Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Command Line RPC vulnerability scanner?

From: Russell Fulton <r.fulton(at)auckland.ac.nz>
Date: Thu Jul 31 2003 - 16:26:14 EDT

On Fri, 2003-08-01 at 03:30, Schmehl, Paul L wrote:
> I have both eEye's tool and ISS's tool. I decided to run the ISS

I ran it on our class B a couple of days ago and after about 5 hours it stopped scanning after finding 7500 hosts listening on port 135. The process did not terminate it just hung with no more output being written to stdout. The output file had a truncated line at the end suggesting that the buffer had not been fully written.

The number of host is close to what I would expect so I'm going to try again today.

Another feature of this scanner is that it scans in random order so if anything goes wrong you can't simply restart from where you left off :( I don't know why ISS decided to do this rather than a simple sequential scan.

As others have mentioned the scanner does two tests and returns one of 4 results for each: [VULN], [ptch], [....] and [ ? ? ].

THe meaning of the first two are obvious but the others are not specified and I would like to have more information of exactly what they mean. Anyone worked it out?

We have found some systems that are proving very difficult to patch - we can't get them to the requisite SP levels because of lack of disk space or other issues. Does anyone know of safe workarounds for such systems?  

-- 
Russell Fulton, Network Security Officer, The University of Auckland,
New Zealand.


---------------------------------------------------------------------------
----------------------------------------------------------------------------
Received on Thu Jul 31 16:40:46 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:14 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library