I'm running Nessus 2.0.6a on Linux, scanning a Solaris 9 system. One of the
services this system is running is the Delegate telnet proxy on port 6072,
version 8.5.5. The results returned by Nessus seem to think this is a
webserver, and that it is vulnerable to the Apache chunk handling
vulnerability (among others). Safe checks are NOT enabled, and Nessus was
running a full scan of all ports. I can't imagine Delegate telnet proxy
would be vulnerable to these exploits for other software.
Is Nessus reporting inaccurate results here? What's the reason for these
results?
The list of results for port 6072 are listed below.
Thanks.
Vulnerability found on port unknown (6072/tcp)
The remote host appears to be vulnerable to the Apache
Web Server Chunk Handling Vulnerability.
If Safe Checks are enabled, this may be a false positive
since it is based on the version of Apache. Although
unpatched Apache versions 1.2.2 and above, 1.3 through
1.3.24 and 2.0 through 2.0.36, the remote server may
be running a patched version of Apache
Solution : Upgrade to version 1.3.26 or 2.0.39 or newer
See also :
http://httpd.apache.org/info/security_bulletin_20020617.txt
http://httpd.apache.org/info/security_bulletin_20020620.txt
Risk factor : High
CVE : CAN-2002-0392
<http://cgi.nessus.org/cve.php3?cve=CAN-2002-0392>
BID : 5033 <http://cgi.nessus.org/bid.php3?bid=5033>
Nessus ID : 11030 <http://cgi.nessus.org/nessus_id.php3?id=11030>
[ back to the list of ports ] <>
Vulnerability found on port unknown (6072/tcp)
Requesting an overly long URL starting with an interrogation
mark (as in /?AAAAA[....]AAAA) crashes the remote server
(possibly Xeneo Web Server).
Solution : upgrade to latest version of Xeneo Web Server
Risk factor : High
Nessus ID : 11545 <http://cgi.nessus.org/nessus_id.php3?id=11545>
[ back to the list of ports ] <>
Warning found on port unknown (6072/tcp)
It seems that your web server rejects requests
from Nessus. It is probably protected by a reverse proxy.
Risk factor : None
Solution : change your configuration
if your tests to be accurate
Nessus ID : 11238 <http://cgi.nessus.org/nessus_id.php3?id=11238>
[ back to the list of ports ] <>
Information found on port unknown (6072/tcp)
A web server is running on this port
Nessus ID : 10330 <http://cgi.nessus.org/nessus_id.php3?id=10330>