0" id="idm131383424">25220 (1) - TCP/IP Timestamps Supported</h2>
2859<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2860 <![endif]]]-->Synopsis</h2>
2861<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service implements TCP timestamps.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2862 <![endif]]]-->Description</h2>
2863<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host implements TCP timestamps, as defined by RFC1323. A side effect of this feature is that the uptime of the remote host can sometimes be computed.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2864 <![endif]]]-->See Also</h2>
2865<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="http://www.ietf.org/rfc/rfc1323.txt" target="_blank">http://www.ietf.org/rfc/rfc1323.txt</a>
2866</td></tr></table>
2867<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2868 <![endif]]]-->Solution</h2>
2869<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2870 <![endif]]]-->Risk Factor</h2>
2871<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2872 <![endif]]]-->Plugin Information: </h2>
2873<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2007/05/16, Modification date: 2011/03/20</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2874 <![endif]]]-->Hosts</h2>
2875<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/0)</h2>
2876<h2 xmlns="" class="classsection0" id="idm131376000">25240 (1) - Samba Server Detection</h2>
2877<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2878 <![endif]]]-->Synopsis</h2>
2879<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An SMB server is running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2880 <![endif]]]-->Description</h2>
2881<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running Samba, a CIFS/SMB server for Linux and Unix.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2882 <![endif]]]-->See Also</h2>
2883<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="http://www.samba.org/" target="_blank">http://www.samba.org/</a>
2884</td></tr></table>
2885<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2886 <![endif]]]-->Solution</h2>
2887<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2888 <![endif]]]-->Risk Factor</h2>
2889<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2890 <![endif]]]-->Plugin Information: </h2>
2891<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2007/05/16, Modification date: 2013/01/07</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2892 <![endif]]]-->Hosts</h2>
2893<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/445)</h2>
2894<h2 xmlns="" class="classsection0" id="idm131368448">26024 (1) - PostgreSQL Server Detection</h2>
2895<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2896 <![endif]]]-->Synopsis</h2>
2897<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A database service is listening on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2898 <![endif]]]-->Description</h2>
2899<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service is a PostgreSQL database server, or a derivative such as EnterpriseDB.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2900 <![endif]]]-->See Also</h2>
2901<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="http://www.postgresql.org/" target="_blank">http://www.postgresql.org/</a>
2902</td></tr></table>
2903<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2904 <![endif]]]-->Solution</h2>
2905<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Limit incoming traffic to this port if desired.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2906 <![endif]]]-->Risk Factor</h2>
2907<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2908 <![endif]]]-->Plugin Information: </h2>
2909<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2007/09/14, Modification date: 2013/02/14</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2910 <![endif]]]-->Hosts</h2>
2911<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/5432)</h2>
2912<h2 xmlns="" class="classsection0" id="idm131352704">35371 (1) - DNS Server hostname.bind Map Hostname Disclosure</h2>
2913<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2914 <![endif]]]-->Synopsis</h2>
2915<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The DNS server discloses the remote host name.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2916 <![endif]]]-->Description</h2>
2917<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to learn the remote host name by querying the remote DNS server for 'hostname.bind' in the CHAOS domain.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2918 <![endif]]]-->Solution</h2>
2919<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It may be possible to disable this feature. Consult the vendor's documentation for more information.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2920 <![endif]]]-->Risk Factor</h2>
2921<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2922 <![endif]]]-->Plugin Information: </h2>
2923<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2009/01/15, Modification date: 2011/09/14</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2924 <![endif]]]-->Hosts</h2>
2925<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (udp/53)</h2>
2926<span xmlns="" class="classpre"> <br>The remote host name is :<br> <br>metasploitable</span><h2 xmlns="" class="classsection0" id="idm131345664">35716 (1) - Ethernet Card Manufacturer Detection</h2>
2927<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2928 <![endif]]]-->Synopsis</h2>
2929<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The manufacturer can be identified from the Ethernet OUI.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2930 <![endif]]]-->Description</h2>
2931<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Each ethernet MAC address starts with a 24-bit Organizationally Unique Identifier (OUI). These OUIs are registered by IEEE.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2932 <![endif]]]-->See Also</h2>
2933<table xmlns="" width="100%">
2934<tr><td width="100%" valign="top" class="classcell"> <a href="http://standards.ieee.org/faqs/regauth.html" target="_blank">http://standards.ieee.org/faqs/regauth.html</a>
2935</td></tr>
2936<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?794673b4" target="_blank">http://www.nessus.org/u?794673b4</a>
2937</td></tr>
2938</table>
2939<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2940 <![endif]]]-->Solution</h2>
2941<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2942 <![endif]]]-->Risk Factor</h2>
2943<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2944 <![endif]]]-->Plugin Information: </h2>
2945<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2009/02/19, Modification date: 2015/10/16</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2946 <![endif]]]-->Hosts</h2>
2947<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/0)</h2>
2948<span xmlns="" class="classpre"> <br>The following card manufacturers were identified :<br> <br>00:0c:29:b6:d1:83 : VMware, Inc.</span><h2 xmlns="" class="classsection0" id="idm131331456">39446 (1) - Apache Tomcat Default Error Page Version Detection</h2>
2949<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2950 <![endif]]]-->Synopsis</h2>
2951<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote web server reports its version number on error pages.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2952 <![endif]]]-->Description</h2>
2953<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Apache Tomcat is running on the remote host and is reporting its version number on the default error pages. A remote attacker can exploit this information to mount further attacks.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2954 <![endif]]]-->See Also</h2>
2955<table xmlns="" width="100%">
2956<tr><td width="100%" valign="top" class="classcell"> <a href="http://wiki.apache.org/tomcat/FAQ/Miscellaneous#Q6" target="_blank">http://wiki.apache.org/tomcat/FAQ/Miscellaneous#Q6</a>
2957</td></tr>
2958<tr><td width="100%" valign="top" class="classcell"> <a href="http://jcp.org/en/jsr/detail?id=315" target="_blank">http://jcp.org/en/jsr/detail?id=315</a>
2959</td></tr>
2960</table>
2961<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2962 <![endif]]]-->Solution</h2>
2963<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Replace the default error pages with custom error pages to hide the version number. Refer to the Apache wiki or the Java Servlet Specification for more information.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2964 <![endif]]]-->Risk Factor</h2>
2965<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2966 <![endif]]]-->Plugin Information: </h2>
2967<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2009/06/18, Modification date: 2016/05/09</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2968 <![endif]]]-->Hosts</h2>
2969<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/8180)</h2>
2970<span xmlns="" class="classpre"> <br>Nessus found the following version information on an Apache Tomcat<br>404 page or in the HTTP Server header :<br> <br> Source : <title>Apache Tomcat/5.5<br> Version : 5.5</span><h2 xmlns="" class="classsection0" id="idm131312640">39519 (1) - Backported Security Patch Detection (FTP)</h2>
2971<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2972 <![endif]]]-->Synopsis</h2>
2973<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Security patches are backported.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2974 <![endif]]]-->Description</h2>
2975<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Security patches may have been 'backported' to the remote FTP server without changing its version number. <br> <br>Banner-based checks have been disabled to avoid false positives. <br> <br>Note that this test is informational only and does not denote any security problem.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2976 <![endif]]]-->See Also</h2>
2977<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="https://access.redhat.com/security/updates/backporting/?sc_cid=3093" target="_blank">https://access.redhat.com/security/updates/backporting/?sc_cid=3093</a>
2978</td></tr></table>
2979<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2980 <![endif]]]-->Solution</h2>
2981<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2982 <![endif]]]-->Risk Factor</h2>
2983<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2984 <![endif]]]-->Plugin Information: </h2>
2985<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2009/06/25, Modification date: 2015/07/07</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2986 <![endif]]]-->Hosts</h2>
2987<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/2121)</h2>
2988<span xmlns="" class="classpre"> <br>Give Nessus credentials to perform local checks.</span><h2 xmlns="" class="classsection0" id="idm131291008">39520 (1) - Backported Security Patch Detection (SSH)</h2>
2989<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2990 <![endif]]]-->Synopsis</h2>
2991<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Security patches are backported.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2992 <![endif]]]-->Description</h2>
2993<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Security patches may have been 'backported' to the remote SSH server without changing its version number. <br> <br>Banner-based checks have been disabled to avoid false positives. <br> <br>Note that this test is informational only and does not denote any security problem.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2994 <![endif]]]-->See Also</h2>
2995<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="https://access.redhat.com/security/updates/backporting/?sc_cid=3093" target="_blank">https://access.redhat.com/security/updates/backporting/?sc_cid=3093</a>
2996</td></tr></table>
2997<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
2998 <![endif]]]-->Solution</h2>
2999<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3000 <![endif]]]-->Risk Factor</h2>
3001<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3002 <![endif]]]-->Plugin Information: </h2>
3003<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2009/06/25, Modification date: 2015/07/07</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3004 <![endif]]]-->Hosts</h2>
3005<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/22)</h2>
3006<span xmlns="" class="classpre"> <br>Give Nessus credentials to perform local checks.</span><h2 xmlns="" class="classsection0" id="idm131269376">39521 (1) - Backported Security Patch Detection (WWW)</h2>
3007<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3008 <![endif]]]-->Synopsis</h2>
3009<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Security patches are backported.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3010 <![endif]]]-->Description</h2>
3011<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Security patches may have been 'backported' to the remote HTTP server without changing its version number.<br> <br>Banner-based checks have been disabled to avoid false positives.<br> <br>Note that this test is informational only and does not denote any security problem.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3012 <![endif]]]-->See Also</h2>
3013<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="https://access.redhat.com/security/updates/backporting/?sc_cid=3093" target="_blank">https://access.redhat.com/security/updates/backporting/?sc_cid=3093</a>
3014</td></tr></table>
3015<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3016 <![endif]]]-->Solution</h2>
3017<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3018 <![endif]]]-->Risk Factor</h2>
3019<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3020 <![endif]]]-->Plugin Information: </h2>
3021<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2009/06/25, Modification date: 2015/07/07</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3022 <![endif]]]-->Hosts</h2>
3023<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/80)</h2>
3024<span xmlns="" class="classpre"> <br>Give Nessus credentials to perform local checks.</span><h2 xmlns="" class="classsection0" id="idm131255936">42088 (1) - SMTP Service STARTTLS Command Support</h2>
3025<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3026 <![endif]]]-->Synopsis</h2>
3027<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote mail service supports encrypting traffic.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3028 <![endif]]]-->Description</h2>
3029<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote SMTP service supports the use of the 'STARTTLS' command to switch from a cleartext to an encrypted communications channel.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3030 <![endif]]]-->See Also</h2>
3031<table xmlns="" width="100%">
3032<tr><td width="100%" valign="top" class="classcell"> <a href="https://en.wikipedia.org/wiki/STARTTLS" target="_blank">https://en.wikipedia.org/wiki/STARTTLS</a>
3033</td></tr>
3034<tr><td width="100%" valign="top" class="classcell"> <a href="https://tools.ietf.org/html/rfc2487" target="_blank">https://tools.ietf.org/html/rfc2487</a>
3035</td></tr>
3036</table>
3037<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3038 <![endif]]]-->Solution</h2>
3039<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3040 <![endif]]]-->Risk Factor</h2>
3041<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3042 <![endif]]]-->Plugin Information: </h2>
3043<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2009/10/09, Modification date: 2017/06/15</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3044 <![endif]]]-->Hosts</h2>
3045<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
3046<span xmlns="" class="classpre"> <br>Here is the SMTP service's SSL certificate that Nessus was able to<br>collect after sending a 'STARTTLS' command :<br> <br>------------------------------ snip ------------------------------<br>Subject Name: <br> <br>Country: XX<br>State/Province: There is no such thing outside US<br>Locality: Everywhere<br>Organization: OCOSA<br>Organization Unit: Office for Complication of Otherwise Simple Affairs<br>Common Name: ubuntu804-base.localdomain<br>Email Address: root@ubuntu804-base.localdomain<br> <br>Issuer Name: <br> <br>Country: XX<br>State/Province: There is no such thing outside US<br>Locality: Everywhere<br>Organization: OCOSA<br>Organization Unit: Office for Complication of Otherwise Simple Affairs<br>Common Name: ubuntu804-base.localdomain<br>Email Address: root@ubuntu804-base.localdomain<br> <br>Serial Number: 00 FA F9 3A 4C 7F B6 B9 CC <br> <br>Version: 1<br> <br>Signature Algorithm: SHA-1 With RSA Encryption<br> <br>Not Valid Before: Mar 17 14:07:45 2010 GMT<br>Not Valid After: Apr 16 14:07:45 2010 GMT<br> <br>Public Key Info: <br> <br>Algorithm: RSA Encryption<br>Key Length: 1024 bits<br>Public Key: 00 D6 B4 13 36 33 9A 95 71 7B 1B DE 7C 83 75 DA 71 B1 3C A9 <br> 7F FE AD 64 1B 77 E9 4F AE BE CA D4 F8 CB EF AE BB 43 79 24 <br> 73 FF 3C E5 9E 3B 6D FC C8 B1 AC FA 4C 4D 5E 9B 4C 99 54 0B <br> D7 A8 4A 50 BA A9 DE 1D 1F F4 E4 6B 02 A3 F4 6B 45 CD 4C AF <br> 8D 89 62 33 8F 65 BB 36 61 9F C4 2C 73 C1 4E 2E A0 A8 14 4E <br> 98 70 46 61 BB D1 B9 31 DF 8C 99 EE 75 6B 79 3C 40 A0 AE 97 <br> 00 90 9D DC 99 0D 33 A4 B5 <br>Exponent: 01 00 01 <br> <br>Signature Length: 128 bytes / 1024 bits<br>Signature: 00 92 A4 B4 B8 14 55 63 25 51 4A 0B C3 2A 22 CF 3A F8 17 6A <br> 0C CF 66 AA A7 65 2F 48 6D CD E3 3E 5C 9F 77 6C D4 44 54 1F <br> 1E 84 4F 8E D4 8D DD AC 2D 88 09 21 A8 DA 56 2C A9 05 3C 49 <br> 68 35 19 75 0C DA 53 23 88 88 19 2D 74 26 C1 22 65 EE 11 68 <br> 83 6A 53 4A 9C 27 CB A0 B4 E9 8D 29 0C B2 3C 18 5C 67 CC 53 <br> A6 1E 30 D0 AA 26 7B 1E AE 40 B9 29 01 6C 2E BC A2 19 94 7C <br> 15 6E 8D 30 38 F6 CA 2E 75 <br> <br>------------------------------ snip ------------------------------</span><h2 xmlns="" class="classsection0" id="idm131219840">45410 (1) - SSL Certificate 'commonName' Mismatch</h2>
3047<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3048 <![endif]]]-->Synopsis</h2>
3049<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The 'commonName' (CN) attribute in the SSL certificate does not match the hostname.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3050 <![endif]]]-->Description</h2>
3051<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The service running on the remote host presents an SSL certificate for which the 'commonName' (CN) attribute does not match the hostname on which the service listens.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3052 <![endif]]]-->Solution</h2>
3053<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">If the machine has several names, make sure that users connect to the service through the DNS hostname that matches the common name in the certificate.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3054 <![endif]]]-->Risk Factor</h2>
3055<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3056 <![endif]]]-->Plugin Information: </h2>
3057<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2010/04/03, Modification date: 2017/06/05</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3058 <![endif]]]-->Hosts</h2>
3059<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
3060<span xmlns="" class="classpre"> <br>The host name known by Nessus is :<br> <br> metasploitable<br> <br>The Common Name in the certificate is :<br> <br> ubuntu804-base.localdomain</span><h2 xmlns="" class="classsection0" id="idm131211776">45590 (1) - Common Platform Enumeration (CPE)</h2>
3061<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3062 <![endif]]]-->Synopsis</h2>
3063<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It was possible to enumerate CPE names that matched on the remote system.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3064 <![endif]]]-->Description</h2>
3065<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">By using information obtained from a Nessus scan, this plugin reports CPE (Common Platform Enumeration) matches for various hardware and software products found on a host. <br> <br>Note that if an official CPE is not available for the product, this plugin computes the best possible CPE based on the information available from the scan.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3066 <![endif]]]-->See Also</h2>
3067<table xmlns="" width="100%">
3068<tr><td width="100%" valign="top" class="classcell"> <a href="http://cpe.mitre.org/" target="_blank">http://cpe.mitre.org/</a>
3069</td></tr>
3070<tr><td width="100%" valign="top" class="classcell"> <a href="https://nvd.nist.gov/products/cpe" target="_blank">https://nvd.nist.gov/products/cpe</a>
3071</td></tr>
3072</table>
3073<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3074 <![endif]]]-->Solution</h2>
3075<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3076 <![endif]]]-->Risk Factor</h2>
3077<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3078 <![endif]]]-->Plugin Information: </h2>
3079<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2010/04/21, Modification date: 2017/06/06</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3080 <![endif]]]-->Hosts</h2>
3081<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/0)</h2>
3082<span xmlns="" class="classpre"> <br>The remote operating system matched the following CPE : <br> <br> cpe:/o:canonical:ubuntu_linux:8.04<br> <br>Following application CPE's matched on the remote system :<br> <br> cpe:/a:openbsd:openssh:4.7 -> OpenBSD OpenSSH 4.7<br> cpe:/a:samba:samba:3.0.20 -> Samba 3.0.20<br> cpe:/a:apache:http_server:2.2.8 -> Apache Software Foundation Apache HTTP Server 2.2.8<br> cpe:/a:php:php:5.2.4 -> PHP 5.2.4<br> cpe:/a:isc:bind:9.4.</span><h2 xmlns="" class="classsection0" id="idm131195008">48243 (1) - PHP Version Detection</h2>
3083<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3084 <![endif]]]-->Synopsis</h2>
3085<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It was possible to obtain the version number of the remote PHP installation.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3086 <![endif]]]-->Description</h2>
3087<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Nessus was able to determine the version of PHP available on the remote web server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3088 <![endif]]]-->Solution</h2>
3089<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3090 <![endif]]]-->Risk Factor</h2>
3091<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3092 <![endif]]]-->Plugin Information: </h2>
3093<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2010/08/04, Modification date: 2017/07/07</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3094 <![endif]]]-->Hosts</h2>
3095<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/80)</h2>
3096<span xmlns="" class="classpre"> <br>Nessus was able to identify the following PHP version information :<br> <br> Version : 5.2.4-2ubuntu5.10<br> Source : X-Powered-By: PHP/5.2.4-2ubuntu5.10</span><h2 xmlns="" class="classsection0" id="idm131187840">50845 (1) - OpenSSL Detection</h2>
3097<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3098 <![endif]]]-->Synopsis</h2>
3099<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service appears to use OpenSSL to encrypt traffic.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3100 <![endif]]]-->Description</h2>
3101<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Based on its response to a TLS request with a specially crafted server name extension, it seems that the remote service is using the OpenSSL library to encrypt traffic.<br> <br>Note that this plugin can only detect OpenSSL implementations that have enabled support for TLS extensions (RFC 4366).</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3102 <![endif]]]-->See Also</h2>
3103<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="http://www.openssl.org" target="_blank">http://www.openssl.org</a>
3104</td></tr></table>
3105<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3106 <![endif]]]-->Solution</h2>
3107<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3108 <![endif]]]-->Risk Factor</h2>
3109<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3110 <![endif]]]-->Plugin Information: </h2>
3111<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2010/11/30, Modification date: 2013/10/18</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3112 <![endif]]]-->Hosts</h2>
3113<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
3114<h2 xmlns="" class="classsection0" id="idm131179648">51891 (1) - SSL Session Resume Supported</h2>
3115<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3116 <![endif]]]-->Synopsis</h2>
3117<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host allows resuming SSL sessions.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3118 <![endif]]]-->Description</h2>
3119<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This script detects whether a host allows resuming SSL sessions by performing a full SSL handshake to receive a session ID, and then reconnecting with the previously used session ID. If the server accepts the session ID in the second connection, the server maintains a cache of sessions that can be resumed.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3120 <![endif]]]-->Solution</h2>
3121<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3122 <![endif]]]-->Risk Factor</h2>
3123<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3124 <![endif]]]-->Plugin Information: </h2>
3125<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2011/02/07, Modification date: 2013/10/18</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3126 <![endif]]]-->Hosts</h2>
3127<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
3128<span xmlns="" class="classpre"> <br>This port supports resuming SSLv3 sessions.</span><h2 xmlns="" class="classsection0" id="idm131164928">52703 (1) - vsftpd Detection</h2>
3129<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3130 <![endif]]]-->Synopsis</h2>
3131<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An FTP server is listening on the remote port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3132 <![endif]]]-->Description</h2>
3133<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is running vsftpd, an FTP server for UNIX-like systems written in C.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3134 <![endif]]]-->See Also</h2>
3135<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="http://vsftpd.beasts.org/" target="_blank">http://vsftpd.beasts.org/</a>
3136</td></tr></table>
3137<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3138 <![endif]]]-->Solution</h2>
3139<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3140 <![endif]]]-->Risk Factor</h2>
3141<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3142 <![endif]]]-->Plugin Information: </h2>
3143<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2011/03/17, Modification date: 2013/03/21</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3144 <![endif]]]-->Hosts</h2>
3145<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/21)</h2>
3146<span xmlns="" class="classpre"> <br> Source : 220 (vsFTPd 2.3.4)<br> Version : 2.3.4</span><h2 xmlns="" class="classsection0" id="idm131156352">53335 (1) - RPC portmapper (TCP)</h2>
3147<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3148 <![endif]]]-->Synopsis</h2>
3149<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An ONC RPC portmapper is running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3150 <![endif]]]-->Description</h2>
3151<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The RPC portmapper is running on this port. <br> <br>The portmapper allows someone to get the port number of each RPC service running on the remote host by sending either multiple lookup requests or a DUMP request.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3152 <![endif]]]-->Solution</h2>
3153<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3154 <![endif]]]-->Risk Factor</h2>
3155<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3156 <![endif]]]-->Plugin Information: </h2>
3157<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2011/04/08, Modification date: 2011/08/29</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3158 <![endif]]]-->Hosts</h2>
3159<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/111)</h2>
3160<h2 xmlns="" class="classsection0" id="idm131145984">54615 (1) - Device Type</h2>
3161<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3162 <![endif]]]-->Synopsis</h2>
3163<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It is possible to guess the remote device type.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3164 <![endif]]]-->Description</h2>
3165<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Based on the remote operating system, it is possible to determine what the remote system type is (eg: a printer, router, general-purpose computer, etc).</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3166 <![endif]]]-->Solution</h2>
3167<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3168 <![endif]]]-->Risk Factor</h2>
3169<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3170 <![endif]]]-->Plugin Information: </h2>
3171<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2011/05/23, Modification date: 2011/05/23</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3172 <![endif]]]-->Hosts</h2>
3173<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/0)</h2>
3174<span xmlns="" class="classpre">Remote device type : general-purpose<br>Confidence level : 95</span><h2 xmlns="" class="classsection0" id="idm131131264">56984 (1) - SSL / TLS Versions Supported</h2>
3175<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3176 <![endif]]]-->Synopsis</h2>
3177<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service encrypts communications.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3178 <![endif]]]-->Description</h2>
3179<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3180 <![endif]]]-->Solution</h2>
3181<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3182 <![endif]]]-->Risk Factor</h2>
3183<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3184 <![endif]]]-->Plugin Information: </h2>
3185<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2011/12/01, Modification date: 2017/06/15</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3186 <![endif]]]-->Hosts</h2>
3187<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
3188<span xmlns="" class="classpre"> <br>This port supports SSLv2/SSLv3/TLSv1.0.</span><h2 xmlns="" class="classsection0" id="idm131124608">57041 (1) - SSL Perfect Forward Secrecy Cipher Suites Supported</h2>
3189<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3190 <![endif]]]-->Synopsis</h2>
3191<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3192 <![endif]]]-->Description</h2>
3193<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot be broken at a future date if the server's private key is compromised.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3194 <![endif]]]-->See Also</h2>
3195<table xmlns="" width="100%">
3196<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.openssl.org/docs/apps/ciphers.html" target="_blank">http://www.openssl.org/docs/apps/ciphers.html</a>
3197</td></tr>
3198<tr><td width="100%" valign="top" class="classcell"> <a href="https://en.wikipedia.org/wiki/Diffie-Hellman_key_exchange" target="_blank">https://en.wikipedia.org/wiki/Diffie-Hellman_key_exchange</a>
3199</td></tr>
3200<tr><td width="100%" valign="top" class="classcell"> <a href="https://en.wikipedia.org/wiki/Perfect_forward_secrecy" target="_blank">https://en.wikipedia.org/wiki/Perfect_forward_secrecy</a>
3201</td></tr>
3202</table>
3203<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3204 <![endif]]]-->Solution</h2>
3205<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3206 <![endif]]]-->Risk Factor</h2>
3207<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3208 <![endif]]]-->Plugin Information: </h2>
3209<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2011/12/07, Modification date: 2017/06/12</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3210 <![endif]]]-->Hosts</h2>
3211<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
3212<span xmlns="" class="classpre"> <br>Here is the list of SSL PFS ciphers supported by the remote server :<br> <br> Low Strength Ciphers (<= 64-bit key)<br> <br> EXP-EDH-RSA-DES-CBC-SHA Kx=DH(512) Au=RSA Enc=DES-CBC(40) Mac=SHA1 export <br> EDH-RSA-DES-CBC-SHA Kx=DH Au=RSA Enc=DES-CBC(56) Mac=SHA1 <br> <br> Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)<br> <br> EDH-RSA-DES-CBC3-SHA Kx=DH Au=RSA Enc=3DES-CBC(168) Mac=SHA1 <br> <br> High Strength Ciphers (>= 112-bit key)<br> <br> DHE-RSA-AES128-SHA Kx=DH Au=RSA Enc=AES-CBC(128) Mac=SHA1 <br> DHE-RSA-AES256-SHA Kx=DH Au=RSA Enc=AES-CBC(256) Mac=SHA1 <br> <br>The fields above are :<br> <br> {OpenSSL ciphername}<br> Kx={key exchange}<br> Au={authentication}<br> Enc={symmetric encryption method}<br> Mac={message authentication code}<br> {export flag}</span><h2 xmlns="" class="classsection0" id="idm131099776">62563 (1) - SSL Compression Methods Supported</h2>
3213<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3214 <![endif]]]-->Synopsis</h2>
3215<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service supports one or more compression methods for SSL connections.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3216 <![endif]]]-->Description</h2>
3217<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This script detects which compression methods are supported by the remote service for SSL connections.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3218 <![endif]]]-->See Also</h2>
3219<table xmlns="" width="100%">
3220<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.iana.org/assignments/comp-meth-ids/comp-meth-ids.xml" target="_blank">http://www.iana.org/assignments/comp-meth-ids/comp-meth-ids.xml</a>
3221</td></tr>
3222<tr><td width="100%" valign="top" class="classcell"> <a href="https://tools.ietf.org/html/rfc3749" target="_blank">https://tools.ietf.org/html/rfc3749</a>
3223</td></tr>
3224<tr><td width="100%" valign="top" class="classcell"> <a href="https://tools.ietf.org/html/rfc3943" target="_blank">https://tools.ietf.org/html/rfc3943</a>
3225</td></tr>
3226<tr><td width="100%" valign="top" class="classcell"> <a href="https://tools.ietf.org/html/rfc5246" target="_blank">https://tools.ietf.org/html/rfc5246</a>
3227</td></tr>
3228</table>
3229<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3230 <![endif]]]-->Solution</h2>
3231<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3232 <![endif]]]-->Risk Factor</h2>
3233<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3234 <![endif]]]-->Plugin Information: </h2>
3235<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2012/10/16, Modification date: 2017/06/12</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3236 <![endif]]]-->Hosts</h2>
3237<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
3238<span xmlns="" class="classpre"> <br>Nessus was able to confirm that the following compression method is <br>supported by the target :<br> <br> DEFLATE (0x01)</span><h2 xmlns="" class="classsection0" id="idm131087232">65792 (1) - VNC Server Unencrypted Communication Detection</h2>
3239<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3240 <![endif]]]-->Synopsis</h2>
3241<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">A VNC server with one or more unencrypted 'security-types' is running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3242 <![endif]]]-->Description</h2>
3243<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This script checks the remote VNC server protocol version and the available 'security types' to determine if any unencrypted 'security-types' are in use or available.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3244 <![endif]]]-->Solution</h2>
3245<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3246 <![endif]]]-->Risk Factor</h2>
3247<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3248 <![endif]]]-->Plugin Information: </h2>
3249<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2013/04/03, Modification date: 2014/03/12</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3250 <![endif]]]-->Hosts</h2>
3251<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/5900)</h2>
3252<span xmlns="" class="classpre"> <br>The remote VNC server supports the following security type<br>which does not perform full data communication encryption :<br> <br> 2 (VNC authentication)</span><h2 xmlns="" class="classsection0" id="idm131079936">66334 (1) - Patch Report</h2>
3253<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3254 <![endif]]]-->Synopsis</h2>
3255<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is missing several patches.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3256 <![endif]]]-->Description</h2>
3257<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host is missing one or more security patches. This plugin lists the newest version of each patch to install to make sure the remote host is up-to-date.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3258 <![endif]]]-->Solution</h2>
3259<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Install the patches listed below.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3260 <![endif]]]-->Risk Factor</h2>
3261<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3262 <![endif]]]-->Plugin Information: </h2>
3263<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2013/07/08, Modification date: 2017/10/17</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3264 <![endif]]]-->Hosts</h2>
3265<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/0)</h2>
3266<span xmlns="" class="classpre"> <br> <br>. You need to take the following 2 actions :<br> <br>[ Apache HTTP Server httpOnly Cookie Information Disclosure (57792) ]<br> <br>+ Action to take : Upgrade to Apache version 2.0.65 / 2.2.22 or later.<br> <br> <br>[ Samba Badlock Vulnerability (90509) ]<br> <br>+ Action to take : Upgrade to Samba version 4.2.11 / 4.3.8 / 4.4.2 or later.<br> <br> </span><h2 xmlns="" class="classsection0" id="idm131066240">70544 (1) - SSL Cipher Block Chaining Cipher Suites Supported</h2>
3267<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3268 <![endif]]]-->Synopsis</h2>
3269<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3270 <![endif]]]-->Description</h2>
3271<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic Codebook (ECB) mode, but have the potential to leak information if used improperly.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3272 <![endif]]]-->See Also</h2>
3273<table xmlns="" width="100%">
3274<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.openssl.org/docs/apps/ciphers.html" target="_blank">http://www.openssl.org/docs/apps/ciphers.html</a>
3275</td></tr>
3276<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?cc4a822a" target="_blank">http://www.nessus.org/u?cc4a822a</a>
3277</td></tr>
3278<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.openssl.org/~bodo/tls-cbc.txt" target="_blank">http://www.openssl.org/~bodo/tls-cbc.txt</a>
3279</td></tr>
3280</table>
3281<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3282 <![endif]]]-->Solution</h2>
3283<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3284 <![endif]]]-->Risk Factor</h2>
3285<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3286 <![endif]]]-->Plugin Information: </h2>
3287<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2013/10/22, Modification date: 2013/10/22</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3288 <![endif]]]-->Hosts</h2>
3289<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/25)</h2>
3290<span xmlns="" class="classpre"> <br>Here is the list of SSL CBC ciphers supported by the remote server :<br> <br> Low Strength Ciphers (<= 64-bit key)<br> <br> DES-CBC-MD5 Kx=RSA Au=RSA Enc=DES-CBC(56) Mac=MD5 <br> EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2-CBC(40) Mac=MD5 export <br> EXP-EDH-RSA-DES-CBC-SHA Kx=DH(512) Au=RSA Enc=DES-CBC(40) Mac=SHA1 export <br> EDH-RSA-DES-CBC-SHA Kx=DH Au=RSA Enc=DES-CBC(56) Mac=SHA1 <br> EXP-ADH-DES-CBC-SHA Kx=DH(512) Au=None Enc=DES-CBC(40) Mac=SHA1 export <br> ADH-DES-CBC-SHA Kx=DH Au=None Enc=DES-CBC(56) Mac=SHA1 <br> EXP-DES-CBC-SHA Kx=RSA(512) Au=RSA Enc=DES-CBC(40) Mac=SHA1 export <br> EXP-RC2-CBC-MD5 Kx=RSA(512) Au=RSA Enc=RC2-CBC(40) Mac=MD5 export <br> DES-CBC-SHA Kx=RSA Au=RSA Enc=DES-CBC(56) Mac=SHA1 <br> <br> Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)<br> <br> DES-CBC3-MD5 Kx=RSA Au=RSA Enc=3DES-CBC(168) Mac=MD5 <br> EDH-RSA-DES-CBC3-SHA Kx=DH Au=RSA Enc=3DES-CBC(168) Mac=SHA1 <br> ADH-DES-CBC3-SHA Kx=DH Au=None Enc=3DES-CBC(168) Mac=SHA1 <br> DES-CBC3-SHA Kx=RSA Au=RSA Enc=3DES-CBC(168) Mac=SHA1 <br> <br> High Strength Ciphers (>= 112-bit key)<br> <br> RC2-CBC-MD5 Kx=RSA Au=RSA Enc=RC2-CBC(128) Mac=MD5 <br> DHE-RSA-AES128-SHA Kx=DH Au=RSA Enc=AES-CBC(128) Mac=SHA1 <br> DHE-RSA-AES256-SHA Kx=DH Au=RSA Enc=AES-CBC(256) Mac=SHA1 <br> ADH-AES128-SHA Kx=DH Au=None Enc=AES-CBC(128) Mac=SHA1 <br> ADH-AES256-SHA Kx=DH Au=None Enc=AES-CBC(256) Mac=SHA1 <br> AES128-SHA Kx=RSA Au=RSA Enc=AES-CBC(128) Mac=SHA1 <br> AES256-SHA Kx=RSA Au=RSA Enc=AES-CBC(256) Mac=SHA1 <br> <br>The fields above are :<br> <br> {OpenSSL ciphername}<br> Kx={key exchange}<br> Au={authentication}<br> Enc={symmetric encryption method}<br> Mac={message authentication code}<br> {export flag}</span><h2 xmlns="" class="classsection0" id="idm131029120">70657 (1) - SSH Algorithms and Languages Supported</h2>
3291<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3292 <![endif]]]-->Synopsis</h2>
3293<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">An SSH server is listening on this port.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3294 <![endif]]]-->Description</h2>
3295<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">This script detects which algorithms and languages are supported by the remote service for encrypting communications.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3296 <![endif]]]-->Solution</h2>
3297<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3298 <![endif]]]-->Risk Factor</h2>
3299<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3300 <![endif]]]-->Plugin Information: </h2>
3301<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2013/10/28, Modification date: 2017/08/28</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3302 <![endif]]]-->Hosts</h2>
3303<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/22)</h2>
3304<span xmlns="" class="classpre"> <br>Nessus negotiated the following encryption algorithm with the server : <br> <br>The server supports the following options for kex_algorithms : <br> <br> diffie-hellman-group-exchange-sha1<br> diffie-hellman-group-exchange-sha256<br> diffie-hellman-group1-sha1<br> diffie-hellman-group14-sha1<br> <br>The server supports the following options for server_host_key_algorithms : <br> <br> ssh-dss<br> ssh-rsa<br> <br>The server supports the following options for encryption_algorithms_client_to_server : <br> <br> 3des-cbc<br> aes128-cbc<br> aes128-ctr<br> aes192-cbc<br> aes192-ctr<br> aes256-cbc<br> aes256-ctr<br> arcfour<br> arcfour128<br> arcfour256<br> blowfish-cbc<br> cast128-cbc<br> rijndael-cbc@lysator.liu.se<br> <br>The server supports the following options for encryption_algorithms_server_to_client : <br> <br> 3des-cbc<br> aes128-cbc<br> aes128-ctr<br> aes192-cbc<br> aes192-ctr<br> aes256-cbc<br> aes256-ctr<br> arcfour<br> arcfour128<br> arcfour256<br> blowfish-cbc<br> cast128-cbc<br> rijndael-cbc@lysator.liu.se<br> <br>The server supports the following options for mac_algorithms_client_to_server : <br> <br> hmac-md5<br> hmac-md5-96<br> hmac-ripemd160<br> hmac-ripemd160@openssh.com<br> hmac-sha1<br> hmac-sha1-96<br> umac-64@openssh.com<br> <br>The server supports the following options for mac_algorithms_server_to_client : <br> <br> hmac-md5<br> hmac-md5-96<br> hmac-ripemd160<br> hmac-ripemd160@openssh.com<br> hmac-sha1<br> hmac-sha1-96<br> umac-64@openssh.com<br> <br>The server supports the following options for compression_algorithms_client_to_server : <br> <br> none<br> zlib@openssh.com<br> <br>The server supports the following options for compression_algorithms_server_to_client : <br> <br> none<br> zlib@openssh.com</span><h2 xmlns="" class="classsection0" id="idm130999168">72779 (1) - DNS Server Version Detection</h2>
3305<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3306 <![endif]]]-->Synopsis</h2>
3307<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Nessus was able to obtain version information on the remote DNS server.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3308 <![endif]]]-->Description</h2>
3309<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Nessus was able to obtain version information by sending a special TXT record query to the remote host.<br> <br>Note that this version is not necessarily accurate and could even be forged, as some DNS servers send the information based on a configuration file.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3310 <![endif]]]-->Solution</h2>
3311<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3312 <![endif]]]-->Risk Factor</h2>
3313<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3314 <![endif]]]-->Plugin Information: </h2>
3315<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2014/03/03, Modification date: 2014/11/05</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3316 <![endif]]]-->Hosts</h2>
3317<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/53)</h2>
3318<span xmlns="" class="classpre"> <br>DNS server answer for "version.bind" (over TCP) :<br> <br> 9.4.2</span><h2 xmlns="" class="classsection0" id="idm130991488">84574 (1) - Backported Security Patch Detection (PHP)</h2>
3319<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3320 <![endif]]]-->Synopsis</h2>
3321<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Security patches have been backported.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3322 <![endif]]]-->Description</h2>
3323<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Security patches may have been 'backported' to the remote PHP install without changing its version number.<br> <br>Banner-based checks have been disabled to avoid false positives.<br> <br>Note that this test is informational only and does not denote any security problem.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3324 <![endif]]]-->See Also</h2>
3325<table xmlns="" width="100%"><tr><td width="100%" valign="top" class="classcell"> <a href="https://access.redhat.com/security/updates/backporting/?sc_cid=3093" target="_blank">https://access.redhat.com/security/updates/backporting/?sc_cid=3093</a>
3326</td></tr></table>
3327<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3328 <![endif]]]-->Solution</h2>
3329<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3330 <![endif]]]-->Risk Factor</h2>
3331<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3332 <![endif]]]-->Plugin Information: </h2>
3333<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2015/07/07, Modification date: 2015/07/07</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3334 <![endif]]]-->Hosts</h2>
3335<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/80)</h2>
3336<span xmlns="" class="classpre"> <br>Give Nessus credentials to perform local checks.</span><h2 xmlns="" class="classsection0" id="idm130973952">96982 (1) - Server Message Block (SMB) Protocol Version 1 Enabled (uncredentialed check)</h2>
3337<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3338 <![endif]]]-->Synopsis</h2>
3339<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote Windows host supports the SMBv1 protocol.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3340 <![endif]]]-->Description</h2>
3341<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">The remote Windows host supports Server Message Block Protocol version 1 (SMBv1). Microsoft recommends that users discontinue the use of SMBv1 due to the lack of security features that were included in later SMB versions. Additionally, the Shadow Brokers group reportedly has an exploit that affects SMB; however, it is unknown if the exploit affects SMBv1 or another version. In response to this, US-CERT recommends that users disable SMBv1 per SMB best practices to mitigate these potential issues.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3342 <![endif]]]-->See Also</h2>
3343<table xmlns="" width="100%">
3344<tr><td width="100%" valign="top" class="classcell"> <a href="https://blogs.technet.microsoft.com/filecab/2016/09/16/stop-using-smb1/" target="_blank">https://blogs.technet.microsoft.com/filecab/2016/09/16/stop-using-smb1/</a>
3345</td></tr>
3346<tr><td width="100%" valign="top" class="classcell"> <a href="https://support.microsoft.com/en-us/kb/2696547" target="_blank">https://support.microsoft.com/en-us/kb/2696547</a>
3347</td></tr>
3348<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?8dcab5e4" target="_blank">http://www.nessus.org/u?8dcab5e4</a>
3349</td></tr>
3350<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?36fd3072" target="_blank">http://www.nessus.org/u?36fd3072</a>
3351</td></tr>
3352<tr><td width="100%" valign="top" class="classcell"> <a href="http://www.nessus.org/u?4c7e0cf3" target="_blank">http://www.nessus.org/u?4c7e0cf3</a>
3353</td></tr>
3354</table>
3355<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3356 <![endif]]]-->Solution</h2>
3357<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Disable SMBv1 according to the vendor instructions in Microsoft KB2696547. Additionally, block SMB directly by blocking TCP port 445 on all network boundary devices. For SMB over the NetBIOS API, block TCP ports 137 / 139 and UDP ports 137 / 138 on all network boundary devices.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3358 <![endif]]]-->Risk Factor</h2>
3359<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3360 <![endif]]]-->References</h2>
3361<table xmlns="" width="100%"><tr>
3362<td width="30%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: bold !important;">XREF</span></td>
3363<td width="70%" valign="top" class="classcell"><span class="classtext" style="color: #263645; font-weight: normal;">OSVDB:151058</span></td>
3364</tr></table>
3365<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3366 <![endif]]]-->Plugin Information: </h2>
3367<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2017/02/03, Modification date: 2017/02/16</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3368 <![endif]]]-->Hosts</h2>
3369<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/445)</h2>
3370<span xmlns="" class="classpre"> <br>The remote host supports SMBv1.</span><h2 xmlns="" class="classsection0" id="idm130954624">100871 (1) - Microsoft Windows SMB Versions Supported (remote check)</h2>
3371<h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3372 <![endif]]]-->Synopsis</h2>
3373<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">It was possible to obtain information about the version of SMB running on the remote host.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3374 <![endif]]]-->Description</h2>
3375<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Nessus was able to obtain the version of SMB running on the remote host by sending an authentication request to port 139 or 445.<br> <br>Note that this plugin is a remote check and does not work on agents.</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3376 <![endif]]]-->Solution</h2>
3377<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">n/a</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3378 <![endif]]]-->Risk Factor</h2>
3379<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">None</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3380 <![endif]]]-->Plugin Information: </h2>
3381<span xmlns="" class="classtext" style="color: #263645; font-weight: normal;">Publication date: 2017/06/19, Modification date: 2017/06/19</span><h2 xmlns="" class="classh1 " style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3382 <![endif]]]-->Hosts</h2>
3383<h2 xmlns="" class="classh2" style="color: #357abd">192.168.189.131 (tcp/445)</h2>
3384<span xmlns="" class="classpre"> <br>The remote host supports the following versions of SMB :<br> SMBv1</span><h1 xmlns="" class="classchapter" id="idm130947328">Remediations</h1>
3385<table xmlns="">
3386<tr width="100%" onclick="ceall(0)" onmouseover="this.style.cursor='pointer'" title="Collapse"><td align="left" width="100%">[-] Collapse All</td></tr>
3387<tr width="100%" onclick="ceall(1)" onmouseover="this.style.cursor='pointer'" title="Expand"><td align="left" width="100%">[+] Expand All</td></tr>
3388</table>
3389<h2 xmlns="" class="classsection" id="idm130947072">Suggested Remediations</h2>
3390<h2 xmlns="" class="classh1 remediations" style="vertical-align: middle;"><!--[if mso]><img src="cid:#" width="1" height="25" border="0" style="display: block; float: left;">
3391 <![endif]]]--></h2>
3392<table xmlns="" cellpadding="0" cellspacing="0" border="0" width="100%"><tr><td style="padding: 10px 0 10px 10px !important; margin: 0 0 5px 0; font-weight: bold; font-size: 13px; border-bottom: 1px dotted #ddd;">Taking the following actions across 1 hosts would resolve 3% of the vulnerabilities on the network:</td></tr></table>
3393<table xmlns="" width="100%" cellpadding="0" cellspacing="0" border="0">
3394<tr bgcolor="">
3395<td width="95%" valign="top" style="padding: 10px 10px !important; border-bottom: 1px dotted #ddd;"><span class="classtext" style="color: #263645; font-weight: bold !important;">Action to take</span></td>
3396<td width="5%" valign="top" style="padding: 10px 10px !important; border-bottom: 1px dotted #ddd;"><span class="classtext" style="color: #263645; font-weight: normal;">Vulns</span></td>
3397<td width="5%" valign="top" style="padding: 10px 10px !important; border-bottom: 1px dotted #ddd;"><span class="classtext" style="color: #263645; font-weight: normal;">Hosts</span></td>
3398</tr>
3399<tr bgcolor="#eeeeee">
3400<td width="95%" valign="top" style="padding: 10px 10px !important; border-bottom: 1px dotted #ddd;"><span class="classtext" style="color: #263645; font-weight: normal;">Apache HTTP Server httpOnly Cookie Information Disclosure: Upgrade to Apache version 2.0.65 / 2.2.22 or later.</span></td>
3401<td width="5%" valign="top" style="padding: 10px 10px !important; border-bottom: 1px dotted #ddd;"><span class="classtext" style="color: #263645; font-weight: normal;">1</span></td>
3402<td width="5%" valign="top" style="padding: 10px 10px !important; border-bottom: 1px dotted #ddd;"><span class="classtext" style="color: #263645; font-weight: normal;">1</span></td>
3403</tr>
3404<tr bgcolor="">
3405<td width="95%" valign="top" style="padding: 10px 10px !important; border-bottom: 1px dotted #ddd;"><span class="classtext" style="color: #263645; font-weight: normal;">Samba Badlock Vulnerability: Upgrade to Samba version 4.2.11 / 4.3.8 / 4.4.2 or later.</span></td>
3406<td width="5%" valign="top" style="padding: 10px 10px !important; border-bottom: 1px dotted #ddd;"><span class="classtext" style="color: #263645; font-weight: normal;">0</span></td>
3407<td width="5%" valign="top" style="padding: 10px 10px !important; border-bottom: 1px dotted #ddd;"><span class="classtext" style="color: #263645; font-weight: normal;">1</span></td>
3408</tr>
3409</table></div></td></tr></table></td></tr></table><div id="copyright">
3410 This is a report from the
3411 <a xmlns="" href="http://www.tenable.com/" target="_blank">Nessus Vulnerability Scanner</a>
3412 .<br xmlns="">
3413 Nessus is published by Tenable Network Security, Inc | 7021 Columbia Gateway Drive Suite 500, Columbia, MD 21046<br xmlns="">
3414 © 2017 Tenable Network Security, Inc. All rights reserved.
3415 </div></body></html>