Ok, that part seems simple enough. Now, on 2000 and above systems, I know Nessus has been right every time in our environment. On the NT systems, it has been right on every machine I have personally checked. However, we have found something I need help understanding. Unfortunately, I have to figure it out by 8am EST...

On atleast one NT4 Workstation system, the user looked for the files MS says verify the patch installed:

Date Time Version Size File name
------------------------------------------------------
11-Aug-2003 11:29 4.0.1381.7230 701,200 Ole32.dll 11-Aug-2003 11:29 4.0.1381.7230 345,872 Rpcrt4.dll
11-Aug-2003 11:29 4.0.1381.7230 107,792 Rpcss.exe


They found these files in the system32 directory as they should be. But they also found older versions of these files in a backup directory. Upon deleting the older files and rescanning, the machine no longer appeared as vulnerable.

This is where and why I am having a hard time with this. Since my Nessus scanners do not have any SMB account info, and I do not have access to nor an account on the machine in question, can anyone explain this? Now, I told you what the user told me. I do not know what else they may have done, like reboot...

I have faith in the Nessus scan results I am getting, but unfortunately I have to convince alot more than me. Any thoughts, ideas, insights, suggestions, are greatly appreciated.

Thanks again,
Carl

Renaud Deraison wrote:

On Tue, Nov 18, 2003 at 05:07:34PM -0500, Carlton Foster wrote:


We are still finding a number of NT4 systems vulnerable according to plugin 11808 for MS03-026 and 11835 for MS03-039. I need a question answered definitively to end the debate.

I am not a programmer and I am very new to Nessus, but if I understand 11808 and 11835 correctly, they are not reading file versions from the hard drive, but are actually trying to exploit the vulnerability. Is this correct?

Using tcpdump to watch the test using just 11808 and 11835, we see no evidence of files being looked for, but management requires a firm statement that I cannot provide. Can someone please state clearly how 11808 and 11835 work so that I can pass it along.



Microsoft slightly changed the behavior of their API with MS03-026 and
MS03-029 (different error code returned for otherwise invalid requests). What these plugins do is that they determine the presence of the patch
by sending invalid requests and looking at the returned error codes.


The latest versions are supposed to be very accurate so my guess is that
it's a real alert.

                                -- Renaud
_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus




_______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to