Administrator Report

Date:Sunday, March 10, 2002 16:21:01
User Name:xxxxxxxxxx
Company:xxxxxxxxxx
Session ID:112
Session Name:Test 1
Current Job ID:131
Current Job Date:March 10, 2002 4:19:31 PM


Session Managed By:

Console



Console


List of vulnerable hosts:

192.168.160.10
192.168.160.11
192.168.160.2
192.168.160.3
192.168.161.41

192.168.160.10

Risk
Vulnerability Name Description
Go To Top
Incorrect System Clock Vulnerability A bad system clock can induce errors by managing your network.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
NetBIOS Null Session Outsiders can access information on the target system without authentication.
NEW
ICMP Timestamp Reply Vulnerability An attacker can flood the local network with undesirable packets.
First Reported: March 10, 2002 3:45:31 PM
Traceroute Is Possible Traceroute is a common command that makes it possible to quickly map a part of your network. An attacker can use this information to prepare an intrusion.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
NetBIOS Names Retrieved An attacker can gather information on a remote system.
First Reported: March 10, 2002 3:45:31 PM Port: 137
Extended Info
HTTP Available Banner Exposure An attacker can gather information about the Web server that is running, and use it to prepare a strong attack.
First Reported: March 10, 2002 3:45:31 PM Port: 80
Extended Info
Number of vulnerabilities in 192.168.160.10: 6

192.168.160.11

Risk
Vulnerability Name Description
Go To Top
HTTP Directory Listing The configuration of the Web server does not conform to a strict "need to know" policy, which means that outside users can access more information than they need.
First Reported: March 10, 2002 3:45:31 PM Port: 80
Extended Info
discard/udp Service is Running A remote attacker can usea simple, open and not-very-useful network service named discard/UDP to eat the network bandwidth.
NEW Port: 9
ICMP Timestamp Reply Vulnerability An attacker can flood the local network with undesirable packets.
First Reported: March 10, 2002 3:45:31 PM
Traceroute Is Possible Traceroute is a common command that makes it possible to quickly map a part of your network. An attacker can use this information to prepare an intrusion.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
HTTP Available Banner Exposure An attacker can gather information about the Web server that is running, and use it to prepare a strong attack.
First Reported: March 10, 2002 3:45:31 PM Port: 80
Extended Info
Red Hat Linux Apache Remote Username Enumeration Vulnerability It is possible to know if a user exists on your host from the response returned by your web server.
First Reported: March 10, 2002 3:45:31 PM Port: 80
Apache Split-Logfile File Appending Vulnerability An attacker can act arbitrarily on your webserver.
First Reported: March 10, 2002 3:45:31 PM Port: 80
Number of vulnerabilities in 192.168.160.11: 7

192.168.160.2

Risk
Vulnerability Name Description
Go To Top
Incorrect System Clock Vulnerability A bad system clock can induce errors by managing your network.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Apache - HTTP Server is Outdated The Web server running on the system is outdated. An update is recommended.
First Reported: March 10, 2002 3:45:31 PM Port: 80
Apache - HTTP Server is Outdated The Web server running on the system is outdated. An update is recommended.
First Reported: March 10, 2002 3:45:31 PM Port: 443
discard/udp Service is Running A remote attacker can usea simple, open and not-very-useful network service named discard/UDP to eat the network bandwidth.
NEW Port: 9
ICMP Timestamp Reply Vulnerability An attacker can flood the local network with undesirable packets.
First Reported: March 10, 2002 3:45:31 PM
Traceroute Is Possible Traceroute is a common command that makes it possible to quickly map a part of your network. An attacker can use this information to prepare an intrusion.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
HTTP Available Banner Exposure An attacker can gather information about the Web server that is running, and use it to prepare a strong attack.
First Reported: March 10, 2002 3:45:31 PM Port: 80
Extended Info
HTTP Available Banner Exposure An attacker can gather information about the Web server that is running, and use it to prepare a strong attack.
First Reported: March 10, 2002 3:45:31 PM Port: 443
Extended Info
Apache Split-Logfile File Appending Vulnerability An attacker can act arbitrarily on your webserver.
First Reported: March 10, 2002 3:45:31 PM Port: 80
Apache Split-Logfile File Appending Vulnerability An attacker can act arbitrarily on your webserver.
First Reported: March 10, 2002 3:45:31 PM Port: 443
Number of vulnerabilities in 192.168.160.2: 10

192.168.160.3

Risk
Vulnerability Name Description
Go To Top
Anonymous Remote Registry Access An attacker can remotely access or change important system parameters.
First Reported: March 10, 2002 3:45:31 PM
OS/2 Subsystem Enabled The OS/2 subsystem process is enabled on a Windows NT machine. An attacker could exploit this to install a backdoor with a Trojan horse.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
NT Posix SubSystem Enabled The Posix subsystem process is enabled on a Windows NT machine. An attacker could exploit this to install a backdoor with a Trojan horse.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Privilege "Act as part of the operating system" Enabled From an unprivileged account, an attacker could use an advanced Windows NT privilege to gain administrative rights.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Unsecured Registry Access An attacker can remotely access or change important system parameters.
First Reported: March 10, 2002 3:45:31 PM
Microsoft Windows NT RPC Endpoint Mapper Denial of Service Vulnerability A remote attacker can deny access to legitimate users on your vulnerable server.
First Reported: March 10, 2002 3:45:31 PM
LDAP Null Base A remote attacker can access to sensitive information on your network and thus prepare further serious attacks.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
AT&T VNC Service Available A remote attacker could gain unauthorized access to your machines, instead of legit users.
First Reported: March 10, 2002 3:45:31 PM
Microsoft Network Monitor Multiple Buffer Overflow Vulnerabilities A remote attacker can access to sensitive information on your vulnerable server.
First Reported: March 10, 2002 3:45:31 PM
SMB Share List Obtained Windows networking resources and information can be gathered without authentication.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
NetBIOS Null Session Outsiders can access information on the target system without authentication.
First Reported: March 10, 2002 3:45:31 PM
Read Access to Application Event Log An important file logging activity can be read remotely by unauthenticated users.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Read Access to Security Event Log An important system file logging activity can be read remotely by unauthenticated users.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Read Access to System Event Log An important system file logging activity can be read remotely by unauthenticated users.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Write Access to Application Event Log Outsiders can tamper with an important system file.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Write Access to Security Event Log Outsiders can tamper with an important system file.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Write Access to System Event Log Outsiders can tamper with an important system file.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
.reg Files Associated With Regedit.exe The unsuspecting user can be tricked into executing commands that changed sensitive configuration information. Our solution prevents this dangerous situation.
First Reported: March 10, 2002 3:45:31 PM
Privilege "Add workstations to the domain" Enabled From an unprivileged account, an attacker could use a Windows NT advanced privilege to remotely add workstations and servers to the NT domain.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Privilege "Bypass traverse checking" Enabled In a secure installation, this privilege should not be given to ordinary users.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Privilege "Restore Files and Directories" Enabled From an unprivileged account, an attacker could use a Windows NT advanced privilege named "Restore Files and Directories" to replace any file on the server.
First Reported: March 10, 2002 3:45:31 PM
DCOM Enabled The DCOM function is enabled on a Windows NT machine. An attacker could exploit this to install a backdoor with a Trojan horse.
First Reported: March 10, 2002 3:45:31 PM
Microsoft Windows NT/2000 NetBIOS Release Vulnerability It is possible to make your host believe its name is not used any more. Then your host will not further respond to NetBIOS messages.
First Reported: March 10, 2002 3:45:31 PM
NT ResetBrowser frame & HostAnnouncement flood patch not installed These vulnerabilities could allow a malicious user to make it difficult or impossible for users on a network to locate services or other computers on the network. In the worst case, the first vulnerability also could enable the malicious user to provide bogus information to network users.
First Reported: March 10, 2002 3:45:31 PM
Relative Shell Path patch not installed This vulnerability would enable a malicious user to substitute code of his choice for the normal Windows desktop on machines that he can interactively log onto. Such code would run automatically whenever a user subsequently logged onto the same machine, and could take any action the user had privileges to take on the machine.
First Reported: March 10, 2002 3:45:31 PM
Microsoft Windows NT 4.0 Networking Mutex DoS Vulnerability This vulnerability allows a local user to prevent this host from communicating with the network.
First Reported: March 10, 2002 3:45:31 PM
Microsoft IIS 4.0/5.0 Multiple Vulnerabilities A remote attacker can use several meanings to compromise your web server.
First Reported: March 10, 2002 3:45:31 PM Port: 80
NT Terminal Server Multiple Connection Request DoS Vulnerability A remote attacker can deny access to legitimate users on your vulnerable server.
First Reported: March 10, 2002 3:45:31 PM
Microsoft IE Import/Export Favorites Vulnerability A malicious user can act arbitrarily on your vulnerable server.
First Reported: March 10, 2002 3:45:31 PM
DNS Zone Transfer An attacker can use the name-to-address mapping mechanism to gather sensitive information about the internal network topology.
First Reported: March 10, 2002 3:45:31 PM Port: 53
Extended Info
DNS Server Enabled The system runs a name-to-address mapping server. Its security must be enforced.
First Reported: March 10, 2002 3:45:31 PM Port: 53
SMTP Relay is Enabled Vulnerability Mail server accepts and relays mail from unknown sources.
First Reported: March 10, 2002 3:45:31 PM Port: 25
POP3 Service Is Running Vulnerability An unsecured network service named POP3 is running on the target system.
First Reported: March 10, 2002 3:45:31 PM Port: 110
WINS Fill Log Bad network configuration allows an outside attacker to fill a log file.
First Reported: March 10, 2002 3:45:31 PM Port: 42
Traceroute Is Possible Traceroute is a common command that makes it possible to quickly map a part of your network. An attacker can use this information to prepare an intrusion.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
NetBIOS Names Retrieved An attacker can gather information on a remote system.
First Reported: March 10, 2002 3:45:31 PM Port: 137
Extended Info
Privilege "Increase Quota" Enabled A user or group has advanced privileges to a currently unused NT function. This privilege must be disabled for all users or groups.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Privilege "Replace Process Level Token" Enabled From an unprivileged account, an attacker could use a Windows NT advanced privilege named "Replace Process Level Token" to gain administrator rights.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Default Login Name Obtained from Registry Database The system leaks information on local user names, making cracker's task easier.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
NetBIOS Groups Enumerated Through Null Session Outsiders can gather information on the target system without authentication.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Minimum Password Age Incorrect Vulnerability The value that your security policy specifies on the minimum password is shorter than 1 day.
First Reported: March 10, 2002 3:45:31 PM
Maximum Password Age Incorrect Vulnerability The value that your security policy specifies on the maximum password age is longer than 42 days.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Password Policy Information Available An attacker could access information of the structure containing lockout password information.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Network Transport List Available An attacker can use information about transport protocols to prepare further attacks.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
SMTP Available Banner Vulnerability An attacker can gather information about the operating system and the SMTP server type running on the remote host.
First Reported: March 10, 2002 3:45:31 PM Port: 25
Extended Info
POP3 Server Returns Information in Banner Vulnerability An attacker can gather information about the live operating system or the active POP3 application, to prepare a strong attack.
First Reported: March 10, 2002 3:45:31 PM Port: 110
Extended Info
IMAP Server Returns Information in Banner Vulnerability The program used to give acess to users' mailboxes reveals information on the server version, which could be used to launch further attacks.
First Reported: March 10, 2002 3:45:31 PM Port: 143
Extended Info
SMTP Forgery When your SMTP server accepts any domain in the HELO command, it is possible for attackers to forge mail from your server.
First Reported: March 10, 2002 3:45:31 PM Port: 25
Extended Info
Number of vulnerabilities in 192.168.160.3: 48

192.168.161.41

Risk
Vulnerability Name Description
Go To Top
Anonymous Remote Registry Access An attacker can remotely access or change important system parameters.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
OS/2 Subsystem Enabled The OS/2 subsystem process is enabled on a Windows NT machine. An attacker could exploit this to install a backdoor with a Trojan horse.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
NT Posix SubSystem Enabled The Posix subsystem process is enabled on a Windows NT machine. An attacker could exploit this to install a backdoor with a Trojan horse.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Unsecured Registry Access An attacker can remotely access or change important system parameters.
First Reported: March 10, 2002 3:45:31 PM
Incorrect System Clock Vulnerability A bad system clock can induce errors by managing your network.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
SMB Share List Obtained Windows networking resources and information can be gathered without authentication.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
NetBIOS Null Session Outsiders can access information on the target system without authentication.
First Reported: March 10, 2002 3:45:31 PM
Read Access to Application Event Log An important file logging activity can be read remotely by unauthenticated users.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Read Access to Security Event Log An important system file logging activity can be read remotely by unauthenticated users.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Read Access to System Event Log An important system file logging activity can be read remotely by unauthenticated users.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Write Access to Application Event Log Outsiders can tamper with an important system file.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Write Access to System Event Log Outsiders can tamper with an important system file.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
.reg Files Associated With Regedit.exe The unsuspecting user can be tricked into executing commands that changed sensitive configuration information. Our solution prevents this dangerous situation.
First Reported: March 10, 2002 3:45:31 PM
Privilege "Bypass traverse checking" Enabled In a secure installation, this privilege should not be given to ordinary users.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
DCOM Enabled The DCOM function is enabled on a Windows NT machine. An attacker could exploit this to install a backdoor with a Trojan horse.
First Reported: March 10, 2002 3:45:31 PM
Microsoft RDP DoS Vulnerability By sending a particular sequence of packets to the port associated with RDP on an affected server, an attacker could cause the server to fail.
First Reported: March 10, 2002 3:45:31 PM Port: 3389
Microsoft Internet Explorer Cookie Disclosure Vulnerability Malicious attackers can access to the disclosure of sensitive information on your station.
First Reported: March 10, 2002 3:45:31 PM
SNMP Agent on NT The SNMP agent on NT is active.
First Reported: March 10, 2002 3:45:31 PM
ICMP Timestamp Reply Vulnerability An attacker can flood the local network with undesirable packets.
First Reported: March 10, 2002 3:45:31 PM
Traceroute Is Possible Traceroute is a common command that makes it possible to quickly map a part of your network. An attacker can use this information to prepare an intrusion.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
NetBIOS Names Retrieved An attacker can gather information on a remote system.
First Reported: March 10, 2002 3:45:31 PM Port: 137
Extended Info
Default Login Name Obtained from Registry Database The system leaks information on local user names, making cracker's task easier.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
NetBIOS Groups Enumerated Through Null Session Outsiders can gather information on the target system without authentication.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Minimum Password Age Incorrect Vulnerability The value that your security policy specifies on the minimum password is shorter than 1 day.
First Reported: March 10, 2002 3:45:31 PM
Insufficient Password History Length Vulnerability The value that your security policy specifies on the length of password histories less than 3.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Insufficient Minimum Password Length Vulnerability A password length less than 6 characters has been detected.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Network Transport List Available An attacker can use information about transport protocols to prepare further attacks.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Local User on Workstation is Present An attacker can use information to prepare further attacks.
First Reported: March 10, 2002 3:45:31 PM
Extended Info
Number of vulnerabilities in 192.168.161.41: 28

Total Number of vulnerabilities : 99

2001 VIGILANTe.com, Inc.
SecureScan and the VIGILANTe Logo are trademarks of VIGILANTe.com, Inc.
All Rights Reserved
All products names referenced herein are trademarks of their respectives companies
North America: 1-888-403-2699 Southern European (France, Italy, Luxemburg, Spain, Switzerland) +33 1 53 92 70 00