I am getting a ridiculous number of false positives with this new plugin: "Gauntlet Overflow" ID: 10420
It is detecting systems that don't even have 8999 port open, that are vulnerable to the exploit: Here are five completelly unrelated example entries: Pasted verbatim, with only the hostnames removed. ------------------------------- general/icmp High list of hostnames.. It seems that the remote host is vulnerable to a buffer overflow on port 8999, which may give a shell access to anyone. Solution : if the remote host is a Gauntlet firewall, then see http://www.tis.com/support/cyberadvisory.html, or else you can probably ignore this alert. Risk factor : High ------------------------------- general/tcp High list of hostnames It seems that the remote host is vulnerable to a buffer overflow on port 8999, which may give a shell access to anyone. Solution : if the remote host is a Gauntlet firewall, then see http://www.tis.com/support/cyberadvisory.html, or else you can probably ignore this alert. Risk factor : High ------------------------------- general/udp High list of hostnames It seems that the remote host is vulnerable to a buffer overflow on port 8999, which may give a shell access to anyone. Solution : if the remote host is a Gauntlet firewall, then see http://www.tis.com/support/cyberadvisory.html, or else you can probably ignore this alert. Risk factor : High ------------------------------- netbios-ssn (139/tcp) High esus.cs.montana.edu wti-mo178-fiery.coe.montana.edu It seems that the remote host is vulnerable to a buffer overflow on port 8999, which may give a shell access to anyone. Solution : if the remote host is a Gauntlet firewall, then see http://www.tis.com/support/cyberadvisory.html, or else you can probably ignore this alert. Risk factor : High ------------------------------- smtp (25/tcp) High list of hostnames It seems that the remote host is vulnerable to a buffer overflow on port 8999, which may give a shell access to anyone. Solution : if the remote host is a Gauntlet firewall, then see http://www.tis.com/support/cyberadvisory.html, or else you can probably ignore this alert. Risk factor : High ------------------------------- It appears to be listing the guantlet plugin notification for completelly unrelated services. (see above) The systems are completelly different, linux,unix,sgi. I've looked through the systems and none of them have any listening services on port 8999. Versions: nessusd: debian 2.0.10a-3 plugins updated via nessus-update-plugins. -- Luke Computer Science System Administrator Security Administrator,College of Engineering Montana State University-Bozeman,Montana _______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
