Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.11871
Category:Misc.
Title:Find if IIS server allows BASIC and/or NTLM authentication
Summary:NOSUMMARY
Description:Description:

The remote host appears to be running a version of IIS which allows remote
users to determine which authentication schemes are required for confidential
webpages.

That is, by requesting valid webpages with purposely invalid credentials, you
can ascertain whether or not the authentication scheme is in use. This can
be used for brute-force attacks against known UserIDs.

Solution : None at this time
Risk factor : Low

Cross-Ref: BugTraq ID: 4235
Common Vulnerability Exposure (CVE) ID: CVE-2002-0419
http://www.securityfocus.com/bid/4235
Bugtraq: 20020305 Considerations for IIS Authentication (#NISR05032002C) (Google Search)
http://marc.info/?l=bugtraq&m=101535399100534&w=2
http://www.iss.net/security_center/static/8382.php
CopyrightThis script is Copyright (C) 2003 Tenable Network Security

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.