> If the goal is a fast scan, can one just run #12054? It would seem that > anyone with a Microsoft web server that #12055 catches would also have NTLM > available. Should #12055 catch that many more systems?
If you have a web server and you're concerned about security you should consider firewalling all services that aren't required (that's just a truism about security in general). A web server will continue to function as a web server with port 445 firewalled with IPSec. It might be inconvenient to manage, but it will run fine and it would be more secure. The recommendation I give users detected is to patch *AND* apply IPSec and/or ICF. But you're probably right. The NTLM test will catch 99.9...% of those caught by the IIS test. _______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
