I am getting a ridiculous number of false positives with this new plugin:
"Gauntlet Overflow"
ID: 10420

It is detecting systems that don't even have 8999 port open, that are
vulnerable to the exploit:
Here are five completelly unrelated example entries:
Pasted verbatim, with only the hostnames removed.

-------------------------------
general/icmp

High

list of hostnames..

It seems that the remote host is vulnerable
to a buffer overflow on port 8999, which may
give a shell access to anyone.

Solution : if the remote host is a Gauntlet firewall, then
see http://www.tis.com/support/cyberadvisory.html, or else
you can probably ignore this alert.

Risk factor : High
-------------------------------
general/tcp

High

list of hostnames

It seems that the remote host is vulnerable
to a buffer overflow on port 8999, which may
give a shell access to anyone.

Solution : if the remote host is a Gauntlet firewall, then
see http://www.tis.com/support/cyberadvisory.html, or else
you can probably ignore this alert.

Risk factor : High
-------------------------------
general/udp

High

list of hostnames


It seems that the remote host is vulnerable
to a buffer overflow on port 8999, which may
give a shell access to anyone.

Solution : if the remote host is a Gauntlet firewall, then
see http://www.tis.com/support/cyberadvisory.html, or else
you can probably ignore this alert.

Risk factor : High
-------------------------------
netbios-ssn (139/tcp)

High

esus.cs.montana.edu
wti-mo178-fiery.coe.montana.edu


It seems that the remote host is vulnerable
to a buffer overflow on port 8999, which may
give a shell access to anyone.

Solution : if the remote host is a Gauntlet firewall, then
see http://www.tis.com/support/cyberadvisory.html, or else
you can probably ignore this alert.

Risk factor : High
-------------------------------
smtp (25/tcp)

High

list of hostnames


It seems that the remote host is vulnerable
to a buffer overflow on port 8999, which may
give a shell access to anyone.

Solution : if the remote host is a Gauntlet firewall, then
see http://www.tis.com/support/cyberadvisory.html, or else
you can probably ignore this alert.

Risk factor : High
-------------------------------


It appears to be listing the guantlet plugin notification for completelly
unrelated services. (see above)
The systems are completelly different, linux,unix,sgi.
I've looked through the systems and none of them have any listening
services on port 8999.

Versions:
nessusd: debian 2.0.10a-3
plugins updated via nessus-update-plugins.


-- 
Luke Computer Science System Administrator
Security Administrator,College of Engineering
Montana State University-Bozeman,Montana

_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to