> If the goal is a fast scan, can one just run #12054?  It would seem that
> anyone with a Microsoft web server that #12055 catches would also have
NTLM
> available.  Should #12055 catch that many more systems?

If you have a web server and you're concerned about security you should
consider firewalling all services that aren't required (that's just a truism
about security in general). A web server will continue to function as a web
server with port 445 firewalled with IPSec. It might be inconvenient to
manage, but it will run fine and it would be more secure. The recommendation
I give users detected is to patch *AND* apply IPSec and/or ICF.

But you're probably  right.  The NTLM test will catch 99.9...% of those
caught by the IIS test.


_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to