Full Disclosure mailing list archives

RE: Scanning the PCs for RPC Vulnerability


From: "Schmehl, Paul L" <pauls () utdallas edu>
Date: Wed, 3 Sep 2003 10:07:46 -0500

-----Original Message----- 
From: Nadeem Rafi [mailto:nrafi () jeraisy com] 
Sent: Wednesday, September 03, 2003 5:07 AM 
To: full-disclosure () lists netsys com 
Subject: [Full-disclosure] Scanning the PCs for RPC Vulnerability 

I have found some faults in the scanning tools available from 
Foundstone and Microsoft for RPC vulnerable machines. Both of 
these tools are not error free. These tools are showing the ip 
addresses of even those machines which are Windows 9x, 
Windows98/Sec, Windows ME. Both tools are not free from this error.

What do you mean by this?  I haven't used the Foundstone tool, but are
you saying that the MS tool puts IPs of Win9x/ME hosts on the list of
vulnerable hosts?

Paul Schmehl (pauls () utdallas edu)
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/~pauls/ 

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: