The symptoms you describe sound like a reboot had not been done after the patch was 
applied. If it happens again, check the registry key 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session 
Manager\PendingFileRenameOperations  and you should see a list of the files that 
NT/2K/XP will copy and rename during the next reboot. The files in question are in use 
when the patch is applied and are not replaced directly.
 
Maybe a reboot was done after deleting the backup files and deleting them was not the 
cure but the reboot was?

        -----Original Message----- 
        From: Carlton Foster [mailto:[EMAIL PROTECTED] 
        Sent: Wed 11/19/2003 01:58 
        To: Discussion of Nessus software 
        Cc: 
        Subject: Re: URGENT - Help with 11808 and 11835
        
        

        Ok, that part seems simple enough.  Now, on 2000 and above systems, I
        know Nessus has been right every time in our environment.  On the NT
        systems, it has been right on every machine I have personally checked. 
        However, we have found something I need help understanding. 
        Unfortunately, I have to figure it out by 8am EST...
        
        On atleast one NT4 Workstation system, the user looked for the files MS
        says verify the patch installed:
        
        Date         Time   Version        Size     File name
           ------------------------------------------------------
           11-Aug-2003  11:29  4.0.1381.7230  701,200  Ole32.dll
           11-Aug-2003  11:29  4.0.1381.7230  345,872  Rpcrt4.dll
           11-Aug-2003  11:29  4.0.1381.7230  107,792  Rpcss.exe
        
        They found these files in the system32 directory as they should be.  But
        they also found older versions of these files in a backup directory. 
        Upon deleting the older files and rescanning, the machine no longer
        appeared as vulnerable.
        
        This is where and why I am having a hard time with this.  Since my
        Nessus scanners do not have any SMB account info, and I do not have
        access to nor an account on the machine in question, can anyone explain
        this?  Now, I told you what the user told me.  I do not know what else
        they may have done, like reboot...
        
        I have faith in the Nessus scan results I am getting, but unfortunately
        I have to convince alot more than me.  Any thoughts, ideas, insights,
        suggestions, are greatly appreciated.
        
        Thanks again,
        Carl
        
        Renaud Deraison wrote:
        
        >On Tue, Nov 18, 2003 at 05:07:34PM -0500, Carlton Foster wrote:
        > 
        >
        >>We are still finding a number of NT4 systems vulnerable according to
        >>plugin 11808 for MS03-026 and 11835 for MS03-039.  I need a question
        >>answered definitively to end the debate.
        >>
        >>I am not a programmer and I am very new to Nessus, but if I understand
        >>11808 and 11835 correctly, they are not reading file versions from the
        >>hard drive, but are actually trying to exploit the vulnerability.  Is
        >>this correct?
        >>
        >>Using tcpdump to watch the test using just 11808 and 11835, we see no
        >>evidence of files being looked for, but management requires a firm
        >>statement that I cannot provide.  Can someone please state clearly how
        >>11808 and 11835 work so that I can pass it along.
        >>   
        >>
        >
        >Microsoft slightly changed the behavior of their API with MS03-026 and
        >MS03-029 (different error code returned for otherwise invalid requests).
        >What these plugins do is that they determine the presence of the patch
        >by sending invalid requests and looking at the returned error codes.
        >
        >The latest versions are supposed to be very accurate so my guess is that
        >it's a real alert.
        >
        >                               -- Renaud
        >_______________________________________________
        >Nessus mailing list
        >[EMAIL PROTECTED]
        >http://mail.nessus.org/mailman/listinfo/nessus
        >
        > 
        >
        
        _______________________________________________
        Nessus mailing list
        [EMAIL PROTECTED]
        http://mail.nessus.org/mailman/listinfo/nessus
        

_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to