Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Nessus: users

detect world writeable nfs shares on unix system services?

 

 

Nessus users RSS feed   Index | Next | Previous | View Threaded


jcranfill at gmail

Dec 16, 2008, 3:07 PM

Post #1 of 2 (911 views)
Permalink
detect world writeable nfs shares on unix system services?

New user, running Nessus 3 on XP sp3.

The following plugins work correctly for me when attempting to identify
world writeable nfs shares in a small *nix environment:

Mountable NFS Shares
NFS export
User Mountable NFS shares

However, they do not seem to pick up on two MS servers running Unix System
Services. Using 'showmount -e ussserver1or2' from the *nix boxes clearly
shows exported directories (and one writeable to everyone) available. Is
there another plugin available that would display these as the 'nfs export'
plugin does? Or any suggestions on how to modify it so that it will include
them?

Thanks,
JC


deraison-lists at nessus

Dec 19, 2008, 7:03 AM

Post #2 of 2 (836 views)
Permalink
Re: detect world writeable nfs shares on unix system services? [In reply to]

Hi Jeff,

On Dec 16, 2008, at 6:07 PM, Jeff Cranfill wrote:

> New user, running Nessus 3 on XP sp3.
>
> The following plugins work correctly for me when attempting to
> identify world writeable nfs shares in a small *nix environment:
>
> Mountable NFS Shares
> NFS export
> User Mountable NFS shares
>
> However, they do not seem to pick up on two MS servers running Unix
> System Services. Using 'showmount -e ussserver1or2' from the *nix
> boxes clearly shows exported directories (and one writeable to
> everyone) available. Is there another plugin available that would
> display these as the 'nfs export' plugin does? Or any suggestions
> on how to modify it so that it will include them?

First, could you make sure you're running the most up to date set of
plugins? We fixed some issues in NFS a month or so ago, maybe that
will solve your problem.

If not, could you send me (privately) a pcap of the traffic sent while
you do a 'showmount -e ussserver1or2' ?


Thanks,

-- Renaud




_______________________________________________
Nessus mailing list
Nessus [at] list
http://mail.nessus.org/mailman/listinfo/nessus

Nessus users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.