Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


RE: Command Line RPC vulnerability scanner?
.

  • To: "Schmehl, Paul L" <[EMAIL PROTECTED]>
  • Subject: RE: Command Line RPC vulnerability scanner?
  • From: Russell Fulton <[EMAIL PROTECTED]>
  • Date: 01 Aug 2003 08:26:14 +1200
  • Cc: [EMAIL PROTECTED]
  • In-reply-to: <[EMAIL PROTECTED]>
  • References: <[EMAIL PROTECTED]>
.
 
On Fri, 2003-08-01 at 03:30, Schmehl, Paul L wrote:
> I have both eEye's tool and ISS's tool.  I decided to run the ISS
> commandline scanner on our entire class B last night.  That way I could
> come in this morning and have a complete report of patch compliance.  Or
> so I thought.  When I got in to my office this morning, the ISS tool had
> been running for 15 hours and had reported on a total of 99 hosts.

I ran it on our class B a couple of days ago and after about 5 hours it
stopped scanning after finding 7500 hosts listening on port 135.  The
process did not terminate it just hung with no more output being written
to stdout.  The output file had a truncated line at the end suggesting
that the  buffer had not been fully written.

The number of host is close to what I would expect so I'm going to try
again today.

Another feature of this scanner is that it scans in random order so if
anything goes wrong you can't simply restart from where you left off :(
I don't know why ISS decided to do this rather than a simple sequential
scan.

As others have mentioned the scanner does two tests and returns one of 4
results for each: [VULN], [ptch], [....] and [ ? ? ].

THe meaning of the first two are obvious but the others are not
specified and I would like to have more information of exactly what they
mean.  Anyone worked it out?

We have found some systems that are proving very difficult to patch - we
can't get them to the requisite SP levels because of lack of disk space
or other issues.  Does anyone know of safe workarounds for such systems?
 
-- 
Russell Fulton, Network Security Officer, The University of Auckland,
New Zealand.


---------------------------------------------------------------------------
----------------------------------------------------------------------------


 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.