Bugtraq mailing list archives

Re: ISS Internet Scanner Cannot be relied upon for conclusive


From: blkadder () VALUE NET (blkadder () VALUE NET)
Date: Mon, 8 Feb 1999 09:55:03 -0800


On Mon, 8 Feb 1999, David LeBlanc wrote:

One of the ways to check for this particular bug is to us SNMP to pull down
the sysDescr information, and parse it to look for versions that we know
have problems. _If_ we can get the system description, it is an easy and
reliable way to find vulnerable machines.  However, if SNMP isn't running,
or won't respond (even after trying to guess the community string), then
this method won't work.

Another method to check for that particular bug is to actually attempt the
exploit. And you are not doing that because.... ???



Current thread: