Title: false negative with windows_asn1_vuln_ntlm.nasl ?

Greets,

I'm trying to identify machines vulnerable to ms04-007.  I'll settle for all CIFS/SMB servers that are vulnerable.

I'm running

# nasl -s -t <host> /usr/local/lib/nessus/plugins/cifs445.nasl /usr/local/lib/nessus/plugins/netbios_name_get.nasl /usr/local/lib/nessus/plugins/windows_asn1_vuln_ntlm.nasl

I look for "SMB server" or "CIFS server" to see if that service is running, and then look for "Success" to determine vulnerability.

I expect about 90% of my CIFS/SMB servers to be unpatched.  However, I'm only getting 32% vulnerable -- so based on my expectation, this would mean a 90% - 32% = 58% false negative rate, which is pretty bad.  What am I doing wrong?

In the false negatives, what I'm seeing is that when windows_asn1_vuln_ntlm is executing, when it is setting up the netbios session, the called name is blank -- so the tested host returns "called name not present" and the script gives up, even though SMB/name keys are being set.

???

--woody


Woody Weaver                     cell: 301 524 8138
Manager, GIT Security Planning   mail: [EMAIL PROTECTED]
Schering-Plough, Madison NJ      land: 301 473 7320


Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to