Greets,
I'm trying to identify machines vulnerable to ms04-007. I'll settle for all CIFS/SMB servers that are vulnerable.
I'm running
# nasl -s -t <host> /usr/local/lib/nessus/plugins/cifs445.nasl /usr/local/lib/nessus/plugins/netbios_name_get.nasl /usr/local/lib/nessus/plugins/windows_asn1_vuln_ntlm.nasl
I look for "SMB server" or "CIFS server" to see if that service is running, and then look for "Success" to determine vulnerability.
I expect about 90% of my CIFS/SMB servers to be unpatched. However, I'm only getting 32% vulnerable -- so based on my expectation, this would mean a 90% - 32% = 58% false negative rate, which is pretty bad. What am I doing wrong?
In the false negatives, what I'm seeing is that when windows_asn1_vuln_ntlm is executing, when it is setting up the netbios session, the called name is blank -- so the tested host returns "called name not present" and the script gives up, even though SMB/name keys are being set.
???
--woody
Woody Weaver cell: 301 524 8138
Manager, GIT Security Planning mail: [EMAIL PROTECTED]
Schering-Plough, Madison NJ land: 301 473 7320
smime.p7s
Description: S/MIME cryptographic signature
_______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
