查看: 1717|回复: 7

漏洞

  [复制链接]

傻♂逼

梦石
0
星屑
374
在线时间
1606 小时
注册时间
2007-3-13
回帖
6005

烫烫烫开拓者

发表于 2008-2-4 03:45:15 | 显示全部楼层 |阅读模式

加入我们,或者,欢迎回来。

您需要 登录 才可以下载或查看,没有账号?注册会员

×
而且我用Telnet通过21号端口勉强连上了6R服务器 因该把telnet服务禁掉的 net stop telnet BY XScn 我承认我无聊,我RP. 真的! 扫描时间 2008-2-3 19:33:28 - 2008-2-3 19:39:23 检测结果 存活主机 1 漏洞数量 0 警告数量 1 提示数量 4 主机列表 主机 检测结果 222.77.178.198 发现安全警告 主机摘要 - OS: Unknown OS; PORT/TCP: 21, 80, 3389 [返回顶部] 主机分析: 222.77.178.198 主机地址 端口/服务 服务漏洞 222.77.178.198 www (80/tcp) 发现安全提示 222.77.178.198 ftp (21/tcp) 发现安全提示 222.77.178.198 Windows Terminal Services (3389/tcp) 发现安全提示 222.77.178.198 msrdp (3389/tcp) 发现安全警告 安全漏洞及解决方案: 222.77.178.198 类型 端口/服务 安全漏洞及解决方案 提示 www (80/tcp) 开放服务 "WEB"服务运行于该端口 BANNER信息 : HTTP/1.1 400 Bad Request Content-Type: text/html Date: Sun, 03 Feb 2008 11:33:49 GMT Connection: close Content-Length: 39

Bad Request (Invalid Hostname)

NESSUS_ID : 10330 提示 ftp (21/tcp) 开放服务 "ftp"服务可能运行于该端口. NESSUS_ID : 10330 提示 Windows Terminal Services (3389/tcp) 开放服务 "Windows Terminal Services"服务可能运行于该端口. NESSUS_ID : 10330 提示 Windows Terminal Services (3389/tcp) Windows Terminal Service Enabled The Terminal Services are enabled on the remote host. Terminal Services allow a Windows user to remotely obtain a graphical login (and therefore act as a local user on the remote host). If an attacker gains a valid login and password, he may be able to use this service to gain further access on the remote host. An attacker may also use this service to mount a dictionnary attack against the remote host to try to log in remotely. Note that RDP (the Remote Desktop Protocol) is vulnerable to Man-in-the-middle attacks, making it easy for attackers to steal the credentials of legitimates users by impersonating the Windows server. Solution : Disable the Terminal Services if you do not use them, and do not allow this service to run across the internet Risk factor : Medium BUGTRAQ_ID : 3099, 7258 NESSUS_ID : 10940 警告 msrdp (3389/tcp) Microsoft Windows Remote Desktop Protocol Server Private Key Disclosure Vulnerability The remote version of Remote Desktop Protocol Server (Terminal Service) is vulnerable to a man in the middle attack. An attacker may exploit this flaw to decrypt communications between client and server and obtain sensitive information (passwords, ...). See Also : http://www.oxid.it/downloads/rdp-gbu.pdf Solution : None at this time. Risk factor : Medium CVE_ID : CAN-2005-1794 BUGTRAQ_ID : 13818 NESSUS_ID : 18405 --------------------------------------------------------------------------------
哎呀,蛋疼什么的最有爱了

名侦探小柯

梦石
10
星屑
4393
在线时间
3739 小时
注册时间
2006-9-6
回帖
36595

极短27获奖MZ评测员开拓者贵宾第3届短篇游戏大赛主流游戏组亚军第5届短篇游戏比赛亚军

发表于 2008-2-4 03:50:31 | 显示全部楼层
我讨厌报告BUG又要VIP看的帖……
不定期回归 ~ 游戏开发之旅
———————————————————————————————
回复

使用道具 举报

傻♂逼

梦石
0
星屑
374
在线时间
1606 小时
注册时间
2007-3-13
回帖
6005

烫烫烫开拓者

 楼主| 发表于 2008-2-4 03:53:36 | 显示全部楼层
以下引用越前リョーマ于2008-2-3 19:50:31的发言:

我讨厌报告BUG又要VIP看的帖……

只是报告而已.给你看了也没用
哎呀,蛋疼什么的最有爱了
回复

使用道具 举报

有事烧纸

梦石
0
星屑
154
在线时间
509 小时
注册时间
2005-10-22
回帖
6429

贵宾VX城市地图大赛冠军第1届RMTV比赛冠军第1届TG大赛冠军

发表于 2008-2-4 04:06:50 | 显示全部楼层
好。。。好深奥的漏洞- -
米看懂。。。等6来看好了。。。。
神隐中,偶尔诈尸
回复

使用道具 举报

胃:伪·好人之怨念<

梦石
0
星屑
50
在线时间
4 小时
注册时间
2007-6-24
回帖
4977

开拓者VX城市地图大赛亚军

发表于 2008-2-4 07:17:38 | 显示全部楼层
我也讨厌报告BUG还弄VIP限制的贴
哈哈哈哈哈
回复

使用道具 举报

傻♂逼

梦石
0
星屑
374
在线时间
1606 小时
注册时间
2007-3-13
回帖
6005

烫烫烫开拓者

 楼主| 发表于 2008-2-4 18:35:31 | 显示全部楼层
主要看警告
漏洞没什么
主要是可能被利用的服务
  1. 提示 Windows Terminal Services (3389/tcp) 开放服务

  2. "Windows Terminal Services"服务可能运行于该端口.
复制代码
哎呀,蛋疼什么的最有爱了
回复

使用道具 举报

傻♂逼

梦石
0
星屑
374
在线时间
1606 小时
注册时间
2007-3-13
回帖
6005

烫烫烫开拓者

 楼主| 发表于 2008-2-4 18:36:54 | 显示全部楼层
END。
太RP了
回复

使用道具 举报

鬼神

梦石
0
星屑
60
在线时间
23 小时
注册时间
2007-12-24
回帖
453
发表于 2008-2-5 08:10:01 | 显示全部楼层
本帖需要VIP点 34464 才能浏览!
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册会员

本版积分规则

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.

在本版发帖返回顶部