Services Report

Date:Sunday, March 10, 2002 16:21:01
User Name:xxxxxxxxxxxxxxxxxxxxxx
Company:xxxxxxxxxx
Session ID:112
Session Name:Test 1
Current Job ID:131
Current Job Date:March 10, 2002 4:19:31 PM

Services
Number of Vulnerabilities
go to Detail
discard (udp)
2
dns (tcp)
2
http (tcp)
12
imap (tcp)
1
NetBios Name (udp)
3
pop3 (tcp)
2
smtp (tcp)
3
Windows_TerminalServer4 (tcp)
1
wins (tcp)
1



Detail :
discard (udp)

192.168.160.11
Go To Top
Risk
Vulnerability Name Description
discard/udp Service is RunningA remote attacker can usea simple, open and not-very-useful network service named discard/UDP to eat the network bandwidth.
NEW Port: 9

192.168.160.2
Go To Top
Risk
Vulnerability Name Description
discard/udp Service is RunningA remote attacker can usea simple, open and not-very-useful network service named discard/UDP to eat the network bandwidth.
NEW Port: 9


dns (tcp)

192.168.160.3
Go To Top
Risk
Vulnerability Name Description
DNS Zone TransferAn attacker can use the name-to-address mapping mechanism to gather sensitive information about the internal network topology.
First Reported:March 10, 2002 3:45:31 PM Port: 53
Extended Info
DNS Server EnabledThe system runs a name-to-address mapping server. Its security must be enforced.
First Reported:March 10, 2002 3:45:31 PM Port: 53


http (tcp)

192.168.160.10
Go To Top
Risk
Vulnerability Name Description
HTTP Available Banner ExposureAn attacker can gather information about the Web server that is running, and use it to prepare a strong attack.
First Reported:March 10, 2002 3:45:31 PM Port: 80
Extended Info

192.168.160.11
Go To Top
Risk
Vulnerability Name Description
HTTP Directory ListingThe configuration of the Web server does not conform to a strict "need to know" policy, which means that outside users can access more information than they need.
First Reported:March 10, 2002 3:45:31 PM Port: 80
Extended Info
HTTP Available Banner ExposureAn attacker can gather information about the Web server that is running, and use it to prepare a strong attack.
First Reported:March 10, 2002 3:45:31 PM Port: 80
Extended Info
Red Hat Linux Apache Remote Username Enumeration VulnerabilityIt is possible to know if a user exists on your host from the response returned by your web server.
First Reported:March 10, 2002 3:45:31 PM Port: 80
Apache Split-Logfile File Appending VulnerabilityAn attacker can act arbitrarily on your webserver.
First Reported:March 10, 2002 3:45:31 PM Port: 80

192.168.160.2
Go To Top
Risk
Vulnerability Name Description
Apache - HTTP Server is OutdatedThe Web server running on the system is outdated. An update is recommended.
First Reported:March 10, 2002 3:45:31 PM Port: 80
Apache - HTTP Server is OutdatedThe Web server running on the system is outdated. An update is recommended.
First Reported:March 10, 2002 3:45:31 PM Port: 443
HTTP Available Banner ExposureAn attacker can gather information about the Web server that is running, and use it to prepare a strong attack.
First Reported:March 10, 2002 3:45:31 PM Port: 80
Extended Info
HTTP Available Banner ExposureAn attacker can gather information about the Web server that is running, and use it to prepare a strong attack.
First Reported:March 10, 2002 3:45:31 PM Port: 443
Extended Info
Apache Split-Logfile File Appending VulnerabilityAn attacker can act arbitrarily on your webserver.
First Reported:March 10, 2002 3:45:31 PM Port: 80
Apache Split-Logfile File Appending VulnerabilityAn attacker can act arbitrarily on your webserver.
First Reported:March 10, 2002 3:45:31 PM Port: 443

192.168.160.3
Go To Top
Risk
Vulnerability Name Description
Microsoft IIS 4.0/5.0 Multiple VulnerabilitiesA remote attacker can use several meanings to compromise your web server.
First Reported:March 10, 2002 3:45:31 PM Port: 80


imap (tcp)

192.168.160.3
Go To Top
Risk
Vulnerability Name Description
IMAP Server Returns Information in Banner VulnerabilityThe program used to give acess to users' mailboxes reveals information on the server version, which could be used to launch further attacks.
First Reported:March 10, 2002 3:45:31 PM Port: 143
Extended Info


NetBios Name (udp)

192.168.160.10
Go To Top
Risk
Vulnerability Name Description
NetBIOS Names RetrievedAn attacker can gather information on a remote system.
First Reported:March 10, 2002 3:45:31 PM Port: 137
Extended Info

192.168.160.3
Go To Top
Risk
Vulnerability Name Description
NetBIOS Names RetrievedAn attacker can gather information on a remote system.
First Reported:March 10, 2002 3:45:31 PM Port: 137
Extended Info

192.168.161.41
Go To Top
Risk
Vulnerability Name Description
NetBIOS Names RetrievedAn attacker can gather information on a remote system.
First Reported:March 10, 2002 3:45:31 PM Port: 137
Extended Info


pop3 (tcp)

192.168.160.3
Go To Top
Risk
Vulnerability Name Description
POP3 Service Is Running VulnerabilityAn unsecured network service named POP3 is running on the target system.
First Reported:March 10, 2002 3:45:31 PM Port: 110
POP3 Server Returns Information in Banner VulnerabilityAn attacker can gather information about the live operating system or the active POP3 application, to prepare a strong attack.
First Reported:March 10, 2002 3:45:31 PM Port: 110
Extended Info


smtp (tcp)

192.168.160.3
Go To Top
Risk
Vulnerability Name Description
SMTP Relay is Enabled VulnerabilityMail server accepts and relays mail from unknown sources.
First Reported:March 10, 2002 3:45:31 PM Port: 25
SMTP ForgeryWhen your SMTP server accepts any domain in the HELO command, it is possible for attackers to forge mail from your server.
First Reported:March 10, 2002 3:45:31 PM Port: 25
Extended Info
SMTP Available Banner VulnerabilityAn attacker can gather information about the operating system and the SMTP server type running on the remote host.
First Reported:March 10, 2002 3:45:31 PM Port: 25
Extended Info


Windows_TerminalServer4 (tcp)

192.168.161.41
Go To Top
Risk
Vulnerability Name Description
Microsoft RDP DoS VulnerabilityBy sending a particular sequence of packets to the port associated with RDP on an affected server, an attacker could cause the server to fail.
First Reported:March 10, 2002 3:45:31 PM Port: 3389


wins (tcp)

192.168.160.3
Go To Top
Risk
Vulnerability Name Description
WINS Fill LogBad network configuration allows an outside attacker to fill a log file.
First Reported:March 10, 2002 3:45:31 PM Port: 42


2001 VIGILANTe.com, Inc.
SecureScan and the VIGILANTe Logo are trademarks of VIGILANTe.com, Inc.
All Rights Reserved
All products names referenced herein are trademarks of their respectives companies
North America: 1-888-403-2699 Southern European (France, Italy, Luxemburg, Spain, Switzerland) +33 1 53 92 70 00