Network Vulnerability Assessment Report
19.09.2006
Sorted by host names

Session name: Acorp LAN420Start Time:19.09.2006 14:21:33
Finish Time:19.09.2006 14:32:05
Elapsed:0 day(s) 00:10:32
Total records generated:9
high severity:0
Medium severity:1
informational:8


Summary of scanned hosts

HostHolesWarningsOpen portsState
10.0.0.75012Finished


10.0.0.75

ServiceSeverityDescription
www (80/tcp)
Info
Port is open
telnet (23/tcp)
Info
Port is open
telnet (23/tcp)
Medium

Synopsis :

A telnet server is listening on the remote port

Description :

The remote host is running a telnet server.
Using telnet is not recommended as logins, passwords and commands
are transferred in clear text.

An attacker may eavesdrop on a telnet session and obtain the
credentials of other users.

Solution :

Disable this service and use SSH instead

Risk factor :

Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:NR/C:P/A:N/I:N/B:C)

Plugin output:

Remote telnet banner:


BusyBox on router login:
telnet (23/tcp)
Info
A telnet server seems to be running on this port
www (80/tcp)
Info
The following directories were discovered:
/cgi-bin, /html

While this is not, in and of itself, a bug, you should manually inspect
these directories to ensure that they are in compliance with company
security standards

Other references : OWASP:OWASP-CM-006
www (80/tcp)
Info
The following CGI have been discovered :

Syntax : cginame (arguments [default value])

/cgi-bin/webcm (var:main [menu] var:style [style5] getpage [../html/defs/style5/menus/menu.html] errorpage [../html/index.html] var:pagename [home] var:errorpagename [home] var:menu [home] var:menutitle [Home] var:pagetitle [Home] var:pagemaster [home] login:command/username [] login:command/password [] )

www (80/tcp)
Info
The remote web server type is :




general/tcp
Info
Nessus was not able to reliably identify the remote operating system. It might be:
APC PowerNet UPS
APC UPS Management Card
EMC Celerra File Server
Fluke Optiview Network Analyzer
HP Deskjet 6127
Netopia Router
Nexsan ATABeast disk vault server
QNX 6.3
Sony Network Camera SNC-RZ30N
www (80/tcp)
Info
A web server is running on this port