Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member mickalo's Avatar
    Join Date
    Apr 2002
    Location
    N.W. Iowa
    Posts
    753

    Default Security Metrics Scan

    Hello,

    we have a customer who uses this Security Metrics to process secure ordering. They ran a scan the other day on our server and had one issue which I'm not real sure what can be done or how to correct it. This is the issue they sent us:
    Code:
    Synopsis : It is possible to log on the remote device with 
    a default password. Description : The remote Linksys device has 
    its default password (no username  / 'admin') set. An attacker may 
    connect to it and reconfigure it using this account. Solution: Connect 
    to this port with a web browser, and click on the 'Password' section 
    to set a strong password. Risk Factor: High  / CVSS Base Score : 
    7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P) 
    Other references : OSVDB:
    This is in reference to TCP ports 2082 and 2095. Is there way to correct this issue that won't cause problems?

    Thx's

    Thunder Rain Internet Publishing

    Providing Internet Solutions that work!
    Custom Perl and Database Programming

  2. #2
    Member
    Join Date
    Jan 2005
    Location
    /dev/null
    Posts
    770

    Default

    it looks distinctly like a false positive, unless you have an account 'admin' with no password set on it on your server

  3. #3
    Member mickalo's Avatar
    Join Date
    Apr 2002
    Location
    N.W. Iowa
    Posts
    753

    Default

    thanks for the info. there is an account "admin" setup but that's been there since the server was setup over 4yrs ago and has a password assigned to it. So not sure what the problem is.

    Mike

    Thunder Rain Internet Publishing

    Providing Internet Solutions that work!
    Custom Perl and Database Programming

  4. #4
    Member
    Join Date
    Dec 2006
    Posts
    113

    Default

    Their scanner thinks that it can log into 2082 and 2095 with no username set, and a password of: admin

    It's highly unlikely that's accurate as nickp666 said, but I'd try it anyway, and when it doesn't actually work, I'd tell the SecurityMetrics people what nick said, that it's a false positive.

    I wonder if the SecurityMetrics people are allowed to verify the scan results manually. If they are adamant that the results are accurate, tell them you give them permission to try to manually verify the results.

    If you wouldn't mind, I'd be interested in knowing the outcome of this (e.g., how SecurityMetrics handled it, if they were able to manually attempt to verify the results, etc).

  5. #5
    Member mickalo's Avatar
    Join Date
    Apr 2002
    Location
    N.W. Iowa
    Posts
    753

    Default

    well I think the false/positive results is exactly the issue. we've gone through and manually tried logging in on those ports and it always failed. The "admin" account does not have SSH/shell access either.

    we've submitted our finding to those Security Metrics people and awaiting their response.

    thx's for assistance.

    Mike

    Thunder Rain Internet Publishing

    Providing Internet Solutions that work!
    Custom Perl and Database Programming

Similar Threads & Tags
Similar threads

  1. Quick Security Scan Question
    By Doug E in forum Security
    Replies: 2
    Last Post: 07-19-2009, 12:33 AM
  2. Security Metrics PCI compliance - Exim fails test.
    By jols in forum E-mail Discussions
    Replies: 6
    Last Post: 12-11-2008, 11:55 PM
  3. Security scan on server failed
    By veronicabend in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 10-01-2008, 09:24 AM
  4. Quick Security Scan
    By Pete in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 01-16-2002, 11:44 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube