![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.11871 |
Category: | Misc. |
Title: | Find if IIS server allows BASIC and/or NTLM authentication |
Summary: | NOSUMMARY |
Description: | Description: The remote host appears to be running a version of IIS which allows remote users to determine which authentication schemes are required for confidential webpages. That is, by requesting valid webpages with purposely invalid credentials, you can ascertain whether or not the authentication scheme is in use. This can be used for brute-force attacks against known UserIDs. Solution : None at this time Risk factor : Low |
Cross-Ref: |
BugTraq ID: 4235 Common Vulnerability Exposure (CVE) ID: CVE-2002-0419 http://www.securityfocus.com/bid/4235 Bugtraq: 20020305 Considerations for IIS Authentication (#NISR05032002C) (Google Search) http://marc.info/?l=bugtraq&m=101535399100534&w=2 http://www.iss.net/security_center/static/8382.php |
Copyright | This script is Copyright (C) 2003 Tenable Network Security |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |