webForumDet fria alternativet

testadatorn, lite noteringar!

Datasäkerhet

0 svar · 218 visningar · startad av Sjodahl

Medlem sedan maj 20033 218 inlägg
Frågan#1

Hej går det att bli av med följande notisar?

Allvarlighetsgrad Problem och lösningar
Notering The following directories were discovered:
/cgi-bin, /css, /doc, /download, /icons, /image, /manual, /old, /test

While this is not, in and of itself, a bug, you should manually inspect
these directories to ensure that they are in compliance with company
security standards

Läs mer
Notering The following CGI have been discovered :

Syntax : cginame (arguments [default value])

/projekt/Kalender/index.php (Year [2005] Month [3] )
/index.php (0 [] date [3-2005] 0 [] )

Läs mer
Notering The remote web server type is :

Apache

and the 'ServerTokens' directive is ProductOnly
Apache does not permit to hide the server type.

Läs mer
Notering Remote MySQL version : 4.1.11

Läs mer
Varning
Mambo Site Server is an open source Web Content Management System. An attacker
may use it to perform a cross site scripting attack on this host.

Solution: Upgrade to the latest version of this software
Risk factor : Medium
BID : 9588

Läs mer
Varning
The remote server is running a version of PsNews (a content management system)
which is older than 1.2.

This version is affected by multiple cross-site scripting flaws. An attacker
may exploit these to steal the cookies from legitimate users of this website.

Solution : Upgrade to a newer version.
Risk factor : Medium
BID : 11124

Läs mer
Varning
The Terminal Services are enabled on the remote host.

Terminal Services allow a Windows user to remotely obtain
a graphical login (and therefore act as a local user on the
remote host).

If an attacker gains a valid login and password, he may
be able to use this service to gain further access
on the remote host. An attacker may also use this service
to mount a dictionnary attack against the remote host to try
to log in remotely.

Note that RDP (the Remote Desktop Protocol) is vulnerable
to Man-in-the-middle attacks, making it easy for attackers to
steal the credentials of legitimates users by impersonating the
Windows server.

Solution : Disable the Terminal Services if you do not use them, and
do not allow this service to run across the internet

Risk factor : Medium
CVE : CVE-2001-0540
BID : 3099, 7258

Läs mer
Varning
Mambo Site Server is an open source Web Content Management System. An attacker
may use it to perform a cross site scripting attack on this host.

Solution: Upgrade to a newer version.
Risk factor : Medium
BID : 7135

Läs mer
Notering For your information, here is the traceroute to 62.119.159.228 :
195.149.144.21
195.149.144.17
195.7.64.19
194.68.123.66
212.105.101.81
62.13.27.29
62.119.156.92
?
62.119.159.228

Läs mer
Varning
The remote host is running PHP Code Snippet Library (PHP-CSL), a library
written in PHP.

The remote version of this software is vulnerable to a cross-site scripting
attack.

An attacker can exploit it by compromising the values of the parameter
cat_select in index.php.

This can be used to take advantage of the trust between a client and server
allowing the malicious user to execute malicious JavaScript on
the client's machine.

Solution : Upgrade to the latest version of this software
Risk factor: Medium
BID : 11038

Läs mer
Varning
The remote host seems to be running MyAbraCadaWeb. An attacker
may use it to perform a cross site scripting attack on
this host, or to reveal the full path to its physical location.

Solution: Upgrade to a newer version.
Risk factor : Medium
BID : 7126, 7127

Läs mer
Varning
CuteNews is installed on the remote host.

This host is vulnerable to a cross-site-scripting (XSS) attack.
An attacker, exploiting this flaw, would need to be able
to coerce a user to browse to a purposefully malicious URI.
Upon successful exploitation, the attacker would be able
to run code within the web-browser in the security context of the
CuteNews server.

Solution : Upgrade to the latest version
Risk factor : Medium
BID : 11097

Läs mer
Varning
The remote host is using Invision Power Board.

There is a bug in this software which makes it vulnerable to cross site
scripting attacks.

An attacker may use this bug to steal the credentials of the legitimate users
of this site.

Solution : At this time, the vendor did not supply any patch
Risk factor : High
BID : 9822

Läs mer

265 ms totalt · 4 externa anrop · v20260731065814-full.a51de22e
128 ms — deklarationer (db)
0 ms — hämta statistik (cache)
132 ms — hämta tråd, inlägg och bilagor (db)
127 ms — ändringar (db)