兴化400生活网

标题: 懂网络安全的进来看看! [打印本页]

作者: 繁星    时间: 2005-6-20 13:53
标题: 懂网络安全的进来看看!
<TABLE cellSpacing=1 cellPadding=2 width="100%" border=0><TBODY><TR><TD class=title colSpan=2>扫描时间</TD></TR><TR><TD class=default width="100%">2005-6-20 13:34:14 - 2005-6-20 13:41:53</TD></TR></TBODY></TABLE><BR><BR><TABLE cellSpacing=0 cellPadding=0 width="60%" bgColor=#a1a1a1 border=0><TBODY><TR><TD><TABLE cellSpacing=1 cellPadding=2 width="100%" border=0><TBODY><TR><TD class=title colSpan=2>检测结果</TD></TR><TR><TD class=default width="60%">存活主机</TD><TD class=default width="30%">1</TD></TR><TR><TD class=default width="60%">漏洞数量</TD><TD class=default width="30%">0</TD></TR><TR><TD class=default width="60%">警告数量</TD><TD class=default width="30%">3</TD></TR><TR><TD class=default width="60%">提示数量</TD><TD class=default width="30%">8</TD></TR></TBODY></TABLE></TD></TR></TBODY></TABLE><BR><BR><A name=toc></A><TABLE cellSpacing=0 cellPadding=0 width="60%" bgColor=#a1a1a1 border=0><TBODY><TR><TD><TABLE cellSpacing=1 cellPadding=2 width="100%" border=0><TBODY><TR><TD class=title colSpan=2>主机列表</TD></TR><TR><TD class=sub width="60%">主机</TD><TD class=sub width="40%">检测结果</TD></TR><TR><TD class=default width="60%">&lt;A href="file:///C:/Documents%20and%20Settings/chen/Local%20Settings/Temp/Rar$EX01.188/X-Scan-v3.2/log/218_90_240_116_report.html#218_90_240_116"><FONT color=#0000cf>218.90.240.116</FONT></A></TD><TD class=default width="40%">发现安全警告</TD></TR><TR><TD class=default colSpan=100>主机摘要 - OS: Unknown OS; PORT/TCP: 21, 80, 1025, 3389</TD></TR></TBODY></TABLE></TD></TR></TBODY></TABLE><A name=218_90_240_116></A><A name=218_90_240_116_toc></A><DIV align=left><FONT color=#0000cf size=-2>&lt;A href="file:///C:/Documents%20and%20Settings/chen/Local%20Settings/Temp/Rar$EX01.188/X-Scan-v3.2/log/218_90_240_116_report.html#toc">[返回顶部]</A></FONT></DIV><BR><BR><TABLE cellSpacing=0 cellPadding=0 width="60%" bgColor=#a1a1a1 border=0><TBODY><TR><TD><TABLE cellSpacing=1 cellPadding=2 width="100%" border=0><TBODY><TR><TD class=title colSpan=3>主机分析: 218.90.240.116</TD></TR><TR><TD class=sub width="20%">主机地址</TD><TD class=sub width="30%">端口/服务</TD><TD class=sub width="30%">服务漏洞</TD></TR><TR><TD class=default width="20%">218.90.240.116</TD><TD class=default width="30%">&lt;A href="file:///C:/Documents%20and%20Settings/chen/Local%20Settings/Temp/Rar$EX01.188/X-Scan-v3.2/log/218_90_240_116_report.html#218_90_240_116_80_tcp"><FONT color=#0000cf>www (80/tcp)</FONT></A></TD><TD class=default width="30%">发现安全提示</TD></TR><TR><TD class=default width="20%">218.90.240.116</TD><TD class=default width="30%">&lt;A href="file:///C:/Documents%20and%20Settings/chen/Local%20Settings/Temp/Rar$EX01.188/X-Scan-v3.2/log/218_90_240_116_report.html#218_90_240_116_21_tcp"><FONT color=#0000cf>ftp (21/tcp)</FONT></A></TD><TD class=default width="30%">发现安全提示</TD></TR><TR><TD class=default width="20%">218.90.240.116</TD><TD class=default width="30%">&lt;A href="file:///C:/Documents%20and%20Settings/chen/Local%20Settings/Temp/Rar$EX01.188/X-Scan-v3.2/log/218_90_240_116_report.html#218_90_240_116_3389_tcp"><FONT color=#0000cf>Windows Terminal Services (3389/tcp)</FONT></A></TD><TD class=default width="30%">发现安全警告</TD></TR><TR><TD class=default width="20%">218.90.240.116</TD><TD class=default width="30%">&lt;A href="file:///C:/Documents%20and%20Settings/chen/Local%20Settings/Temp/Rar$EX01.188/X-Scan-v3.2/log/218_90_240_116_report.html#218_90_240_116_1025_tcp"><FONT color=#0000cf>network blackjack (1025/tcp)</FONT></A></TD><TD class=default width="30%">发现安全提示</TD></TR><TR><TD class=default width="20%">218.90.240.116</TD><TD class=default width="30%">&lt;A href="file:///C:/Documents%20and%20Settings/chen/Local%20Settings/Temp/Rar$EX01.188/X-Scan-v3.2/log/218_90_240_116_report.html#218_90_240_116_137_udp"><FONT color=#0000cf>netbios-ns (137/udp)</FONT></A></TD><TD class=default width="30%">发现安全警告</TD></TR><TR><TD class=default width="20%">218.90.240.116</TD><TD class=default width="30%">&lt;A href="file:///C:/Documents%20and%20Settings/chen/Local%20Settings/Temp/Rar$EX01.188/X-Scan-v3.2/log/218_90_240_116_report.html#218_90_240_116_1434_udp"><FONT color=#0000cf>ms-sql-m (1434/udp)</FONT></A></TD><TD class=default width="30%">发现安全警告</TD></TR></TBODY></TABLE></TD></TR></TBODY></TABLE><BR><BR><TABLE cellSpacing=0 cellPadding=0 width="75%" bgColor=#a1a1a1 border=0><TBODY><TR><TD><TABLE cellSpacing=1 cellPadding=2 width="100%" border=0><TBODY><TR><TD class=title colSpan=3>安全漏洞及解决方案: 218.90.240.116</TD></TR><TR><TD class=sub width="10%">类型</TD><TD class=sub width="20%">端口/服务</TD><TD class=sub width="70%">安全漏洞及解决方案</TD></TR><TR><TD class=default vAlign=top width="10%">提示</TD><TD class=default vAlign=top width="20%"><A name=218_90_240_116_80_tcp></A>www (80/tcp)</TD><TD class=default width="70%">A web server is running on this port<BR>Here is its banner : <BR>HTTP/1.1 200 OK <BR>Content-Length: 1839 <BR>Content-Type: text/html <BR>Content-Location: <A href="http://218.90.240.116/Default.htm"><FONT color=#0000cf>http://218.90.240.116/Default.htm</FONT></A> <BR>Last-Modified: Tue, 08 Mar 2005 15:59:10 GMT <BR>Accept-Ranges: bytes <BR>ETag: "01bdfc3f723c51:268" <BR>Server: Microsoft-IIS/6.0 <BR>X-Powered-By: ASP.NET <BR>Date: Mon, 20 Jun 2005 05:42:35 GMT <BR>Connection: close <BR><BR><BR><BR>&lt;body style="MARGIN: 0px" scroll=no onResize=javascript:parent.carnoc.location.reload()&gt; <BR>&lt;script&gt; <BR>if(self!=top){top.location=<BR>NESSUS_ID : <A href="http://cgi.nessus.org/nessus_id.php3?id=10330"><FONT color=#0000cf>10330</FONT></A><BR></TD></TR><TR><TD class=default vAlign=top width="10%">提示</TD><TD class=default vAlign=top width="20%"><A name=218_90_240_116_80_tcp></A>www (80/tcp)</TD><TD class=default width="70%">该插件试图确认远程主机上存在的各普通目录<BR>___________________________________________________________________<BR><BR>The following directories were discovered:<BR>/images, /img, /inc<BR><BR>While this is not, in and of itself, a bug, you should manually inspect <BR>these directories to ensure that they are in compliance with company<BR>security standards<BR><BR>NESSUS_ID : <A href="http://cgi.nessus.org/nessus_id.php3?id=11032"><FONT color=#0000cf>11032</FONT></A><BR></TD></TR><TR><TD class=default vAlign=top width="10%">提示</TD><TD class=default vAlign=top width="20%"><A name=218_90_240_116_80_tcp></A>www (80/tcp)</TD><TD class=default width="70%">此脚本将映射远程web站点并提取一份远程主机所用的CGI列表.<BR><BR>建议你给此插件设置一个较高的超时值.<BR>所要映射的页面需在客户端的&#39;选项&#39;中修改.<BR><BR>风险等级:无<BR>___________________________________________________________________<BR><BR>The following CGI have been discovered :<BR><BR>Syntax : cginame (arguments [default value])<BR><BR>/login.asp (Submit [ 取消 ] Submit1 [ 登录 ] username [] url [Default.asp] xuansave [1] menu [out] eremite [1] )<BR>/search.asp (forumid [] )<BR>/ShowPost.asp (action [Previous] id [44323] topage [22] )<BR>/Default.asp ()<BR>/EditProfile.asp (menu [pass] )<BR>/favorites.asp (menu [topic] )<BR>/Profile.asp (username [寂嫫戀人] )<BR>/help.asp (menu [guizhe] )<BR>/online.asp (menu [cutline] )<BR>/ShowBBS.asp (menu [5] )<BR>/RecoverPasswd.asp (username [] birthday [] Submit1 [ 确定 ] Submit [ 取消 ] )<BR>. (order [regtime] )<BR>/ShowForum.asp (TimeLimit [] search [] forumid [94] order [] topage [2] )<BR>/error.asp (message=&lt;li&gt;您还未&lt;a href [login.asp&gt;登录&lt;/a&gt;社区] message [&lt;li&gt;的用户资料不存在] )<BR>/friend.asp (username [400] menu [add] )<BR><BR>NESSUS_ID : <A href="http://cgi.nessus.org/nessus_id.php3?id=10662"><FONT color=#0000cf>10662</FONT></A><BR></TD></TR><TR><TD class=default vAlign=top width="10%">提示</TD><TD class=default vAlign=top width="20%"><A name=218_90_240_116_80_tcp></A>www (80/tcp)</TD><TD class=default width="70%">发现 HTTP 服务器的类型及版本号.<BR><BR>解决方案: 配置服务器经常更改名称,如:&#39;Wintendo httpD w/Dotmatrix display&#39;<BR>确保移除类似 apache_pb.gif 带有 Apache 的通用标志, 可以设定 &#39;ServerTokens Prod&#39; 为受限<BR>该信息来源于服务器本身的响应首部.<BR><BR>风险等级 : 低<BR>___________________________________________________________________<BR><BR>The remote web server type is :<BR><BR>Microsoft-IIS/6.0 <BR><BR>Solution : You can use urlscan to change reported server for IIS.<BR>NESSUS_ID : <A href="http://cgi.nessus.org/nessus_id.php3?id=10107"><FONT color=#0000cf>10107</FONT></A><BR></TD></TR><TR><TD class=default vAlign=top width="10%">提示</TD><TD class=default vAlign=top width="20%"><A name=218_90_240_116_21_tcp></A>ftp (21/tcp)</TD><TD class=default width="70%">The service closed the connection after 0 seconds without sending any data<BR>It might be protected by some TCP wrapper<BR><BR>NESSUS_ID : <A href="http://cgi.nessus.org/nessus_id.php3?id=10330"><FONT color=#0000cf>10330</FONT></A><BR></TD></TR><TR><TD class=default vAlign=top width="10%">警告</TD><TD class=default vAlign=top width="20%"><A name=218_90_240_116_3389_tcp></A>Windows Terminal Services (3389/tcp)</TD><TD class=default width="70%"><BR>The Terminal Services are enabled on the remote host.<BR><BR>Terminal Services allow a Windows user to remotely obtain<BR>a graphical login (and therefore act as a local user on the<BR>remote host).<BR><BR>If an attacker gains a valid login and password, he may<BR>be able to use this service to gain further access<BR>on the remote host. An attacker may also use this service<BR>to mount a dictionnary attack against the remote host to try<BR>to log in remotely.<BR><BR>Note that RDP (the Remote Desktop Protocol) is vulnerable<BR>to Man-in-the-middle attacks, making it easy for attackers to<BR>steal the credentials of legitimates users by impersonating the<BR>Windows server.<BR><BR>Solution : Disable the Terminal Services if you do not use them, and<BR>do not allow this service to run across the internet<BR><BR>Risk factor : Medium<BR>BUGTRAQ_ID : <A href="http://cgi.nessus.org/bid.php3?bid=3099"><FONT color=#0000cf>3099</FONT></A>, <A href="http://cgi.nessus.org/bid.php3?bid=7258"><FONT color=#0000cf>7258</FONT></A><BR>NESSUS_ID : <A href="http://cgi.nessus.org/nessus_id.php3?id=10940"><FONT color=#0000cf>10940</FONT></A><BR></TD></TR><TR><TD class=default vAlign=top width="10%">提示</TD><TD class=default vAlign=top width="20%"><A name=218_90_240_116_3389_tcp></A>Windows Terminal Services (3389/tcp)</TD><TD class=default width="70%">Maybe the "Windows Terminal Services" service running on this port.<BR><BR>NESSUS_ID : <A href="http://cgi.nessus.org/nessus_id.php3?id=10330"><FONT color=#0000cf>10330</FONT></A><BR></TD></TR><TR><TD class=default vAlign=top width="10%">提示</TD><TD class=default vAlign=top width="20%"><A name=218_90_240_116_1025_tcp></A>network blackjack (1025/tcp)</TD><TD class=default width="70%">Maybe the "network blackjack" service running on this port.<BR><BR>NESSUS_ID : <A href="http://cgi.nessus.org/nessus_id.php3?id=10330"><FONT color=#0000cf>10330</FONT></A><BR></TD></TR><TR><TD class=default vAlign=top width="10%">提示</TD><TD class=default vAlign=top width="20%"><A name=218_90_240_116_1025_tcp></A>network blackjack (1025/tcp)</TD><TD class=default width="70%">一个不知名的服务正在这个端口运行。<BR>他可能是由一个木马所打开.<BR>除非你确实知道这个端口所运行的程序,<BR>你最好检查你的系统.<BR><BR>解决方案: 运行最好的反病毒软件确认是否有木马在运行。<BR><BR>风险等级:低<BR>___________________________________________________________________<BR><BR>An unknown service runs on this port.<BR>It is sometimes opened by this/these Trojan horse(s):<BR>Fraggle Rock<BR>md5 Backdoor<BR>NetSpy<BR>Remote Storm<BR><BR>Unless you know for sure what is behind it, you&#39;d better<BR>check your system<BR><BR>*** Anyway, don&#39;t panic, Nessus only found an open port. It may<BR>*** have been dynamically allocated to some service (RPC...)<BR><BR>Solution: if a trojan horse is running, run a good antivirus scanner<BR>Risk factor : Low<BR>NESSUS_ID : <A href="http://cgi.nessus.org/nessus_id.php3?id=11157"><FONT color=#0000cf>11157</FONT></A><BR></TD></TR><TR><TD class=default vAlign=top width="10%">警告</TD><TD class=default vAlign=top width="20%"><A name=218_90_240_116_137_udp></A>netbios-ns (137/udp)</TD><TD class=default width="70%">如果NetBIOS端口(UDP:137)已经打开,<BR>一个远程攻击者可以利用这个漏洞获得主机<BR>的敏感信息,比如机器名,工作组/域名,<BR>当前登陆用户名等。<BR><BR>解决方法:阻止这个端口的外部通信。<BR><BR>风险等级:中<BR>___________________________________________________________________<BR><BR>The following 6 NetBIOS names have been gathered :<BR>MIR-MIRTSB <BR>WORKGROUP = Workgroup / Domain name<BR>MIR-MIRTSB = This is the computer name<BR>WORKGROUP = Workgroup / Domain name (part of the Browser elections)<BR>WORKGROUP <BR>__MSBROWSE__ <BR>The remote host has the following MAC address on its adapter :<BR>00:0c:6e:e0:b9:ca<BR><BR>If you do not want to allow everyone to find the NetBios name<BR>of your computer, you should filter incoming traffic to this port.<BR><BR>Risk factor : Medium<BR>CVE_ID : <A href="http://cgi.nessus.org/cve.php3?cve=CAN-1999-0621"><FONT color=#0000cf>CAN-1999-0621</FONT></A><BR>NESSUS_ID : <A href="http://cgi.nessus.org/nessus_id.php3?id=10150"><FONT color=#0000cf>10150</FONT></A><BR></TD></TR><TR><TD class=default vAlign=top width="10%">警告</TD><TD class=default vAlign=top width="20%"><A name=218_90_240_116_1434_udp></A>ms-sql-m (1434/udp)</TD><TD class=default width="70%">Microsoft SQL server has a function wherein remote users can <BR>query the database server for the version that is being run.<BR>The query takes place over the same UDP port which handles the <BR>mapping of multiple SQL server instances on the same machine.<BR><BR>CAVEAT: It is important to note that, after Version 8.00.194, Microsoft<BR>decided not to update this function. This means that the data <BR>returned by the SQL ping is inaccurate for newer releases of SQL Server<BR><BR>Nessus sent an MS SQL &#39;ping&#39; request. The results were : <BR>ServerName MIR-MIRTSB InstanceName MSSQLSERVER IsClustered No Version 8.00.194 tcp 1433 np &#92;&#92;MIR-MIRTSB&#92;pipe&#92;sql&#92;query <BR><BR><BR>If you are not running multiple instances of Microsoft SQL Server<BR>on the same machine, It is suggested you filter incoming traffic to this port<BR>NESSUS_ID : <A href="http://cgi.nessus.org/nessus_id.php3?id=10674"><FONT color=#0000cf>10674</FONT></A><BR></TD></TR></TD></TR></TBODY></TABLE></TD></TR></TBODY></TABLE><FONT size=6>这个可是个好东东。而且是400</FONT>
作者: 明月独上西楼    时间: 2005-6-20 16:01
<><IMG src="http://www.400.com.cn/images/Emotions/65.gif"><IMG src="http://www.400.com.cn/images/Emotions/65.gif">X-scan 现在怎么人人都会用了!厉害!</P><>这些问题都是正常的提供服务的端口,所以400还是很安全的!</P><>不要想歪主意了!</P><p>[此帖子已被 明月独上西楼 在 2005-6-20 18:30:22 编辑过]
作者: 麻虎子    时间: 2005-6-21 08:54
<>哈哈,我的传奇登陆服务器就是侦听1025端口,不能把他也认作木马吧,所有说这些工具软件也知识凭的以前的经验来的,技术在发展,搞安全方面的还不能完全信赖于工具软件。现在几大病毒厂商都在研究主动防御,理论上来讲这是不可能的,只有发现了病毒后才出现疫苗。只可能是商家叫的卖点,X-SCAN也一样,他只能扫出软件制作者知道的漏洞。</P><>楼主已经把自己的机器管理员名暴露在这了哦 admin&nbsp; user:chen</P><p>[此帖子已被 麻虎子 在 2005-6-21 8:57:14 编辑过]
作者: 天养    时间: 2005-6-21 10:56
满瓶不动半瓶摇.<IMG src="http://www.400.com.cn/images/Emotions/52.gif">
作者: 烂香蕉    时间: 2005-6-25 19:15
<>大家小心````不要慌张````````黑客又出来吓人了``````````</P>
作者: 近看丑巴巴    时间: 2005-6-27 10:45
<>谢谢提示。</P>
作者: 全職殺手    时间: 2005-7-3 19:12
呵呵




欢迎光临 兴化400生活网 (http://wenhui.vc7.cc/) Powered by Discuz! X2.5