We are still finding a number of NT4 systems vulnerable according to plugin 11808 for MS03-026 and 11835 for MS03-039. I need a question answered definitively to end the debate.

I am not a programmer and I am very new to Nessus, but if I understand 11808 and 11835 correctly, they are not reading file versions from the hard drive, but are actually trying to exploit the vulnerability. Is this correct?

Using tcpdump to watch the test using just 11808 and 11835, we see no evidence of files being looked for, but management requires a firm statement that I cannot provide. Can someone please state clearly how 11808 and 11835 work so that I can pass it along.

Thank you.

_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to