Vulnérabilités SSL/TLS détectées
Vulnérabilités SSL/TLS détectées
Scan_service_reseau_metasploitable
Lun. 5 mai 2025 06:14:32 EDT
[Link] 1/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
83738 (1) - SSL/TLS EXPORT_DHE <= Suites de chiffrement d'exportation 512 bits prises en charge (Logjam)
83875 (1) - Module Diffie-Hellman SSL/TLS <= 1024 bits (Logjam)
153953 (1) - Algorithmes d'échange de clés faibles SSH activés
11219 (26) - Scanner Nessus SYN
11111 (10) - Énumération des services RPC
22964 (8) - Détection de service
10092 (2) - Détection de serveur FTP
10107 (2) - Type et version du serveur HTTP
10863 (2) - Informations sur le certificat SSL
11002 (2) - Détection du serveur DNS
11011 (2) - Détection du service SMB Microsoft Windows
17975 (2) - Détection de service (requête GET)
21643 (2) - Suites de chiffrement SSL prises en charge
22227 (2) - Détection du registre RMI
24260 (2) - Informations sur le protocole HTTP (HyperText Transfer Protocol)
45410 (2) - Incompatibilité du certificat SSL « commonName »
50845 (2) - Détection OpenSSL
56984 (2) - SSL / TLS Versions Supported
57041 (2) - SSL Perfect Forward Secrecy Cipher Suites Supported
62563 (2) - SSL Compression Methods Supported
70544 (2) - SSL Cipher Block Chaining Cipher Suites Supported
156899 (2) - SSL/TLS Recommended Cipher Suites
10028 (1) - DNS Server BIND version Directive Remote Version Detection
10150 (1) - Windows NetBIOS / SMB Remote Host Information Disclosure
10223 (1) - RPC portmapper Service Detection
10263 (1) - SMTP Server Detection
10267 (1) - SSH Server Type and Version Information
10281 (1) - Telnet Server Detection
10287 (1) - Traceroute Information
10342 (1) - VNC Software Detection
10397 (1) - Microsoft Windows SMB LanMan Pipe Server Listing Disclosure
10437 (1) - NFS Share Export List
10785 (1) - Microsoft Windows SMB NativeLanManager Remote System Information Disclosure
10881 (1) - SSH Protocol Versions Supported
11153 (1) - Service Detection (HELP Request)
11154 (1) - Unknown Service Detection: Banner Retrieval
11156 (1) - IRC Daemon Version Detection
11422 (1) - Web Server Unconfigured - Default Install Page Present
11424 (1) - WebDAV Detection
11819 (1) - TFTP Daemon Detection
11936 (1) - OS Identification
18261 (1) - Apache Banner Linux Distribution Disclosure
19288 (1) - VNC Server Security Type Detection
19506 (1) - Nessus Scan Information
20108 (1) - Web Server / Application [Link] Vendor Fingerprinting
21186 (1) - AJP Connector Detection
25220 (1) - TCP/IP Timestamps Supported
25240 (1) - Samba Server Detection
26024 (1) - PostgreSQL Server Detection
35371 (1) - DNS Server [Link] Map Hostname Disclosure
35716 (1) - Ethernet Card Manufacturer Detection
[Link] 2/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
39446 (1) - Apache Tomcat Detection
39519 (1) - Backported Security Patch Detection (FTP)
39520 (1) - Backported Security Patch Detection (SSH)
39521 (1) - Backported Security Patch Detection (WWW)
42088 (1) - SMTP Service STARTTLS Command Support
45590 (1) - Common Platform Enumeration (CPE)
48204 (1) - Apache HTTP Server Version
48243 (1) - PHP Version Detection
51891 (1) - SSL Session Resume Supported
52703 (1) - vsftpd Detection
53335 (1) - RPC portmapper (TCP)
54615 (1) - Device Type
65792 (1) - VNC Server Unencrypted Communication Detection
66334 (1) - Patch Report
70657 (1) - SSH Algorithms and Languages Supported
72779 (1) - DNS Server Version Detection
84574 (1) - Backported Security Patch Detection (PHP)
86420 (1) - Ethernet MAC Addresses
96982 (1) - Server Message Block (SMB) Protocol Version 1 Enabled (uncredentialed check)
100871 (1) - Microsoft Windows SMB Versions Supported (remote check)
104887 (1) - Samba Version
106716 (1) - Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check)
110723 (1) - Target Credential Status by Authentication Protocol - No Credentials Provided
117886 (1) - OS Security Patch Assessment Not Available
118224 (1) - PostgreSQL STARTTLS Support
135860 (1) - WMI Not Available
149334 (1) - SSH Password Authentication Accepted
153588 (1) - SSH SHA-1 HMAC Algorithms Enabled
181418 (1) - OpenSSH Detection
209654 (1) - OS Fingerprints Detected
Synopsis
The remote service encrypts traffic using a protocol with known weaknesses.
Description
The remote service accepts connections encrypted using SSL 2.0 and/or SSL 3.0. These versions of SSL are affected by several cryptographic flaws, including:
An attacker can exploit these flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected service and clients.
Although SSL/TLS has a secure means for choosing the highest supported version of the protocol (so that these versions will be used only if the client or server
support nothing better), many web browsers implement this in an unsafe way that allows an attacker to downgrade a connection (such as in POODLE). Therefore,
it is recommended that these protocols be disabled entirely.
NIST has determined that SSL 3.0 is no longer acceptable for secure communications. As of the date of enforcement found in PCI DSS v3.1, any version of SSL will
not meet the PCI SSC's definition of 'strong cryptography'.
See Also
[Link] 3/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
Solution
Consult the application's documentation to disable SSL 2.0 and 3.0.
Use TLS 1.2 (with approved cipher suites) or higher instead.
Risk Factor
Critical
Plugin Information
Published: 2005/10/12, Modified: 2022/04/04
Plugin Output
[Link] (tcp/25/smtp)
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
[Link] (tcp/5432/postgresql)
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
32321 (2) - Debian OpenSSH/OpenSSL Package Random Number Generator Weakness (SSL check) -
Synopsis
The remote SSL certificate uses a weak key.
Description
The remote x509 certificate on the remote SSL server has been generated on a Debian or Ubuntu system which contains a bug in the random number generator
of its OpenSSL library.
The problem is due to a Debian packager removing nearly all sources of entropy in the remote version of OpenSSL.
An attacker can easily obtain the private part of the remote key and use this to decipher the remote session or set up a man in the middle attack.
See Also
[Link]
[Link]
Solution
Consider all cryptographic material generated on the remote host to be guessable. In particuliar, all SSH, SSL and OpenVPN key material should be re-generated.
Risk Factor
Critical
VPR Score
5.1
[Link] 5/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
EPSS Score
0.0165
References
BID 29179
CVE CVE-2008-0166
XREF CWE:310
Exploitable With
Core Impact (true)
Plugin Information
Published: 2008/05/15, Modified: 2020/11/16
Plugin Output
[Link] (tcp/25/smtp)
[Link] (tcp/5432/postgresql)
32314 (1) - Debian OpenSSH/OpenSSL Package Random Number Generator Weakness -
Synopsis
The remote SSH host keys are weak.
Description
The remote SSH host key has been generated on a Debian or Ubuntu system which contains a bug in the random number generator of its OpenSSL library.
The problem is due to a Debian packager removing nearly all sources of entropy in the remote version of OpenSSL.
An attacker can easily obtain the private part of the remote key and use this to set up decipher the remote session or set up a man in the middle attack.
See Also
[Link]
[Link]
Solution
Consider all cryptographic material generated on the remote host to be guessable. In particuliar, all SSH, SSL and OpenVPN key material should be re-generated.
Risk Factor
Critical
VPR Score
5.1
EPSS Score
0.0165
References
BID 29179
CVE CVE-2008-0166
XREF CWE:310
Exploitable With
Core Impact (true)
[Link] 6/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Plugin Information
Published: 2008/05/14, Modified: 2024/07/24
Plugin Output
[Link] (tcp/22/ssh)
46882 (1) - UnrealIRCd Backdoor Detection -
Synopsis
The remote IRC server contains a backdoor.
Description
The remote IRC server is a version of UnrealIRCd with a backdoor that allows an attacker to execute arbitrary code on the affected host.
See Also
[Link]
[Link]
[Link]
Solution
Re-download the software, verify it using the published MD5 / SHA1 checksums, and re-install it.
Risk Factor
Critical
VPR Score
8.4
EPSS Score
0.6132
References
BID 40820
CVE CVE-2010-2075
Exploitable With
CANVAS (true) Metasploit (true)
Plugin Information
Published: 2010/06/14, Modified: 2022/04/11
Plugin Output
[Link] (tcp/6667/irc)
uid=0(root) gid=0(root)
Synopsis
The remote host may have been compromised.
Description
A shell is listening on the remote port without any authentication being required. An attacker may use it by connecting to the remote port and sending commands
directly.
Solution
[Link] 7/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Verify if the remote host has been compromised, and reinstall the system if necessary.
Risk Factor
Critical
Plugin Information
Published: 2011/02/15, Modified: 2022/04/11
Plugin Output
[Link] (tcp/1524/wild_shell)
Synopsis
A VNC server running on the remote host is secured with a weak password.
Description
The VNC server running on the remote host is secured with a weak password. Nessus was able to login using VNC authentication and a password of 'password'. A
remote, unauthenticated attacker could exploit this to take control of the system.
Solution
Secure the VNC service with a strong password.
Risk Factor
Critical
Plugin Information
Published: 2012/08/29, Modified: 2015/09/24
Plugin Output
[Link] (tcp/5900/vnc)
Synopsis
There is a vulnerable AJP connector listening on the remote host.
Description
A file read/inclusion vulnerability was found in AJP connector. A remote, unauthenticated attacker could exploit this vulnerability to read web application files from
a vulnerable server. In instances where the vulnerable server allows file uploads, an attacker could upload malicious JavaServer Pages (JSP) code within a variety of
file types and gain remote code execution (RCE).
See Also
[Link] 8/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
Solution
Update the AJP configuration to require authorization and/or upgrade the Tomcat server to 7.0.100, 8.5.51, 9.0.31 or later.
Risk Factor
High
VPR Score
8.9
EPSS Score
0.9447
References
CVE CVE-2020-1745
CVE CVE-2020-1938
XREF CISA-KNOWN-EXPLOITED:2022/03/17
XREF CEA-ID:CEA-2020-0021
Plugin Information
Published: 2020/03/24, Modified: 2025/02/12
Plugin Output
[Link] (tcp/8009/ajp13)
Nessus was able to exploit the issue using the following request :
0x0000: 02 02 00 08 48 54 54 50 2F 31 2E 31 00 00 0F 2F ....HTTP/1.1.../
0x0010: 61 73 64 66 2F 78 78 78 78 78 2E 6A 73 70 00 00 asdf/[Link]..
0x0020: 09 6C 6F 63 61 6C 68 6F 73 74 00 FF FF 00 09 6C .localhost.....l
0x0030: 6F 63 61 6C 68 6F 73 74 00 00 50 00 00 09 A0 06 ocalhost..P.....
0x0040: 00 0A 6B 65 65 70 2D 61 6C 69 76 65 00 00 0F 41 ..keep-alive...A
0x0050: 63 63 65 70 74 2D 4C 61 6E 67 75 61 67 65 00 00 ccept-Language..
0x0060: 0E 65 6E 2D 55 53 2C 65 6E 3B 71 3D 30 2E 35 00 .en-US,en;q=0.5.
0x0070: A0 08 00 01 30 00 00 0F 41 63 63 65 70 74 2D 45 ....0...Accept-E
0x0080: 6E 63 6F 64 69 6E 67 00 00 13 67 7A 69 70 2C 20 ncoding...gzip,
0x0090: 64 65 66 6C 61 74 65 2C 20 73 64 63 68 00 00 0D deflate, sdch...
0x00A0: 43 61 63 68 65 2D 43 6F 6E 74 72 6F 6C 00 00 09 Cache-Control...
0x00B0: 6D 61 78 2D 61 67 65 3D 30 00 A0 0E 00 07 4D 6F max-age=0.....Mo
0x00C0: 7A 69 6C 6C 61 00 00 19 55 70 67 72 61 64 65 2D zilla...Upgrade-
0x00D0: 49 6E 73 65 63 75 72 65 2D 52 65 71 75 65 73 74 Insecure-Request
0x00E0: 73 00 00 01 31 00 A0 01 00 09 74 65 78 74 2F 68 s...1.....text/h
0x00F0: 74 6D 6C 00 A0 0B 00 09 6C 6F 63 61 6C 68 6F 73 tml.....localhos
0x0100: 74 00 0A 00 21 6A 61 76 61 78 2E 73 65 72 76 6C t...![Link]
0x0110: 65 74 2E 69 6E 63 6C 75 64 65 2E 72 65 71 75 65 [Link]
0x0120: 73 74 5F 75 72 69 00 00 01 31 00 0A 00 1F 6A 61 st_uri...1....ja
0x0130: 76 61 78 2E 73 65 72 76 6C 65 74 2E 69 6E 63 6C [Link]
0x0140: 75 64 65 2E 70 61 74 68 5F 69 6E 66 6F 00 00 10 ude.path_info...
0x0150: 2F 57 45 42 2D 49 4E 46 2F 77 65 62 2E 78 6D 6C /WEB-INF/[Link]
0x0160: 00 0A 00 22 6A 61 76 61 78 2E 73 65 72 76 6C 65 ..."[Link]
0x0170: 74 2E 69 6E 63 6C 75 64 65 2E 73 65 72 76 6C 65 [Link]
0x0180: 74 5F 70 61 74 68 00 00 00 00 FF t_path.....
[Link] 9/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
[Link]
[...]
Synopsis
An unsupported version of Apache Tomcat is installed on the remote host.
Description
According to its version, Apache Tomcat is less than or equal to 5.5.x. It is, therefore, no longer maintained by its vendor or provider.
Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
[Link]
Solution
Upgrade to a version of Apache Tomcat that is currently supported.
Risk Factor
Critical
Plugin Information
Published: 2023/02/10, Modified: 2024/05/06
Plugin Output
[Link] (tcp/8180/www)
URL : [Link]
Installed version : 5.5
Security End of Life : September 30, 2012
Time since Security End of Life (Est.) : >= 12 years
Synopsis
An unsupported version of Canonical Ubuntu Linux is installed on the remote host.
Description
According to its version, Canonical Ubuntu Linux is 8.04.x. It is, therefore, no longer maintained by its vendor or provider.
Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it may contain security vulnerabilities.
See Also
[Link]
Solution
Upgrade to a version of Canonical Ubuntu Linux that is currently supported.
[Link] 10/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Risk Factor
Critical
Plugin Information
Published: 2024/07/03, Modified: 2025/03/26
Plugin Output
[Link] (tcp/80/www)
Synopsis
The remote service supports the use of medium strength SSL ciphers.
Description
The remote host supports the use of SSL ciphers that offer medium strength encryption. Nessus regards medium strength as any encryption that uses key lengths
at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.
Note that it is considerably easier to circumvent medium strength encryption if the attacker is on the same physical network.
See Also
[Link]
[Link]
Solution
Reconfigure the affected application if possible to avoid use of medium strength ciphers.
Risk Factor
Medium
VPR Score
5.1
EPSS Score
0.4002
References
CVE CVE-2016-2183
Plugin Information
Published: 2009/11/23, Modified: 2025/02/12
Plugin Output
[Link] (tcp/25/smtp)
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
[Link] 11/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Name Code KEX Auth Encryption MAC
---------------------- ---------- --- ---- --------------------- ---
DES-CBC3-MD5 0x07, 0x00, 0xC0 RSA RSA 3DES-CBC(168) MD5
EDH-RSA-DES-CBC3-SHA 0x00, 0x16 DH RSA 3DES-CBC(168) SHA1
ADH-DES-CBC3-SHA 0x00, 0x1B DH None 3DES-CBC(168) SHA1
DES-CBC3-SHA 0x00, 0x0A RSA RSA 3DES-CBC(168) SHA1
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
[Link] (tcp/5432/postgresql)
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
Synopsis
The rlogin service is running on the remote host.
Description
The rlogin service is running on the remote host. This service is vulnerable since data is passed between the rlogin client and server in cleartext. A man-in-the-
middle attacker can exploit this to sniff logins and passwords. Also, it may allow poorly authenticated logins without passwords. If the host is vulnerable to TCP
sequence number guessing (from any network) or IP spoofing (including ARP hijacking on a local network) then it may be possible to bypass authentication.
Finally, rlogin is an easy way to turn file-write access into full logins through the .rhosts or [Link] files.
Solution
Comment out the 'login' line in /etc/[Link] and restart the inetd process. Alternatively, disable this service and use SSH instead.
Risk Factor
High
VPR Score
7.4
EPSS Score
0.4664
References
CVE CVE-1999-0651
Exploitable With
Metasploit (true)
Plugin Information
Published: 1999/08/30, Modified: 2022/04/11
Plugin Output
[Link] (tcp/513/rlogin)
10245 (1) - rsh Service Detection -
[Link] 12/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Synopsis
The rsh service is running on the remote host.
Description
The rsh service is running on the remote host. This service is vulnerable since data is passed between the rsh client and server in cleartext. A man-in-the-middle
attacker can exploit this to sniff logins and passwords. Also, it may allow poorly authenticated logins without passwords. If the host is vulnerable to TCP sequence
number guessing (from any network) or IP spoofing (including ARP hijacking on a local network) then it may be possible to bypass authentication.
Finally, rsh is an easy way to turn file-write access into full logins through the .rhosts or [Link] files.
Solution
Comment out the 'rsh' line in /etc/[Link] and restart the inetd process. Alternatively, disable this service and use SSH instead.
Risk Factor
High
VPR Score
7.4
EPSS Score
0.4664
References
CVE CVE-1999-0651
Exploitable With
Metasploit (true)
Plugin Information
Published: 1999/08/22, Modified: 2022/04/11
Plugin Output
[Link] (tcp/514/rsh)
42256 (1) - NFS Shares World Readable -
Synopsis
The remote NFS server exports world-readable shares.
Description
The remote NFS server is exporting one or more shares without restricting access (based on hostname, IP, or IP range).
See Also
[Link]
Solution
Place the appropriate restrictions on all NFS shares.
Risk Factor
Medium
Plugin Information
Published: 2009/10/26, Modified: 2024/02/21
Plugin Output
[Link] (tcp/2049/rpc-nfs)
[Link] 13/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
/ *
Synopsis
An SMB server running on the remote host is affected by the Badlock vulnerability.
Description
The version of Samba, a CIFS/SMB server for Linux and Unix, running on the remote host is affected by a flaw, known as Badlock, that exists in the Security
Account Manager (SAM) and Local Security Authority (Domain Policy) (LSAD) protocols due to improper authentication level negotiation over Remote Procedure
Call (RPC) channels. A man-in-the-middle attacker who is able to able to intercept the traffic between a client and a server hosting a SAM database can exploit this
flaw to force a downgrade of the authentication level, which allows the execution of arbitrary Samba network calls in the context of the intercepted user, such as
viewing or modifying sensitive security data in the Active Directory (AD) database or disabling critical services.
See Also
[Link]
[Link]
Solution
Upgrade to Samba version 4.2.11 / 4.3.8 / 4.4.2 or later.
Risk Factor
Medium
VPR Score
5.9
EPSS Score
0.7865
References
BID 86002
CVE CVE-2016-2118
XREF CERT:813296
Plugin Information
Published: 2016/04/13, Modified: 2019/11/20
Plugin Output
[Link] (tcp/445/cifs)
Nessus detected that the Samba Badlock patch has not been applied.
Synopsis
The remote name server is affected by Service Downgrade / Reflected DoS vulnerabilities.
Description
[Link] 14/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
According to its self-reported version, the instance of ISC BIND 9 running on the remote name server is affected by performance downgrade and Reflected DoS
vulnerabilities. This is due to BIND DNS not sufficiently limiting the number fetches which may be performed while processing a referral response.
An unauthenticated, remote attacker can exploit this to cause degrade the service of the recursive server or to use the affected server as a reflector in a reflection
attack.
See Also
[Link]
Solution
Upgrade to the ISC BIND version referenced in the vendor advisory.
Risk Factor
Medium
VPR Score
5.2
EPSS Score
0.0334
STIG Severity
I
References
CVE CVE-2020-8616
XREF IAVA:2020-A-0217-S
Plugin Information
Published: 2020/05/22, Modified: 2024/03/12
Plugin Output
[Link] (udp/53/dns)
Synopsis
The remote server's SSL certificate has already expired.
Description
This plugin checks expiry dates of certificates associated with SSL- enabled services on the target and reports whether any have already expired.
Solution
Purchase or generate a new SSL certificate to replace the existing one.
Risk Factor
Medium
[Link] 15/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Plugin Information
Published: 2004/12/03, Modified: 2021/02/03
Plugin Output
[Link] (tcp/25/smtp)
Subject : C=XX, ST=There is no such thing outside US, L=Everywhere, O=OCOSA, OU=Office for Complication of Otherwise Simple Affairs,
CN=[Link], emailAddress=root@[Link]
Issuer : C=XX, ST=There is no such thing outside US, L=Everywhere, O=OCOSA, OU=Office for Complication of Otherwise Simple Affairs,
CN=[Link], emailAddress=root@[Link]
Not valid before : Mar 17 14:07:45 2010 GMT
Not valid after : Apr 16 14:07:45 2010 GMT
[Link] (tcp/5432/postgresql)
Subject : C=XX, ST=There is no such thing outside US, L=Everywhere, O=OCOSA, OU=Office for Complication of Otherwise Simple Affairs,
CN=[Link], emailAddress=root@[Link]
Issuer : C=XX, ST=There is no such thing outside US, L=Everywhere, O=OCOSA, OU=Office for Complication of Otherwise Simple Affairs,
CN=[Link], emailAddress=root@[Link]
Not valid before : Mar 17 14:07:45 2010 GMT
Not valid after : Apr 16 14:07:45 2010 GMT
Synopsis
The SSL certificate for this service is for a different host.
Description
The 'commonName' (CN) attribute of the SSL certificate presented for this service is for a different machine.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
Plugin Information
Published: 2010/04/03, Modified: 2020/04/27
Plugin Output
[Link] (tcp/25/smtp)
[Link]
[Link]
[Link]
[Link] (tcp/5432/postgresql)
[Link] 16/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
[Link]
[Link]
[Link]
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which the chain of trust can be broken, as stated below :
- First, the top of the certificate chain sent by the server might not be descended from a known public certificate authority. This can occur either when the top of
the chain is an unrecognized, self-signed certificate, or when intermediate certificates are missing that would connect the top of the certificate chain to a known
public certificate authority.
- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can occur either when the scan occurs before one of the
certificate's 'notBefore' dates, or after one of the certificate's 'notAfter' dates.
- Third, the certificate chain may contain a signature that either didn't match the certificate's information or could not be verified. Bad signatures can be fixed by
getting the certificate with the bad signature to be re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a
signing algorithm that Nessus either does not support or does not recognize.
If the remote host is a public host in production, any break in the chain makes it more difficult for users to verify the authenticity and identity of the web server.
This could make it easier to carry out man-in-the-middle attacks against the remote host.
See Also
[Link]
[Link]
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
Plugin Information
Published: 2010/12/15, Modified: 2020/04/27
Plugin Output
[Link] (tcp/25/smtp)
|-Subject : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple
Affairs/CN=[Link]/E=root@[Link]
|-Not After : Apr 16 14:07:45 2010 GMT
|-Subject : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple
Affairs/CN=[Link]/E=root@[Link]
|-Issuer : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple
Affairs/CN=[Link]/E=root@[Link]
[Link] (tcp/5432/postgresql)
|-Subject : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple
[Link] 17/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Affairs/CN=[Link]/E=root@[Link]
|-Not After : Apr 16 14:07:45 2010 GMT
|-Subject : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple
Affairs/CN=[Link]/E=root@[Link]
|-Issuer : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple
Affairs/CN=[Link]/E=root@[Link]
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use
of SSL as anyone could establish a man-in-the-middle attack against the remote host.
Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output
[Link] (tcp/25/smtp)
|-Subject : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple
Affairs/CN=[Link]/E=root@[Link]
[Link] (tcp/5432/postgresql)
|-Subject : C=XX/ST=There is no such thing outside US/L=Everywhere/O=OCOSA/OU=Office for Complication of Otherwise Simple
Affairs/CN=[Link]/E=root@[Link]
Synopsis
The remote service supports the use of the RC4 cipher.
Description
The remote host supports the use of RC4 in one or more cipher suites.
The RC4 cipher is flawed in its generation of a pseudo-random stream of bytes so that a wide variety of small biases are introduced into the stream, decreasing its
randomness.
If plaintext is repeatedly encrypted (e.g., HTTP cookies), and an attacker is able to obtain many (i.e., tens of millions) ciphertexts, the attacker may be able to derive
the plaintext.
See Also
[Link] 18/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
[Link]
[Link]
[Link]
[Link]
[Link]
Solution
Reconfigure the affected application, if possible, to avoid use of RC4 ciphers. Consider using TLS 1.2 with AES-GCM suites subject to browser and web server
support.
Risk Factor
Medium
VPR Score
7.3
EPSS Score
0.9303
References
BID 58796
BID 73684
CVE CVE-2013-2566
CVE CVE-2015-2808
Plugin Information
Published: 2013/04/05, Modified: 2025/04/04
Plugin Output
[Link] (tcp/25/smtp)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
[Link] (tcp/5432/postgresql)
[Link] 19/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
Synopsis
The remote service encrypts traffic using an older version of TLS.
Description
The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate
these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and should be used whenever possible.
As of March 31, 2020, Endpoints that aren’t enabled for TLS 1.2 and higher will no longer function properly with major web browsers and major vendors.
PCI DSS v3.2 requires that TLS 1.0 be disabled entirely by June 30, 2018, except for POS POI terminals (and the SSL/TLS termination points to which they connect)
that can be verified as not being susceptible to any known exploits.
See Also
[Link]
Solution
Enable support for TLS 1.2 and 1.3, and disable support for TLS 1.0.
Risk Factor
Medium
References
XREF CWE:327
Plugin Information
Published: 2017/11/22, Modified: 2023/04/19
Plugin Output
[Link] (tcp/25/smtp)
[Link] (tcp/5432/postgresql)
Synopsis
Debugging functions are enabled on the remote web server.
Description
[Link] 20/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
The remote web server supports the TRACE and/or TRACK methods. TRACE and TRACK are HTTP methods that are used to debug web server connections.
See Also
[Link]
[Link]
[Link]
Solution
Disable these HTTP methods. Refer to the plugin output for more information.
Risk Factor
Medium
VPR Score
4.0
EPSS Score
0.8269
References
BID 9506
BID 9561
BID 11604
BID 33374
BID 37995
CVE CVE-2003-1567
CVE CVE-2004-2320
CVE CVE-2010-0386
XREF CERT:288308
XREF CERT:867593
XREF CWE:16
XREF CWE:200
Plugin Information
Published: 2003/01/23, Modified: 2024/04/09
Plugin Output
[Link] (tcp/80/www)
To disable these methods, add the following lines for each virtual
host in your configuration file :
RewriteEngine on
RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK)
RewriteRule .* - [F]
------------------------------ snip ------------------------------\n\nand received the following response from the remote server
[Link] 21/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
:\n\n------------------------------ snip ------------------------------\nHTTP/1.1 200 OK
Date: Mon, 05 May 2025 10:04:29 GMT
Server: Apache/2.2.8 (Ubuntu) DAV/2
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Transfer-Encoding: chunked
Content-Type: message/http
Synopsis
The remote web server contains default files.
Description
The default error page, default index page, example JSPs and/or example servlets are installed on the remote Apache Tomcat server. These files should be
removed as they may help an attacker uncover information about the remote Tomcat install or host itself.
See Also
[Link]
[Link]
Solution
Delete the default index page and remove the example JSP and servlets. Follow the Tomcat or OWASP instructions to replace or modify the default error page.
Risk Factor
Medium
Plugin Information
Published: 2004/03/02, Modified: 2024/09/03
Plugin Output
[Link] (tcp/8180/www)
[Link]
The server is not configured to return a custom page in the event of a client requesting a non-existent resource.
This may result in a potential disclosure of sensitive information about the server to attackers.
Synopsis
The remote DNS server is vulnerable to cache snooping attacks.
Description
The remote DNS server responds to queries for third-party domains that do not have the recursion bit set.
This may allow a remote attacker to determine which domains have recently been resolved via this name server, and therefore which hosts have been recently
visited.
For instance, if an attacker was interested in whether your company utilizes the online services of a particular financial institution, they would be able to use this
attack to build a statistical model regarding company usage of that financial institution. Of course, the attack can also be used to find B2B partners, web-surfing
patterns, external mail servers, and more.
[Link] 22/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Note: If this is an internal DNS server not accessible to outside networks, attacks would be limited to the internal network. This may include employees,
consultants and potentially users on a guest network or WiFi connection if supported.
See Also
[Link]
Solution
Contact the vendor of the DNS software for a fix.
Risk Factor
Medium
Plugin Information
Published: 2004/04/27, Modified: 2020/04/07
Plugin Output
[Link] (udp/53/dns)
[Link]
Synopsis
The remote service supports the use of weak SSL ciphers.
Description
The remote host supports the use of SSL ciphers that offer weak encryption.
Note: This is considerably easier to exploit if the attacker is on the same physical network.
See Also
[Link]
Solution
Reconfigure the affected application, if possible to avoid the use of weak ciphers.
Risk Factor
Medium
References
XREF CWE:326
XREF CWE:327
XREF CWE:720
XREF CWE:753
XREF CWE:803
XREF CWE:928
XREF CWE:934
Plugin Information
[Link] 23/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Published: 2007/10/08, Modified: 2021/02/03
Plugin Output
[Link] (tcp/25/smtp)
Here is the list of weak SSL ciphers supported by the remote server :
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
Synopsis
The remote service supports the use of anonymous SSL ciphers.
Description
The remote host supports the use of anonymous SSL ciphers. While this enables an administrator to set up a service that encrypts traffic without having to
generate and configure SSL certificates, it offers no way to verify the remote host's identity and renders the service vulnerable to a man-in-the-middle attack.
Note: This is considerably easier to exploit if the attacker is on the same physical network.
See Also
[Link]
Solution
Reconfigure the affected application if possible to avoid use of weak ciphers.
Risk Factor
Low
VPR Score
4.4
EPSS Score
0.027
References
[Link] 24/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
BID 28482
CVE CVE-2007-1858
Plugin Information
Published: 2008/03/28, Modified: 2023/10/27
Plugin Output
[Link] (tcp/25/smtp)
The following is a list of SSL anonymous ciphers supported by the remote TCP server :
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
33447 (1) - Multiple Vendor DNS Query ID Field Prediction Cache Poisoning -
Synopsis
The remote name resolver (or the server it uses upstream) is affected by a DNS cache poisoning vulnerability.
Description
The remote DNS resolver does not use random ports when making queries to third-party DNS servers. An unauthenticated, remote attacker can exploit this to
poison the remote DNS server, allowing the attacker to divert legitimate traffic to arbitrary sites.
See Also
[Link]
[Link]
Solution
Contact your DNS server vendor for a patch.
Risk Factor
Medium
VPR Score
6.0
EPSS Score
0.9211
[Link] 25/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)
STIG Severity
I
References
BID 30131
CVE CVE-2008-1447
XREF CERT:800113
XREF IAVA:2008-A-0045
XREF EDB-ID:6122
XREF EDB-ID:6123
XREF EDB-ID:6130
Plugin Information
Published: 2008/07/09, Modified: 2024/04/03
Plugin Output
[Link] (udp/53/dns)
Synopsis
The remote Telnet server transmits traffic in cleartext.
Description
The remote host is running a Telnet server over an unencrypted channel.
Using Telnet over an unencrypted channel is not recommended as logins, passwords, and commands are transferred in cleartext. This allows a remote, man-in-
the-middle attacker to eavesdrop on a Telnet session to obtain credentials or other sensitive information and to modify traffic exchanged between a client and
server.
SSH is preferred over Telnet since it protects credentials from eavesdropping and can tunnel additional data streams such as an X11 session.
Solution
Disable the Telnet service and use SSH instead.
Risk Factor
Medium
Plugin Information
Published: 2009/10/27, Modified: 2024/01/16
Plugin Output
[Link] (tcp/23/telnet)
Nessus collected the following banner from the remote Telnet server :
[Link] 26/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
_ _ _ _ _ _ ____
_ __ ___ ___| |_ __ _ ___ _ __ | | ___ (_) |_ __ _| |__ | | ___|___ \
| '_ ` _ \ / _ \ __/ _` / __| '_ \| |/ _ \| | __/ _` | '_ \| |/ _ \ __) |
| | | | | | __/ || (_| \__ \ |_) | | (_) | | || (_| | |_) | | __// __/
|_| |_| |_|\___|\__\__,_|___/ .__/|_|\___/|_|\__\__,_|_.__/|_|\___|_____|
|_|
Contact: msfdev[at][Link]
metasploitable login:
------------------------------ snip ------------------------------
Synopsis
The remote mail service allows plaintext command injection while negotiating an encrypted communications channel.
Description
The remote SMTP service contains a software flaw in its STARTTLS implementation that could allow a remote, unauthenticated attacker to inject commands during
the plaintext protocol phase that will be executed during the ciphertext protocol phase.
Successful exploitation could allow an attacker to steal a victim's email or associated SASL (Simple Authentication and Security Layer) credentials.
See Also
[Link]
[Link]
Solution
Contact the vendor to see if an update is available.
Risk Factor
Medium
VPR Score
7.3
EPSS Score
0.6128
References
BID 46767
CVE CVE-2011-0411
CVE CVE-2011-1430
CVE CVE-2011-1431
CVE CVE-2011-1432
CVE CVE-2011-1506
CVE CVE-2011-2165
XREF CERT:555316
Plugin Information
Published: 2011/03/10, Modified: 2019/03/06
Plugin Output
[Link] (tcp/25/smtp)
STARTTLS\r\nRSET\r\n
[Link] 27/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Synopsis
Signing is not required on the remote SMB server.
Description
Signing is not required on the remote SMB server. An unauthenticated, remote attacker can exploit this to conduct man-in-the-middle attacks against the SMB
server.
See Also
[Link]
[Link]
[Link]
[Link]
[Link]
Solution
Enforce message signing in the host's configuration. On Windows, this is found in the policy setting 'Microsoft network server: Digitally sign communications
(always)'. On Samba, the setting is called 'server signing'. See the 'see also' links for further details.
Risk Factor
Medium
Plugin Information
Published: 2012/01/19, Modified: 2022/10/05
Plugin Output
[Link] (tcp/445/cifs)
81606 (1) - SSL/TLS EXPORT_RSA <= 512-bit Cipher Suites Supported (FREAK) -
Synopsis
The remote host supports a set of weak ciphers.
Description
The remote host supports EXPORT_RSA cipher suites with keys less than or equal to 512 bits. An attacker can factor a 512-bit RSA modulus in a short amount of
time.
A man-in-the middle attacker may be able to downgrade the session to use EXPORT_RSA cipher suites (e.g. CVE-2015-0204). Thus, it is recommended to remove
support for weak cipher suites.
See Also
[Link]
[Link]
[Link]
Solution
Reconfigure the service to remove support for EXPORT_RSA cipher suites.
Risk Factor
Medium
[Link] 28/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
VPR Score
1.4
EPSS Score
0.9243
References
BID 71936
CVE CVE-2015-0204
XREF CERT:243585
Plugin Information
Published: 2015/03/04, Modified: 2021/02/03
Plugin Output
[Link] (tcp/25/smtp)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
89058 (1) - SSL DROWN Attack Vulnerability (Decrypting RSA with Obsolete and Weakened eNcryption) -
Synopsis
The remote host may be affected by a vulnerability that allows a remote attacker to potentially decrypt captured TLS traffic.
Description
The remote host supports SSLv2 and therefore may be affected by a vulnerability that allows a cross-protocol Bleichenbacher padding oracle attack known as
DROWN (Decrypting RSA with Obsolete and Weakened eNcryption). This vulnerability exists due to a flaw in the Secure Sockets Layer Version 2 (SSLv2)
implementation, and it allows captured TLS traffic to be decrypted. A man-in-the-middle attacker can exploit this to decrypt the TLS connection by utilizing
previously captured traffic and weak cryptography along with a series of specially crafted connections to an SSLv2 server that uses the same private key.
See Also
[Link]
[Link]
Solution
Disable SSLv2 and export grade cryptography cipher suites. Ensure that private keys are not used anywhere with server software that supports SSLv2 connections.
Risk Factor
Medium
[Link] 29/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
VPR Score
3.6
EPSS Score
0.8991
References
BID 83733
CVE CVE-2016-0800
XREF CERT:583776
Plugin Information
Published: 2016/03/01, Modified: 2025/04/04
Plugin Output
[Link] (tcp/25/smtp)
The remote host is affected by SSL DROWN and supports the following
vulnerable cipher suites :
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
Synopsis
The remote SSH server is configured to allow weak encryption algorithms or no algorithm at all.
Description
Nessus has detected that the remote SSH server is configured to use the Arcfour stream cipher or no cipher at all. RFC 4253 advises against using Arcfour due to
an issue with weak keys.
See Also
[Link]
Solution
Contact the vendor or consult product documentation to remove the weak ciphers.
Risk Factor
Medium
Plugin Information
[Link] 30/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Published: 2016/04/04, Modified: 2016/12/14
Plugin Output
[Link] (tcp/22/ssh)
arcfour
arcfour128
arcfour256
arcfour
arcfour128
arcfour256
Synopsis
The remote name server is affected by an assertion failure vulnerability.
Description
A denial of service (DoS) vulnerability exists in ISC BIND versions 9.11.18 / 9.11.18-S1 / 9.12.4-P2 / 9.13 / 9.14.11 / 9.15 / 9.16.2 / 9.17 / 9.17.1 and earlier. An
unauthenticated, remote attacker can exploit this issue, via a specially-crafted message, to cause the service to stop responding.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
[Link]
Solution
Upgrade to the patched release most closely related to your current version of BIND.
Risk Factor
Medium
VPR Score
4.4
EPSS Score
0.9238
STIG Severity
I
References
CVE CVE-2020-8617
XREF IAVA:2020-A-0217-S
Plugin Information
Published: 2020/05/22, Modified: 2023/03/23
Plugin Output
[Link] (udp/53/dns)
[Link] 31/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
139915 (1) - ISC BIND 9.x < 9.11.22, 9.12.x < 9.16.6, 9.17.x < 9.17.4 DoS -
Synopsis
The remote name server is affected by a denial of service vulnerability.
Description
According to its self-reported version number, the installation of ISC BIND running on the remote name server is version 9.x prior to 9.11.22, 9.12.x prior to 9.16.6
or 9.17.x prior to 9.17.4. It is, therefore, affected by a denial of service (DoS) vulnerability due to an assertion failure when attempting to verify a truncated
response to a TSIG-signed request. An authenticated, remote attacker can exploit this issue by sending a truncated response to a TSIG-signed request to trigger an
assertion failure, causing the server to exit.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
See Also
[Link]
Solution
Upgrade to BIND 9.11.22, 9.16.6, 9.17.4 or later.
Risk Factor
Medium
VPR Score
4.4
EPSS Score
0.0045
STIG Severity
I
References
CVE CVE-2020-8622
XREF IAVA:2020-A-0385-S
Plugin Information
Published: 2020/08/27, Modified: 2021/06/03
Plugin Output
[Link] (udp/53/dns)
78479 (2) - SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE) -
Synopsis
[Link] 32/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
It is possible to obtain sensitive information from the remote host with SSL/TLS-enabled services.
Description
The remote host is affected by a man-in-the-middle (MitM) information disclosure vulnerability known as POODLE. The vulnerability is due to the way SSL 3.0
handles padding bytes when decrypting messages encrypted using block ciphers in cipher block chaining (CBC) mode.
MitM attackers can decrypt a selected byte of a cipher text in as few as 256 tries if they are able to force a victim application to repeatedly send the same data over
newly created SSL 3.0 connections.
As long as a client and service both support SSLv3, a connection can be 'rolled back' to SSLv3, even if TLSv1 or newer is supported by the client and service.
The TLS Fallback SCSV mechanism prevents 'version rollback' attacks without impacting legacy clients; however, it can only protect connections when the client and
service support the mechanism. Sites that cannot disable SSLv3 immediately should enable this mechanism.
This is a vulnerability in the SSLv3 specification, not in any particular SSL implementation. Disabling SSLv3 is the only way to completely mitigate the vulnerability.
See Also
[Link]
[Link]
[Link]
Solution
Disable SSLv3.
Services that must support SSLv3 should enable the TLS Fallback SCSV mechanism until SSLv3 can be disabled.
Risk Factor
Medium
VPR Score
5.1
EPSS Score
0.942
References
BID 70574
CVE CVE-2014-3566
XREF CERT:577193
Plugin Information
Published: 2014/10/15, Modified: 2023/06/23
Plugin Output
[Link] (tcp/25/smtp)
Nessus determined that the remote server supports SSLv3 with at least one CBC
cipher suite, indicating that this server is vulnerable.
[Link] (tcp/5432/postgresql)
[Link] 33/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Nessus determined that the remote server supports SSLv3 with at least one CBC
cipher suite, indicating that this server is vulnerable.
Synopsis
It is possible to determine the exact time set on the remote host.
Description
The remote host answers to an ICMP timestamp request. This allows an attacker to know the date that is set on the targeted machine, which may assist an
unauthenticated, remote attacker in defeating time-based authentication protocols.
Timestamps returned from machines running Windows Vista / 7 / 2008 / 2008 R2 are deliberately incorrect, but usually within 1000 seconds of the actual system
time.
Solution
Filter out the ICMP timestamp requests (13), and the outgoing ICMP timestamp replies (14).
Risk Factor
Low
VPR Score
2.2
EPSS Score
0.0037
References
CVE CVE-1999-0524
XREF CWE:200
Plugin Information
Published: 1999/08/01, Modified: 2024/10/07
Plugin Output
[Link] (icmp/0)
Synopsis
An X11 server is listening on the remote host
Description
The remote host is running an X11 server. X11 is a client-server protocol that can be used to display graphical applications running on a given host on a remote
client.
Since the X11 traffic is not ciphered, it is possible for an attacker to eavesdrop on the connection.
Solution
Restrict access to this port. If the X11 client/server facility is not used, disable TCP support in X11 entirely (-nolisten tcp).
Risk Factor
Low
[Link] 34/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Plugin Information
Published: 2000/05/12, Modified: 2019/03/05
Plugin Output
[Link] (tcp/6000/x11)
Synopsis
The SSH server is configured to use Cipher Block Chaining.
Description
The SSH server is configured to support Cipher Block Chaining (CBC) encryption. This may allow an attacker to recover the plaintext message from the ciphertext.
Note that this plugin only checks for the options of the SSH server and does not check for vulnerable software versions.
Solution
Contact the vendor or consult product documentation to disable CBC mode cipher encryption, and enable CTR or GCM cipher mode encryption.
Risk Factor
Low
VPR Score
1.4
EPSS Score
0.0307
References
BID 32319
CVE CVE-2008-5161
XREF CERT:958563
XREF CWE:200
Plugin Information
Published: 2013/10/28, Modified: 2023/10/27
Plugin Output
[Link] (tcp/22/ssh)
3des-cbc
aes128-cbc
aes192-cbc
aes256-cbc
blowfish-cbc
cast128-cbc
rijndael-cbc@[Link]
3des-cbc
aes128-cbc
aes192-cbc
aes256-cbc
[Link] 35/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
blowfish-cbc
cast128-cbc
rijndael-cbc@[Link]
Synopsis
The remote SSH server is configured to allow MD5 and 96-bit MAC algorithms.
Description
The remote SSH server is configured to allow either MD5 or 96-bit MAC algorithms, both of which are considered weak.
Note that this plugin only checks for the options of the SSH server, and it does not check for vulnerable software versions.
Solution
Contact the vendor or consult product documentation to disable MD5 and 96-bit MAC algorithms.
Risk Factor
Low
Plugin Information
Published: 2013/11/22, Modified: 2016/12/14
Plugin Output
[Link] (tcp/22/ssh)
hmac-md5
hmac-md5-96
hmac-sha1-96
hmac-md5
hmac-md5-96
hmac-sha1-96
83738 (1) - SSL/TLS EXPORT_DHE <= 512-bit Export Cipher Suites Supported (Logjam) -
Synopsis
The remote host supports a set of weak ciphers.
Description
The remote host supports EXPORT_DHE cipher suites with keys less than or equal to 512 bits. Through cryptanalysis, a third party can find the shared secret in a
short amount of time.
A man-in-the middle attacker may be able to downgrade the session to use EXPORT_DHE cipher suites. Thus, it is recommended to remove support for weak
cipher suites.
See Also
[Link]
Solution
Reconfigure the service to remove support for EXPORT_DHE cipher suites.
Risk Factor
Low
VPR Score
4.5
EPSS Score
0.9403
References
BID 74733
CVE CVE-2015-4000
XREF CEA-ID:CEA-2021-0004
Plugin Information
Published: 2015/05/21, Modified: 2022/12/05
Plugin Output
[Link] (tcp/25/smtp)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
Synopsis
The remote host allows SSL/TLS connections with one or more Diffie-Hellman moduli less than or equal to 1024 bits.
Description
The remote host allows SSL/TLS connections with one or more Diffie-Hellman moduli less than or equal to 1024 bits. Through cryptanalysis, a third party may be
able to find the shared secret in a short amount of time (depending on modulus size and attacker resources). This may allow an attacker to recover the plaintext or
potentially violate the integrity of connections.
See Also
[Link]
Solution
Reconfigure the service to use a unique Diffie-Hellman moduli of 2048 bits or greater.
Risk Factor
Low
VPR Score
[Link] 37/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
4.5
EPSS Score
0.9403
References
BID 74733
CVE CVE-2015-4000
XREF CEA-ID:CEA-2021-0004
Plugin Information
Published: 2015/05/28, Modified: 2024/09/11
Plugin Output
[Link] (tcp/25/smtp)
Synopsis
The remote SSH server is configured to allow weak key exchange algorithms.
Description
The remote SSH server is configured to allow key exchange algorithms which are considered weak.
This is based on the IETF draft document Key Exchange (KEX) Method Updates and Recommendations for Secure Shell (SSH) RFC9142. Section 4 lists guidance on
key exchange algorithms that SHOULD NOT and MUST NOT be enabled. This includes:
diffie-hellman-group-exchange-sha1
diffie-hellman-group1-sha1
gss-gex-sha1-*
gss-group1-sha1-*
gss-group14-sha1-*
rsa1024-sha1
Note that this plugin only checks for the options of the SSH server, and it does not check for vulnerable software versions.
See Also
[Link]
Solution
Contact the vendor or consult product documentation to disable the weak algorithms.
Risk Factor
Low
[Link] 38/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
3.7 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Plugin Information
Published: 2021/10/13, Modified: 2024/03/22
Plugin Output
[Link] (tcp/22/ssh)
diffie-hellman-group-exchange-sha1
diffie-hellman-group1-sha1
Synopsis
It is possible to determine which TCP ports are open.
Description
This plugin is a SYN 'half-open' port scanner. It shall be reasonably quick even against a firewalled target.
Note that SYN scans are less intrusive than TCP (full connect) scans against broken services, but they might cause problems for less robust firewalls and also leave
unclosed connections on the remote target, if the network is loaded.
Solution
Protect your target with an IP filter.
Risk Factor
None
Plugin Information
Published: 2009/02/04, Modified: 2025/02/12
Plugin Output
[Link] (tcp/21/ftp)
[Link] (tcp/22/ssh)
[Link] (tcp/23/telnet)
[Link] (tcp/25/smtp)
[Link] (tcp/53/dns)
[Link] (tcp/80/www)
[Link] (tcp/111/rpc-portmapper)
[Link] 39/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
[Link] (tcp/139/smb)
[Link] (tcp/445/cifs)
[Link] (tcp/512)
[Link] (tcp/513/rlogin)
[Link] (tcp/514/rsh)
[Link] (tcp/1099/rmi_registry)
[Link] (tcp/1524/wild_shell)
[Link] (tcp/2049/rpc-nfs)
[Link] (tcp/2121/ftp)
[Link] (tcp/3306/mysql)
[Link] (tcp/3632)
[Link] (tcp/5432/postgresql)
[Link] (tcp/5900/vnc)
[Link] (tcp/6000/x11)
[Link] (tcp/6667/irc)
[Link] 40/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
[Link] (tcp/8009/ajp13)
[Link] (tcp/8180/www)
[Link] (tcp/8787)
[Link] (tcp/41795/rpc-status)
Synopsis
An ONC RPC service is running on the remote host.
Description
By sending a DUMP request to the portmapper, it was possible to enumerate the ONC RPC services running on the remote port. Using this information, it is
possible to connect and bind to each service by sending an RPC request to the remote port.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/08/24, Modified: 2011/05/24
Plugin Output
[Link] (tcp/111/rpc-portmapper)
[Link] (udp/111/rpc-portmapper)
[Link] (tcp/2049/rpc-nfs)
[Link] (udp/2049/rpc-nfs)
[Link] (tcp/41795/rpc-status)
[Link] 41/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
[Link] (tcp/44151/rpc-mountd)
[Link] (udp/50457/rpc-mountd)
[Link] (udp/54376/rpc-nlockmgr)
[Link] (tcp/55165/rpc-nlockmgr)
[Link] (udp/56302/rpc-status)
Synopsis
The remote service could be identified.
Description
Nessus was able to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/08/19, Modified: 2024/03/26
Plugin Output
[Link] (tcp/21/ftp)
[Link] (tcp/23/telnet)
[Link] 42/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
[Link] (tcp/25/smtp)
[Link] (tcp/80/www)
[Link] (tcp/1524/wild_shell)
[Link] (tcp/2121/ftp)
[Link] (tcp/5900/vnc)
[Link] (tcp/8180/www)
Synopsis
An FTP server is listening on a remote port.
Description
It is possible to obtain the banner of the remote FTP server by connecting to a remote port.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0030
XREF IAVT:0001-T-0943
Plugin Information
Published: 1999/10/12, Modified: 2023/08/17
Plugin Output
[Link] (tcp/21/ftp)
[Link] (tcp/2121/ftp)
[Link] 43/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Synopsis
A web server is running on the remote host.
Description
This plugin attempts to determine the type and the version of the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0931
Plugin Information
Published: 2000/01/04, Modified: 2020/10/30
Plugin Output
[Link] (tcp/80/www)
[Link] (tcp/8180/www)
Apache-Coyote/1.1
Synopsis
This plugin displays the SSL certificate.
Description
This plugin connects to every SSL-related port and attempts to extract and dump the X.509 certificate.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2008/05/19, Modified: 2021/02/03
Plugin Output
[Link] (tcp/25/smtp)
Subject Name:
Country: XX
State/Province: There is no such thing outside US
Locality: Everywhere
Organization: OCOSA
Organization Unit: Office for Complication of Otherwise Simple Affairs
Common Name: [Link]
Email Address: root@[Link]
Issuer Name:
Country: XX
State/Province: There is no such thing outside US
Locality: Everywhere
Organization: OCOSA
Organization Unit: Office for Complication of Otherwise Simple Affairs
Common Name: [Link]
Email Address: root@[Link]
[Link] 44/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Serial Number: 00 FA F9 3A 4C 7F B6 B9 CC
Version: 1
Fingerprints :
SHA-256 Fingerprint: E7 A7 FA 0D 63 E4 57 C7 C4 A5 9B 38 B7 08 49 C6 A7 0B DA 6F
83 0C 7A F1 E3 2D EE 43 6D E8 13 CC
SHA-1 Fingerprint: ED 09 30 88 70 66 03 BF D5 DC 23 73 99 B4 98 DA 2D 4D 31 C6
MD5 Fingerprint: DC D9 AD 90 6C 8F 2F 73 74 AF 38 3B 25 40 88 28
PEM certificate :
-----BEGIN CERTIFICATE-----
MIIDWzCCAsQCCQD6+TpMf7a5zDANBgkqhkiG9w0BAQUFADCB8TELMAkGA1UEBhMCWFgxKjAoBgNVBAgTIVRoZXJlIGlzIG5vIHN1Y2ggdGhpbmcgb3V0c2lkZSBVUzETMBEG
A1UEBxMKRXZlcnl3aGVyZTEOMAwGA1UEChMFT0NPU0ExPDA6BgNVBAsTM09mZmljZSBmb3IgQ29tcGxpY2F0aW9uIG9mIE90aGVyd2lzZSBTaW1wbGUgQWZmYWlyczEjMCEG
A1UEAxMadWJ1bnR1ODA0LWJhc2UubG9jYWxkb21haW4xLjAsBgkqhkiG9w0BCQEWH3Jvb3RAdWJ1bnR1ODA0LWJhc2UubG9jYWxkb21haW4wHhcNMTAwMzE3MTQwNzQ1WhcN
MTAwNDE2MTQwNzQ1WjCB8TELMAkGA1UEBhMCWFgxKjAoBgNVBAgTIVRoZXJlIGlzIG5vIHN1Y2ggdGhpbmcgb3V0c2lkZSBVUzETMBEGA1UEBxMKRXZlcnl3aGVyZTEOMAwG
A1UEChMFT0NPU0ExPDA6BgNVBAsTM09mZmljZSBmb3IgQ29tcGxpY2F0aW9uIG9mIE90aGVyd2lzZSBTaW1wbGUgQWZmYWlyczEjMCEGA1UEAxMadWJ1bnR1ODA0LWJhc2Uu
bG9jYWxkb21haW4xLjAsBgkqhkiG9w0BCQEWH3Jvb3RAdWJ1bnR1ODA0LWJhc2UubG9jYWxkb21haW4wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANa0EzYzmpVxexve
fIN12nGxPKl//q1kG3fpT66+ytT4y++uu0N5JHP/POWeO238yLGs+kxNXptMmVQL16hKULqp3h0f9ORrAqP0a0XNTK+NiWIzj2W7NmGfxCxzwU4uoKgUTphwRmG70bkx34yZ
7nVreTxAoK6XAJCd3JkNM6S1AgMBAAEwDQYJKoZIhvcNAQEFBQADgYEAkqS0uBRVYyVRSgvDKiLPOvgXagzPZqqnZS9Ibc3jPlyfd2zURFQfHoRPjtSN3awtiAkhqNpWLKkF
PEloNRl1DNpTI4iIGS10JsEiZe4RaINqU0qcJ8ugtOmNKQyyPBhcZ8xTph4w0Komex6uQLkpAWwuvKIZlHwVbo0wOPbKLnU=
-----END CERTIFICATE-----
[Link] (tcp/5432/postgresql)
Subject Name:
Country: XX
State/Province: There is no such thing outside US
Locality: Everywhere
Organization: OCOSA
Organization Unit: Office for Complication of Otherwise Simple Affairs
Common Name: [Link]
Email Address: root@[Link]
Issuer Name:
Country: XX
State/Province: There is no such thing outside US
Locality: Everywhere
Organization: OCOSA
Organization Unit: Office for Complication of Otherwise Simple Affairs
Common Name: [Link]
Email Address: root@[Link]
Serial Number: 00 FA F9 3A 4C 7F B6 B9 CC
Version: 1
[Link] 45/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Fingerprints :
SHA-256 Fingerprint: E7 A7 FA 0D 63 E4 57 C7 C4 A5 9B 38 B7 08 49 C6 A7 0B DA 6F
83 0C 7A F1 E3 2D EE 43 6D E8 13 CC
SHA-1 Fingerprint: ED 09 30 88 70 66 03 BF D5 DC 23 73 99 B4 98 DA 2D 4D 31 C6
MD5 Fingerprint: DC D9 AD 90 6C 8F 2F 73 74 AF 38 3B 25 40 88 28
PEM certificate :
-----BEGIN CERTIFICATE-----
MIIDWzCCAsQCCQD6+TpMf7a5zDANBgkqhkiG9w0BAQUFADCB8TELMAkGA1UEBhMCWFgxKjAoBgNVBAgTIVRoZXJlIGlzIG5vIHN1Y2ggdGhpbmcgb3V0c2lkZSBVUzETMBEG
A1UEBxMKRXZlcnl3aGVyZTEOMAwGA1UEChMFT0NPU0ExPDA6BgNVBAsTM09mZmljZSBmb3IgQ29tcGxpY2F0aW9uIG9mIE90aGVyd2lzZSBTaW1wbGUgQWZmYWlyczEjMCEG
A1UEAxMadWJ1bnR1ODA0LWJhc2UubG9jYWxkb21haW4xLjAsBgkqhkiG9w0BCQEWH3Jvb3RAdWJ1bnR1ODA0LWJhc2UubG9jYWxkb21haW4wHhcNMTAwMzE3MTQwNzQ1WhcN
MTAwNDE2MTQwNzQ1WjCB8TELMAkGA1UEBhMCWFgxKjAoBgNVBAgTIVRoZXJlIGlzIG5vIHN1Y2ggdGhpbmcgb3V0c2lkZSBVUzETMBEGA1UEBxMKRXZlcnl3aGVyZTEOMAwG
A1UEChMFT0NPU0ExPDA6BgNVBAsTM09mZmljZSBmb3IgQ29tcGxpY2F0aW9uIG9mIE90aGVyd2lzZSBTaW1wbGUgQWZmYWlyczEjMCEGA1UEAxMadWJ1bnR1ODA0LWJhc2Uu
bG9jYWxkb21haW4xLjAsBgkqhkiG9w0BCQEWH3Jvb3RAdWJ1bnR1ODA0LWJhc2UubG9jYWxkb21haW4wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANa0EzYzmpVxexve
fIN12nGxPKl//q1kG3fpT66+ytT4y++uu0N5JHP/POWeO238yLGs+kxNXptMmVQL16hKULqp3h0f9ORrAqP0a0XNTK+NiWIzj2W7NmGfxCxzwU4uoKgUTphwRmG70bkx34yZ
7nVreTxAoK6XAJCd3JkNM6S1AgMBAAEwDQYJKoZIhvcNAQEFBQADgYEAkqS0uBRVYyVRSgvDKiLPOvgXagzPZqqnZS9Ibc3jPlyfd2zURFQfHoRPjtSN3awtiAkhqNpWLKkF
PEloNRl1DNpTI4iIGS10JsEiZe4RaINqU0qcJ8ugtOmNKQyyPBhcZ8xTph4w0Komex6uQLkpAWwuvKIZlHwVbo0wOPbKLnU=
-----END CERTIFICATE-----
Synopsis
A DNS server is listening on the remote host.
Description
The remote service is a Domain Name System (DNS) server, which provides a mapping between hostnames and IP addresses.
See Also
[Link]
Solution
Disable this service if it is not needed or restrict access to internal hosts only if the service is available externally.
Risk Factor
None
Plugin Information
Published: 2003/02/13, Modified: 2017/05/16
Plugin Output
[Link] (tcp/53/dns)
[Link] (udp/53/dns)
11011 (2) - Microsoft Windows SMB Service Detection -
Synopsis
A file / print sharing service is listening on the remote host.
Description
The remote service understands the CIFS (Common Internet File System) or Server Message Block (SMB) protocol, used to provide shared access to files, printers,
etc between nodes on a network.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/06/05, Modified: 2021/02/11
Plugin Output
[Link] (tcp/139/smb)
[Link] 46/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
[Link] (tcp/445/cifs)
Synopsis
The remote service could be identified.
Description
It was possible to identify the remote service by its banner or by looking at the error message it sends when it receives an HTTP request.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0935
Plugin Information
Published: 2005/04/06, Modified: 2021/10/27
Plugin Output
[Link] (tcp/3306/mysql)
A MySQL server seems to be running on this port but the Nessus scanner
IP has been blacklisted. Run 'mysqladmin flush-hosts' if you want
complete tests.
[Link] (tcp/6667/irc)
Synopsis
The remote service encrypts communications using SSL.
Description
This plugin detects which SSL ciphers are supported by the remote service for encrypting communications.
See Also
[Link]
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/06/05, Modified: 2024/09/11
Plugin Output
[Link] (tcp/25/smtp)
[Link] 47/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
[Link] 48/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
RC4-MD5 0x01, 0x00, 0x80 RSA RSA RC4(128) MD5
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
Note that this service does not encrypt traffic by default but does
support upgrading to an encrypted connection using STARTTLS.
[Link] (tcp/5432/postgresql)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
Note that this service does not encrypt traffic by default but does
support upgrading to an encrypted connection using STARTTLS.
Synopsis
An RMI registry is listening on the remote host.
Description
The remote host is running an RMI registry, which acts as a bootstrap naming service for registering and retrieving remote objects with simple names in the Java
Remote Method Invocation (RMI) system.
See Also
[Link]
[Link]
Solution
n/a
[Link] 49/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Risk Factor
None
Plugin Information
Published: 2006/08/16, Modified: 2025/03/19
Plugin Output
[Link] (tcp/1099/rmi_registry)
[Link] (tcp/1099/rmi_registry)
Synopsis
Some information about the remote HTTP configuration can be extracted.
Description
This test gives some information about the remote HTTP protocol - the version used, whether HTTP Keep-Alive is enabled, etc...
This test is informational only and does not denote any security problem.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/01/30, Modified: 2024/02/26
Plugin Output
[Link] (tcp/80/www)
Response Body :
<html><head><title>Metasploitable2 - Linux</title></head><body>
<pre>
_ _ _ _ _ _ ____
_ __ ___ ___| |_ __ _ ___ _ __ | | ___ (_) |_ __ _| |__ | | ___|___ \
| '_ ` _ \ / _ \ __/ _` / __| '_ \| |/ _ \| | __/ _` | '_ \| |/ _ \ __) |
| | | | | | __/ || (_| \__ \ |_) | | (_) | | || (_| | |_) | | __// __/
|_| |_| |_|\___|\__\__,_|___/ .__/|_|\___/|_|\__\__,_|_.__/|_|\___|_____|
|_|
Contact: msfdev[at][Link]
</pre>
<ul>
<li><a href="/twiki/">TWiki</a></li>
<li><a href="/phpMyAdmin/">phpMyAdmin</a></li>
<li><a href="/mutillidae/">Mutillidae</a></li>
[Link] 50/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
<li><a href="/dvwa/">DVWA</a></li>
<li><a href="/dav/">WebDAV</a></li>
</ul>
</body>
</html>
[Link] (tcp/8180/www)
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 05 May 2025 10:05:34 GMT
Connection: close
Response Body :
<!--
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License. You may obtain a copy of the License at
[Link]
img {
border: none;
}
a:link, a:visited {
color: blue
}
th {
font-family: Verdana, "Times New Roman", Times, serif;
font-size: 110%;
font-weight: normal;
font-style: italic;
background: #D2A41C;
text-align: left;
}
td {
color: #000000;
font-family: Arial, Helvetica, sans-serif;
}
[Link] {
background: #FFDC75;
}
.center {
text-align: center;
}
.code {
color: #000000;
font-family: "Courier New", Courier, monospace;
font-size: 110%;
margin-left: 2.5em;
}
#banner {
[Link] 51/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
margin-bottom: 12px;
}
p#congrats {
margin-top: 0;
font-weight: bold;
text-align: center;
}
p#footer {
text-align: right;
font-size: 80%;
}
/*]]>*/
</style>
</head>
<body>
<table>
<tr>
<br />
<table width="100%" border="1" cellspacing="0" cellpadding="3">
<tr>
<th>Documentation</th>
</tr>
<tr>
<td class="menu">
<a href="[Link]">Release Notes</a><br/>
<a href="tomcat-docs/[Link]">Change Log</a><br/>
<a href="tomcat-docs">Tomcat Documentation</a><br/>
</td>
</tr>
</table>
<br/>
<table width="100%" border="1" cellspacing="0" cellpadding="3">
<tr>
<th>Tomcat Online</th>
</tr>
<tr>
<td class="menu">
<a href="[Link]
<a href="[Link]
<a href="[Link]
<a href="[Link]
bug_status=UNCONFIRMED&bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&bug_status=RESOLVED&resolution=LAT
ER&resolution=REMIND&resolution=---&bugidtype=include&product=Tomcat+5&cmdtype=doit&order=Importance">Open
Bugs</a><br/>
<a href="[Link]
<a href="[Link]
<a href="irc://[Link]/#tomcat">IRC</a><br/>
</td>
</tr>
</table>
<br/>
<table width="100%" border="1" cellspacing="0" cellpadding="3">
<tr>
<th>Examples</th>
</tr>
<tr>
<td class="menu">
[Link] 52/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
<a href="jsp-examples/">JSP Examples</a><br/>
<a href="servlets-examples/">Servlet Examples</a><br/>
<a href="webdav/">WebDAV capabilities</a><br/>
</td>
</tr>
</table>
<br/>
<table width="100%" border="1" cellspacing="0" cellpadding="3">
<tr>
<th>Miscellaneous</th>
</tr>
<tr>
<td class="menu">
<a href="[Link]
<a href="[Link]
</td>
</tr>
</table>
</td>
<td style="width:20px"> </td>
<p>As you may have guessed by now, this is the default Tomcat home page. It can be found on the local filesystem at:</p>
<p class="code">$CATALINA_HOME/webapps/ROOT/[Link]</p>
<p>where "$CATALINA_HOME" is the root of the Tomcat installation directory. If you're seeing this page, and you don't think you
should be, then either you're either a user who has arrived at new installation of Tomcat, or you're an administrator who hasn't got
his/her setup quite right. Providing the latter is the case, please refer to the <a href="tomcat-docs">Tomcat Documentation</a> for
more detailed setup and administration information than is found in the INSTALL file.</p>
<p><b>NOTE:</b> This page is precompiled. If you change it, this page will not change since
it was compiled into a servlet at build time.
(See <tt>$CATALINA_HOME/webapps/ROOT/WEB-INF/[Link]</tt> as to how it was mapped.)
</p>
<p>Included with this release are a host of sample Servlets and JSPs (with associated source code), extensive documentation
(including the Servlet 2.4 and JSP 2.0 API JavaDoc), and an introductory guide to developing web applications.</p>
<p>Tomcat mailing lists are available at the Tomcat project web site:</p>
<ul>
<li><b><a href="[Link] for general questions related to configuring and
using Tomcat</li>
<li><b><a href="[Link] for developers working on Tomcat</li>
</ul>
</tr>
</table>
</body>
</html>
Synopsis
The 'commonName' (CN) attribute in the SSL certificate does not match the hostname.
Description
The service running on the remote host presents an SSL certificate for which the 'commonName' (CN) attribute does not match the hostname on which the service
listens.
Solution
If the machine has several names, make sure that users connect to the service through the DNS hostname that matches the common name in the certificate.
Risk Factor
None
Plugin Information
[Link] 53/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Published: 2010/04/03, Modified: 2021/03/09
Plugin Output
[Link] (tcp/25/smtp)
metasploitable
[Link]
[Link] (tcp/5432/postgresql)
metasploitable
[Link]
Synopsis
The remote service appears to use OpenSSL to encrypt traffic.
Description
Based on its response to a TLS request with a specially crafted server name extension, it seems that the remote service is using the OpenSSL library to encrypt
traffic.
Note that this plugin can only detect OpenSSL implementations that have enabled support for TLS extensions (RFC 4366).
See Also
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/11/30, Modified: 2020/06/12
Plugin Output
[Link] (tcp/25/smtp)
[Link] (tcp/5432/postgresql)
56984 (2) - SSL / TLS Versions Supported -
Synopsis
The remote service encrypts communications.
Description
This plugin detects which SSL and TLS versions are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/01, Modified: 2023/07/10
Plugin Output
[Link] 54/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
[Link] (tcp/25/smtp)
[Link] (tcp/5432/postgresql)
Synopsis
The remote service supports the use of SSL Perfect Forward Secrecy ciphers, which maintain confidentiality even if the key is stolen.
Description
The remote host supports the use of SSL ciphers that offer Perfect Forward Secrecy (PFS) encryption. These cipher suites ensure that recorded SSL traffic cannot
be broken at a future date if the server's private key is compromised.
See Also
[Link]
[Link]
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/12/07, Modified: 2021/03/09
Plugin Output
[Link] (tcp/25/smtp)
Here is the list of SSL PFS ciphers supported by the remote server :
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
[Link] (tcp/5432/postgresql)
Here is the list of SSL PFS ciphers supported by the remote server :
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
Synopsis
The remote service supports one or more compression methods for SSL connections.
Description
This script detects which compression methods are supported by the remote service for SSL connections.
See Also
[Link]
[Link]
[Link]
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2012/10/16, Modified: 2022/04/11
Plugin Output
[Link] (tcp/25/smtp)
DEFLATE (0x01)
[Link] (tcp/5432/postgresql)
DEFLATE (0x01)
Synopsis
The remote service supports the use of SSL Cipher Block Chaining ciphers, which combine previous blocks with subsequent ones.
Description
The remote host supports the use of SSL ciphers that operate in Cipher Block Chaining (CBC) mode. These cipher suites offer additional security over Electronic
Codebook (ECB) mode, but have the potential to leak information if used improperly.
See Also
[Link]
[Link]
[Link]
Solution
[Link] 56/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/22, Modified: 2021/02/03
Plugin Output
[Link] (tcp/25/smtp)
Here is the list of SSL CBC ciphers supported by the remote server :
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
[Link] (tcp/5432/postgresql)
Here is the list of SSL CBC ciphers supported by the remote server :
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
[Link] 57/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Synopsis
The remote host advertises discouraged SSL/TLS ciphers.
Description
The remote host has open SSL/TLS ports which advertise discouraged cipher suites. It is recommended to only enable support for the following cipher suites:
TLSv1.3:
- 0x13,0x01 TLS13_AES_128_GCM_SHA256
- 0x13,0x02 TLS13_AES_256_GCM_SHA384
- 0x13,0x03 TLS13_CHACHA20_POLY1305_SHA256
TLSv1.2:
- 0xC0,0x2B ECDHE-ECDSA-AES128-GCM-SHA256
- 0xC0,0x2F ECDHE-RSA-AES128-GCM-SHA256
- 0xC0,0x2C ECDHE-ECDSA-AES256-GCM-SHA384
- 0xC0,0x30 ECDHE-RSA-AES256-GCM-SHA384
- 0xCC,0xA9 ECDHE-ECDSA-CHACHA20-POLY1305
- 0xCC,0xA8 ECDHE-RSA-CHACHA20-POLY1305
This is the recommended configuration for the vast majority of services, as it is highly secure and compatible with nearly every client released in the last five (or
more) years.
See Also
[Link]
[Link]
Solution
Only enable support for recommened cipher suites.
Risk Factor
None
Plugin Information
Published: 2022/01/20, Modified: 2024/02/12
Plugin Output
[Link] (tcp/25/smtp)
The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
[Link] 58/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
The fields above are :
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
[Link] (tcp/5432/postgresql)
The remote host has listening SSL/TLS ports which advertise the discouraged cipher suites outlined below:
Medium Strength Ciphers (> 64-bit and < 112-bit key, or 3DES)
{Tenable ciphername}
{Cipher ID code}
Kex={key exchange}
Auth={authentication}
Encrypt={symmetric encryption method}
MAC={message authentication code}
{export flag}
10028 (1) - DNS Server BIND version Directive Remote Version Detection -
Synopsis
It is possible to obtain the version number of the remote DNS server.
Description
The remote host is running BIND or another DNS server that reports its version number when it receives a special request for the text '[Link]' in the domain
'chaos'.
This version is not necessarily accurate and could even be forged, as some DNS servers send the information based on a configuration file.
Solution
It is possible to hide the version number of BIND by using the 'version' directive in the 'options' section in [Link].
Risk Factor
None
References
XREF IAVT:0001-T-0583
Plugin Information
Published: 1999/10/12, Modified: 2022/10/12
Plugin Output
[Link] (udp/53/dns)
Version : 9.4.2
Synopsis
It was possible to obtain the network name of the remote host.
Description
[Link] 59/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
The remote host is listening on UDP port 137 or TCP port 445, and replies to NetBIOS nbtscan or SMB requests.
Note that this plugin gathers information to be used in other plugins, but does not itself generate a report.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2021/02/10
Plugin Output
[Link] (udp/137/netbios-ns)
This SMB server seems to be a Samba server - its MAC address is NULL.
Synopsis
An ONC RPC portmapper is running on the remote host.
Description
The RPC portmapper is running on this port.
The portmapper allows someone to get the port number of each RPC service running on the remote host by sending either multiple lookup requests or a DUMP
request.
Solution
n/a
Risk Factor
None
References
CVE CVE-1999-0632
Plugin Information
Published: 1999/08/19, Modified: 2019/10/04
Plugin Output
[Link] (udp/111/rpc-portmapper)
10263 (1) - SMTP Server Detection -
Synopsis
An SMTP server is listening on the remote port.
Description
The remote host is running a mail (SMTP) server on this port.
Since SMTP servers are the targets of spammers, it is recommended you disable it if you do not use it.
Solution
[Link] 60/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Disable this service if you do not use it, or filter incoming traffic to this port.
Risk Factor
None
References
XREF IAVT:0001-T-0932
Plugin Information
Published: 1999/10/12, Modified: 2020/09/22
Plugin Output
[Link] (tcp/25/smtp)
Synopsis
An SSH server is listening on this port.
Description
It is possible to obtain information about the remote SSH server by sending an empty authentication request.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0933
Plugin Information
Published: 1999/10/12, Modified: 2024/07/24
Plugin Output
[Link] (tcp/22/ssh)
Synopsis
A Telnet server is listening on the remote port.
Description
The remote host is running a Telnet server, a remote terminal server.
Solution
Disable this service if you do not use it.
Risk Factor
None
Plugin Information
Published: 1999/10/12, Modified: 2020/06/12
Plugin Output
[Link] (tcp/23/telnet)
[Link] 61/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Contact: msfdev[at][Link]
metasploitable login:
------------------------------ snip ------------------------------
Synopsis
It was possible to obtain traceroute information.
Description
Makes a traceroute to the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 1999/11/27, Modified: 2023/12/04
Plugin Output
[Link] (udp/0)
Hop Count: 1
Synopsis
The remote host is running a remote display software (VNC).
Description
The remote host is running VNC (Virtual Network Computing), which uses the RFB (Remote Framebuffer) protocol to provide remote access to graphical user
interfaces and thus permits a console on the remote host to be displayed on another.
See Also
[Link]
Solution
Make sure use of this software is done in accordance with your organization's security policy and filter incoming traffic to this port.
Risk Factor
None
Plugin Information
Published: 2000/03/07, Modified: 2017/06/12
Plugin Output
[Link] (tcp/5900/vnc)
[Link] 62/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
3.3
10397 (1) - Microsoft Windows SMB LanMan Pipe Server Listing Disclosure -
Synopsis
It is possible to obtain network information.
Description
It was possible to obtain the browse list of the remote Windows system by sending a request to the LANMAN pipe. The browse list is the list of the nearest
Windows systems of the remote host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2000/05/09, Modified: 2022/02/01
Plugin Output
[Link] (tcp/445/cifs)
METASPLOITABLE ( os : 0.0 )
Synopsis
The remote NFS server exports a list of shares.
Description
This plugin retrieves the list of NFS exported shares.
See Also
[Link]
Solution
Ensure each share is intended to be exported.
Risk Factor
None
Plugin Information
Published: 2000/06/07, Modified: 2019/10/04
Plugin Output
[Link] (tcp/2049/rpc-nfs)
/ *
10785 (1) - Microsoft Windows SMB NativeLanManager Remote System Information Disclosure -
Synopsis
It was possible to obtain information about the remote operating system.
Description
[Link] 63/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Nessus was able to obtain the remote operating system name and version (Windows and/or Samba) by sending an authentication request to port 139 or 445. Note
that this plugin requires SMB to be enabled on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2001/10/17, Modified: 2021/09/20
Plugin Output
[Link] (tcp/445/cifs)
Synopsis
A SSH server is running on the remote host.
Description
This plugin determines the versions of the SSH protocol supported by the remote SSH daemon.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/03/06, Modified: 2024/07/24
Plugin Output
[Link] (tcp/22/ssh)
- 1.99
- 2.0
Synopsis
The remote service could be identified.
Description
It was possible to identify the remote service by its banner or by looking at the error message it sends when it receives a 'HELP'
request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/11/18, Modified: 2024/11/19
Plugin Output
[Link] (tcp/22/ssh)
[Link] 64/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Synopsis
There is an unknown service running on the remote host.
Description
Nessus was unable to identify a service on the remote host even though it returned a banner of some type.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/11/18, Modified: 2022/07/26
Plugin Output
[Link] (tcp/8787)
If you know what this service is and think the banner could be used to
identify it, please send a description of the service along with the
following output to svc-signatures@[Link] :
Port : 8787
Type : get_http
Banner :
0x0000: 00 00 00 03 04 08 46 00 00 03 A1 04 08 6F 3A 16 ......F......o:.
0x0010: 44 52 62 3A 3A 44 52 62 43 6F 6E 6E 45 72 72 6F DRb::DRbConnErro
0x0020: 72 07 3A 07 62 74 5B 17 22 2F 2F 75 73 72 2F 6C r.:.bt[."//usr/l
0x0030: 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F ib/ruby/1.8/drb/
0x0040: 64 72 62 2E 72 62 3A 35 37 33 3A 69 6E 20 60 6C [Link]:in `l
0x0050: 6F 61 64 27 22 37 2F 75 73 72 2F 6C 69 62 2F 72 oad'"7/usr/lib/r
0x0060: 75 62 79 2F 31 2E 38 2F 64 72 62 2F 64 72 62 2E uby/1.8/drb/drb.
0x0070: 72 62 3A 36 31 32 3A 69 6E 20 60 72 65 63 76 5F rb:612:in `recv_
0x0080: 72 65 71 75 65 73 74 27 22 37 2F 75 73 72 2F 6C request'"7/usr/l
0x0090: 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F ib/ruby/1.8/drb/
0x00A0: 64 72 62 2E 72 62 3A 39 31 31 3A 69 6E 20 60 72 [Link]:in `r
0x00B0: 65 63 76 5F 72 65 71 75 65 73 74 27 22 3C 2F 75 ecv_request'"</u
0x00C0: 73 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F sr/lib/ruby/1.8/
0x00D0: 64 72 62 2F 64 72 62 2E 72 62 3A 31 35 33 30 3A drb/[Link]:
0x00E0: 69 6E 20 60 69 6E 69 74 5F 77 69 74 68 5F 63 6C in `init_with_cl
0x00F0: 69 65 6E 74 27 22 39 2F 75 73 72 2F 6C 69 62 2F ient'"9/usr/lib/
0x0100: 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F 64 72 62 ruby/1.8/drb/drb
0x0110: 2E 72 62 3A 31 35 34 32 3A 69 6E 20 60 73 65 74 .rb:1542:in `set
0x0120: 75 70 5F 6D 65 73 73 61 67 65 27 22 33 2F 75 73 up_message'"3/us
0x0130: 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 r/lib/ruby/1.8/d
0x0140: 72 62 2F 64 72 62 2E 72 62 3A 31 34 39 34 3A 69 rb/[Link]:i
0x0150: 6E 20 60 70 65 72 66 6F 72 6D 27 22 35 2F 75 73 n `perform'"5/us
0x0160: 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 r/lib/ruby/1.8/d
0x0170: 72 62 2F 64 72 62 2E 72 62 3A 31 35 38 39 3A 69 rb/[Link]:i
0x0180: 6E 20 60 6D 61 69 6E 5F 6C 6F 6F 70 27 22 30 2F n `main_loop'"0/
0x0190: 75 73 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 usr/lib/ruby/1.8
0x01A0: 2F 64 72 62 2F 64 72 62 2E 72 62 3A 31 35 38 35 /drb/[Link]
0x01B0: 3A 69 6E 20 60 6C 6F 6F 70 27 22 35 2F 75 73 72 :in `loop'"5/usr
0x01C0: 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 72 /lib/ruby/1.8/dr
0x01D0: 62 2F 64 72 62 2E 72 62 3A 31 35 38 35 3A 69 6E b/[Link]:in
0x01E0: 20 60 6D 61 69 6E 5F 6C 6F 6F 70 27 22 31 2F 75 `main_loop'"1/u
0x01F0: 73 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F sr/lib/ruby/1.8/
0x0200: 64 72 62 2F 64 72 62 2E 72 62 3A 31 35 38 31 3A drb/[Link]:
0x0210: 69 6E 20 60 73 74 61 72 74 27 22 35 2F 75 73 72 in `start'"5/usr
0x0220: 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 72 /lib/ruby/1.8/dr
0x0230: 62 2F 64 72 62 2E 72 62 3A 31 35 38 31 3A 69 6E b/[Link]:in
0x0240: 20 60 6D 61 69 6E 5F 6C 6F 6F 70 27 22 2F 2F 75 `main_loop'"//u
0x0250: 73 72 2F 6C 69 62 2F 72 75 62 79 2F 31 2E 38 2F sr/lib/ruby/1.8/
0x0260: 64 72 62 2F 64 72 62 2E 72 62 3A 31 34 33 30 3A drb/[Link]:
0x0270: 69 6E 20 60 72 75 6E 27 22 31 2F 75 73 72 2F 6C in `run'"1/usr/l
0x0280: 69 62 2F 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F ib/ruby/1.8/drb/
0x0290: 64 72 62 2E 72 62 3A 31 34 32 37 3A 69 6E 20 60 [Link]:in `
0x02A0: 73 74 61 72 74 27 22 2F 2F 75 73 72 2F 6C 69 62 start'"//usr/lib
0x02B0: 2F 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F 64 72 /ruby/1.8/drb/dr
0x02C0: 62 2E 72 62 3A 31 34 32 37 3A 69 6E 20 60 72 75 [Link]:in `ru
0x02D0: 6E 27 22 36 2F 75 73 72 2F 6C 69 62 2F 72 75 62 n'"6/usr/lib/rub
0x02E0: 79 2F 31 2E 38 2F 64 72 62 2F 64 72 62 2E 72 62 y/1.8/drb/[Link]
0x02F0: 3A 31 33 34 37 3A 69 6E 20 60 69 6E 69 74 69 61 :1347:in `initia
0x0300: 6C 69 7A 65 27 22 2F 2F 75 73 72 2F 6C 69 62 2F lize'"//usr/lib/
0x0310: 72 75 62 79 2F 31 2E 38 2F 64 72 62 2F 64 72 62 ruby/1.8/drb/drb
0x0320: 2E 72 62 3A 31 36 32 37 3A 69 6E 20 60 6E 65 77 .rb:1627:in `new
0x0330: 27 22 39 2F 75 73 72 2F 6C 69 62 2F 72 75 62 79 '"9/usr/lib/ruby
0x0340: 2F 31 2E 38 2F 64 72 62 2F 64 72 62 2E 72 62 3A /1.8/drb/[Link]:
0x0350: 31 36 32 37 3A 69 6E 20 60 73 74 61 72 74 5F 73 1627:in `start_s
0x0360: 65 72 76 69 63 65 27 22 25 2F 75 73 72 2F 73 62 ervice'"%/usr/sb
0x0370: 69 6E 2F 64 72 75 62 79 5F 74 69 6D 65 73 65 72 in/druby_timeser
0x0380: 76 65 72 2E 72 62 3A 31 32 3A 09 6D 65 73 67 22 [Link]:.mesg"
0x0390: 20 74 6F 6F 20 6C 61 72 67 65 20 70 61 63 6B 65 too large packe
0x03A0: 74 20 31 31 39 35 37 32 35 38 35 36 t 1195725856
[Link] 65/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Synopsis
The remote host is an IRC server.
Description
This plugin determines the version of the IRC daemon.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2002/11/19, Modified: 2016/01/08
Plugin Output
[Link] (tcp/6667/irc)
Synopsis
The remote web server is not configured or is improperly configured.
Description
The remote web server uses its default welcome page. Therefore, it's probable that this server is not used at all or is serving content that is meant to be hidden.
Solution
Disable this service if you do not use it.
Risk Factor
None
Plugin Information
Published: 2003/03/20, Modified: 2018/08/15
Plugin Output
[Link] (tcp/8180/www)
Synopsis
The remote server is running with WebDAV enabled.
Description
WebDAV is an industry standard extension to the HTTP specification.
It adds a capability for authorized users to remotely add and manage the content of a web server.
Solution
[Link]
Risk Factor
None
Plugin Information
[Link] 66/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Published: 2003/03/20, Modified: 2011/03/14
Plugin Output
[Link] (tcp/80/www)
11819 (1) - TFTP Daemon Detection -
Synopsis
A TFTP server is listening on the remote port.
Description
The remote host is running a TFTP (Trivial File Transfer Protocol) daemon. TFTP is often used by routers and diskless hosts to retrieve their configuration. It can
also be used by worms to propagate.
Solution
Disable this service if you do not use it.
Risk Factor
None
Plugin Information
Published: 2003/08/13, Modified: 2022/12/28
Plugin Output
[Link] (udp/69/tftp)
11936 (1) - OS Identification -
Synopsis
It is possible to guess the remote operating system.
Description
Using a combination of remote probes (e.g., TCP/IP, SMB, HTTP, NTP, SNMP, etc.), it is possible to guess the name of the remote operating system in use. It is also
possible sometimes to guess the version of the operating system.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2003/12/09, Modified: 2025/03/31
Plugin Output
[Link] (tcp/0)
Not all fingerprints could give a match. If you think that these
signatures would help us improve OS fingerprinting, please submit
them by visiting [Link]
SSH:SSH-2.0-OpenSSH_4.7p1 Debian-8ubuntu1
SinFP:
P1:B10113:F0x12:W5840:O0204ffff:M1460:
P2:B10113:F0x12:W5792:O0204ffff0402080affffffff4445414401030307:M1460:
P3:B00000:F0x00:W0:O0:M0
P4:191004_7_p=2121
SMTP:!:220 [Link] ESMTP Postfix (Ubuntu)
SSLcert:!:i/CN:[Link]/O:OCOSAi/OU:Office for Complication of Otherwise Simple Affairss/CN:ubuntu804-
[Link]/O:OCOSAs/OU:Office for Complication of Otherwise Simple Affairs
ed093088706603bfd5dc237399b498da2d4d31c6
i/CN:[Link]/O:OCOSAi/OU:Office for Complication of Otherwise Simple Affairss/CN:ubuntu804-
[Link]/O:OCOSAs/OU:Office for Complication of Otherwise Simple Affairs
ed093088706603bfd5dc237399b498da2d4d31c6
The remote host is running Linux Kernel 2.6 on Ubuntu 8.04 (gutsy)
[Link] 67/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Synopsis
The name of the Linux distribution running on the remote host was found in the banner of the web server.
Description
Nessus was able to extract the banner of the Apache web server and determine which Linux distribution the remote host is running.
Solution
If you do not wish to display this information, edit '[Link]' and set the directive 'ServerTokens Prod' and restart Apache.
Risk Factor
None
Plugin Information
Published: 2005/05/15, Modified: 2025/03/31
Plugin Output
[Link] (tcp/0)
Synopsis
A VNC server is running on the remote host.
Description
This script checks the remote VNC server protocol version and the available 'security types'.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2005/07/22, Modified: 2021/07/13
Plugin Output
[Link] (tcp/5900/vnc)
Synopsis
This plugin displays information about the Nessus scan.
Description
This plugin displays, for each tested host, information about the scan itself :
Solution
[Link] 68/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
n/a
Risk Factor
None
Plugin Information
Published: 2005/08/26, Modified: 2024/12/31
Plugin Output
[Link] (tcp/0)
Synopsis
The remote web server contains a graphic image that is prone to information disclosure.
Description
The '[Link]' file found on the remote web server belongs to a popular web server. This may be used to fingerprint the web server.
Solution
Remove the '[Link]' file or create a custom one for your site.
Risk Factor
None
Plugin Information
Published: 2005/10/28, Modified: 2020/06/12
Plugin Output
[Link] (tcp/8180/www)
Synopsis
There is an AJP connector listening on the remote host.
[Link] 69/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Description
The remote host is running an AJP (Apache JServ Protocol) connector, a service by which a standalone web server such as Apache communicates over TCP with a
Java servlet container such as Tomcat.
See Also
[Link]
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2006/04/05, Modified: 2019/11/22
Plugin Output
[Link] (tcp/8009/ajp13)
Synopsis
The remote service implements TCP timestamps.
Description
The remote host implements TCP timestamps, as defined by RFC1323. A side effect of this feature is that the uptime of the remote host can sometimes be
computed.
See Also
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2007/05/16, Modified: 2023/10/17
Plugin Output
[Link] (tcp/0)
25240 (1) - Samba Server Detection -
Synopsis
An SMB server is running on the remote host.
Description
The remote host is running Samba, a CIFS/SMB server for Linux and Unix.
See Also
[Link]
Solution
n/a
Risk Factor
None
[Link] 70/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Plugin Information
Published: 2007/05/16, Modified: 2022/10/12
Plugin Output
[Link] (tcp/445/cifs)
26024 (1) - PostgreSQL Server Detection -
Synopsis
A database service is listening on the remote host.
Description
The remote service is a PostgreSQL database server, or a derivative such as EnterpriseDB.
See Also
[Link]
Solution
Limit incoming traffic to this port if desired.
Risk Factor
None
Plugin Information
Published: 2007/09/14, Modified: 2023/05/24
Plugin Output
[Link] (tcp/5432/postgresql)
35371 (1) - DNS Server [Link] Map Hostname Disclosure -
Synopsis
The DNS server discloses the remote host name.
Description
It is possible to learn the remote host name by querying the remote DNS server for '[Link]' in the CHAOS domain.
Solution
It may be possible to disable this feature. Consult the vendor's documentation for more information.
Risk Factor
None
Plugin Information
Published: 2009/01/15, Modified: 2011/09/14
Plugin Output
[Link] (udp/53/dns)
metasploitable
Synopsis
The manufacturer can be identified from the Ethernet OUI.
Description
Each ethernet MAC address starts with a 24-bit Organizationally Unique Identifier (OUI). These OUIs are registered by IEEE.
See Also
[Link]
[Link]
[Link] 71/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/02/19, Modified: 2020/05/13
Plugin Output
[Link] (tcp/0)
Synopsis
The remote web server is an Apache Tomcat server.
Description
Nessus was able to detect a remote Apache Tomcat web server.
See Also
[Link]
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0535
Plugin Information
Published: 2009/06/18, Modified: 2025/04/08
Plugin Output
[Link] (tcp/8180/www)
URL : [Link]
Version : 5.5
backported : 0
source : Apache Tomcat/5.5
Synopsis
Security patches are backported.
Description
Security patches may have been 'backported' to the remote FTP server without changing its version number.
Note that this test is informational only and does not denote any security problem.
See Also
[Link]
Solution
[Link] 72/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
n/a
Risk Factor
None
Plugin Information
Published: 2009/06/25, Modified: 2015/07/07
Plugin Output
[Link] (tcp/2121/ftp)
Synopsis
Security patches are backported.
Description
Security patches may have been 'backported' to the remote SSH server without changing its version number.
Note that this test is informational only and does not denote any security problem.
See Also
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/06/25, Modified: 2015/07/07
Plugin Output
[Link] (tcp/22/ssh)
Synopsis
Security patches are backported.
Description
Security patches may have been 'backported' to the remote HTTP server without changing its version number.
Note that this test is informational only and does not denote any security problem.
See Also
[Link]
Solution
n/a
Risk Factor
None
[Link] 73/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Plugin Information
Published: 2009/06/25, Modified: 2015/07/07
Plugin Output
[Link] (tcp/80/www)
Synopsis
The remote mail service supports encrypting traffic.
Description
The remote SMTP service supports the use of the 'STARTTLS' command to switch from a cleartext to an encrypted communications channel.
See Also
[Link]
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2009/10/09, Modified: 2019/03/20
Plugin Output
[Link] (tcp/25/smtp)
Here is the SMTP service's SSL certificate that Nessus was able to
collect after sending a 'STARTTLS' command :
Country: XX
State/Province: There is no such thing outside US
Locality: Everywhere
Organization: OCOSA
Organization Unit: Office for Complication of Otherwise Simple Affairs
Common Name: [Link]
Email Address: root@[Link]
Issuer Name:
Country: XX
State/Province: There is no such thing outside US
Locality: Everywhere
Organization: OCOSA
Organization Unit: Office for Complication of Otherwise Simple Affairs
Common Name: [Link]
Email Address: root@[Link]
Serial Number: 00 FA F9 3A 4C 7F B6 B9 CC
Version: 1
Synopsis
It was possible to enumerate CPE names that matched on the remote system.
Description
By using information obtained from a Nessus scan, this plugin reports CPE (Common Platform Enumeration) matches for various hardware and software products
found on a host.
Note that if an official CPE is not available for the product, this plugin computes the best possible CPE based on the information available from the scan.
See Also
[Link]
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2010/04/21, Modified: 2025/04/15
Plugin Output
[Link] (tcp/0)
Synopsis
It is possible to obtain the version number of the remote Apache HTTP server.
Description
The remote host is running the Apache HTTP Server, an open source web server. It was possible to read the version number from the banner.
See Also
[Link]
Solution
n/a
Risk Factor
None
References
[Link] 75/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
XREF IAVT:0001-T-0030
XREF IAVT:0001-T-0530
Plugin Information
Published: 2010/07/30, Modified: 2023/08/17
Plugin Output
[Link] (tcp/80/www)
URL : [Link]
Version : 2.2.99
Source : Server: Apache/2.2.8 (Ubuntu) DAV/2
backported : 1
modules : DAV/2
os : ConvertedUbuntu
Synopsis
It was possible to obtain the version number of the remote PHP installation.
Description
Nessus was able to determine the version of PHP available on the remote web server.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0936
Plugin Information
Published: 2010/08/04, Modified: 2025/01/31
Plugin Output
[Link] (tcp/80/www)
Version : 5.2.4-2ubuntu5.10
Source : X-Powered-By: PHP/5.2.4-2ubuntu5.10
Synopsis
The remote host allows resuming SSL sessions.
Description
This script detects whether a host allows resuming SSL sessions by performing a full SSL handshake to receive a session ID, and then reconnecting with the
previously used session ID. If the server accepts the session ID in the second connection, the server maintains a cache of sessions that can be resumed.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/02/07, Modified: 2021/09/13
Plugin Output
[Link] (tcp/25/smtp)
[Link] 76/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Synopsis
An FTP server is listening on the remote port.
Description
The remote host is running vsftpd, an FTP server for UNIX-like systems written in C.
See Also
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/03/17, Modified: 2019/11/22
Plugin Output
[Link] (tcp/21/ftp)
Synopsis
An ONC RPC portmapper is running on the remote host.
Description
The RPC portmapper is running on this port.
The portmapper allows someone to get the port number of each RPC service running on the remote host by sending either multiple lookup requests or a DUMP
request.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2011/04/08, Modified: 2011/08/29
Plugin Output
[Link] (tcp/111/rpc-portmapper)
54615 (1) - Device Type -
Synopsis
It is possible to guess the remote device type.
Description
Based on the remote operating system, it is possible to determine what the remote system type is (eg: a printer, router, general-purpose computer, etc).
Solution
n/a
Risk Factor
[Link] 77/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
None
Plugin Information
Published: 2011/05/23, Modified: 2025/03/12
Plugin Output
[Link] (tcp/0)
Synopsis
A VNC server with one or more unencrypted 'security-types' is running on the remote host.
Description
This script checks the remote VNC server protocol version and the available 'security types' to determine if any unencrypted 'security-types' are in use or available.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/04/03, Modified: 2014/03/12
Plugin Output
[Link] (tcp/5900/vnc)
2 (VNC authentication)
Synopsis
The remote host is missing several patches.
Description
The remote host is missing one or more security patches. This plugin lists the newest version of each patch to install to make sure the remote host is up-to-date.
Note: Because the 'Show missing patches that have been superseded' setting in your scan policy depends on this plugin, it will always run and cannot be disabled.
Solution
Install the patches listed below.
Risk Factor
None
Plugin Information
Published: 2013/07/08, Modified: 2025/04/08
Plugin Output
[Link] (tcp/0)
[ ISC BIND 9.x < 9.11.22, 9.12.x < 9.16.6, 9.17.x < 9.17.4 DoS (139915) ]
[Link] 78/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
+ Action to take : Re-download the software, verify it using the published MD5 / SHA1 checksums, and re-install it.
Synopsis
An SSH server is listening on this port.
Description
This script detects which algorithms and languages are supported by the remote service for encrypting communications.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2013/10/28, Modified: 2025/01/20
Plugin Output
[Link] (tcp/22/ssh)
none
zlib@[Link]
hmac-md5
hmac-md5-96
hmac-ripemd160
hmac-ripemd160@[Link]
hmac-sha1
hmac-sha1-96
umac-64@[Link]
ssh-dss
ssh-rsa
3des-cbc
aes128-cbc
aes128-ctr
aes192-cbc
aes192-ctr
aes256-cbc
aes256-ctr
arcfour
arcfour128
arcfour256
blowfish-cbc
cast128-cbc
rijndael-cbc@[Link]
hmac-md5
hmac-md5-96
hmac-ripemd160
hmac-ripemd160@[Link]
hmac-sha1
hmac-sha1-96
umac-64@[Link]
diffie-hellman-group-exchange-sha1
diffie-hellman-group-exchange-sha256
[Link] 79/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
diffie-hellman-group1-sha1
diffie-hellman-group14-sha1
none
zlib@[Link]
3des-cbc
aes128-cbc
aes128-ctr
aes192-cbc
aes192-ctr
aes256-cbc
aes256-ctr
arcfour
arcfour128
arcfour256
blowfish-cbc
cast128-cbc
rijndael-cbc@[Link]
Synopsis
Nessus was able to obtain version information on the remote DNS server.
Description
Nessus was able to obtain version information by sending a special TXT record query to the remote host.
Note that this version is not necessarily accurate and could even be forged, as some DNS servers send the information based on a configuration file.
Solution
n/a
Risk Factor
None
References
XREF IAVT:0001-T-0030
XREF IAVT:0001-T-0937
Plugin Information
Published: 2014/03/03, Modified: 2024/09/24
Plugin Output
[Link] (tcp/53/dns)
9.4.2
Synopsis
Security patches have been backported.
Description
Security patches may have been 'backported' to the remote PHP install without changing its version number.
Note that this test is informational only and does not denote any security problem.
See Also
[Link]
Solution
n/a
[Link] 80/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Risk Factor
None
Plugin Information
Published: 2015/07/07, Modified: 2024/11/22
Plugin Output
[Link] (tcp/80/www)
Synopsis
This plugin gathers MAC addresses from various sources and consolidates them into a list.
Description
This plugin gathers MAC addresses discovered from both remote probing of the host (e.g. SNMP and Netbios) and from running local checks (e.g. ifconfig). It then
consolidates the MAC addresses into a single, unique, and uniform list.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2015/10/16, Modified: 2025/04/28
Plugin Output
[Link] (tcp/0)
96982 (1) - Server Message Block (SMB) Protocol Version 1 Enabled (uncredentialed check) -
Synopsis
The remote Windows host supports the SMBv1 protocol.
Description
The remote Windows host supports Server Message Block Protocol version 1 (SMBv1). Microsoft recommends that users discontinue the use of SMBv1 due to the
lack of security features that were included in later SMB versions. Additionally, the Shadow Brokers group reportedly has an exploit that affects SMB; however, it is
unknown if the exploit affects SMBv1 or another version. In response to this, US-CERT recommends that users disable SMBv1 per SMB best practices to mitigate
these potential issues.
See Also
[Link]
[Link]
[Link]
[Link]
[Link]
Solution
Disable SMBv1 according to the vendor instructions in Microsoft KB2696547. Additionally, block SMB directly by blocking TCP port 445 on all network boundary
devices. For SMB over the NetBIOS API, block TCP ports 137 / 139 and UDP ports 137 / 138 on all network boundary devices.
Risk Factor
None
References
XREF IAVT:0001-T-0710
Plugin Information
[Link] 81/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Published: 2017/02/03, Modified: 2020/09/22
Plugin Output
[Link] (tcp/445/cifs)
Synopsis
It was possible to obtain information about the version of SMB running on the remote host.
Description
Nessus was able to obtain the version of SMB running on the remote host by sending an authentication request to port 139 or 445.
Note that this plugin is a remote check and does not work on agents.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/06/19, Modified: 2019/11/22
Plugin Output
[Link] (tcp/445/cifs)
Synopsis
It was possible to obtain the samba version from the remote operating system.
Description
Nessus was able to obtain the samba version from the remote operating by sending an authentication request to port 139 or 445. Note that this plugin requires
SMB1 to be enabled on the host.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2017/11/30, Modified: 2019/11/22
Plugin Output
[Link] (tcp/445/cifs)
106716 (1) - Microsoft Windows SMB2 and SMB3 Dialects Supported (remote check) -
Synopsis
It was possible to obtain information about the dialects of SMB2 and SMB3 available on the remote host.
Description
Nessus was able to obtain the set of SMB2 and SMB3 dialects running on the remote host by sending an authentication request to port 139 or 445.
[Link] 82/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/02/09, Modified: 2020/03/11
Plugin Output
[Link] (tcp/445/cifs)
The remote host does NOT support the following SMB dialects :
_version_ _introduced in windows version_
2.0.2 Windows 2008
2.1 Windows 7
2.2.2 Windows 8 Beta
2.2.4 Windows 8 Beta
3.0 Windows 8
3.0.2 Windows 8.1
3.1 Windows 10
3.1.1 Windows 10
Synopsis
Nessus was able to find common ports used for local checks, however, no credentials were provided in the scan policy.
Description
Nessus was not able to successfully authenticate directly to the remote target on an available authentication protocol. Nessus was able to connect to the remote
port and identify that the service running on the port supports an authentication protocol, but Nessus failed to authenticate to the remote service using the
provided credentials. There may have been a protocol failure that prevented authentication from being attempted or all of the provided credentials for the
authentication protocol may be invalid. See plugin output for error details.
- This plugin reports per protocol, so it is possible for valid credentials to be provided for one protocol and not another. For example, authentication may succeed
via SSH but fail via SMB, while no credentials were provided for an available SNMP service.
- Providing valid credentials for all available authentication protocols may improve scan coverage, but the value of successful authentication for a given protocol
may vary from target to target depending upon what data (if any) is gathered from the target via that protocol. For example, successful authentication via SSH is
more valuable for Linux targets than for Windows targets, and likewise successful authentication via SMB is more valuable for Windows targets than for Linux
targets.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0504
Plugin Information
Published: 2018/06/27, Modified: 2024/04/19
Plugin Output
[Link] (tcp/0)
Synopsis
OS Security Patch Assessment is not available.
Description
[Link] 83/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
OS Security Patch Assessment is not available on the remote host.
This does not necessarily indicate a problem with the scan.
Credentials may not have been provided, OS security patch assessment may not be supported for the target, the target may not have been identified, or another
issue may have occurred that prevented OS security patch assessment from being available. See plugin output for details.
This plugin reports non-failure information impacting the availability of OS Security Patch Assessment. Failure information is reported by plugin 21745 : 'OS
Security Patch Assessment failed'. If a target host is not supported for OS Security Patch Assessment, plugin 110695 : 'OS Security Patch Assessment Checks Not
Supported' will report concurrently with this plugin.
Solution
n/a
Risk Factor
None
References
XREF IAVB:0001-B-0515
Plugin Information
Published: 2018/10/02, Modified: 2021/07/12
Plugin Output
[Link] (tcp/0)
- Plugin : no_local_checks_credentials.nasl
Plugin ID : 110723
Plugin Name : Target Credential Status by Authentication Protocol - No Credentials Provided
Message :
Credentials were not provided for detected SSH service.
Synopsis
The remote service supports encrypting traffic.
Description
The remote PostgreSQL server supports the use of encryption initiated during pre-login to switch from a cleartext to an encrypted communications channel.
See Also
[Link]
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2018/10/19, Modified: 2022/04/11
Plugin Output
[Link] (tcp/5432/postgresql)
Country: XX
State/Province: There is no such thing outside US
Locality: Everywhere
Organization: OCOSA
Organization Unit: Office for Complication of Otherwise Simple Affairs
Common Name: [Link]
Email Address: root@[Link]
Issuer Name:
[Link] 84/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Country: XX
State/Province: There is no such thing outside US
Locality: Everywhere
Organization: OCOSA
Organization Unit: Office for Complication of Otherwise Simple Affairs
Common Name: [Link]
Email Address: root@[Link]
Serial Number: 00 FA F9 3A 4C 7F B6 B9 CC
Version: 1
Synopsis
WMI queries could not be made against the remote host.
Description
WMI (Windows Management Instrumentation) is not available on the remote host over DCOM. WMI queries are used to gather information about the remote host,
such as its current state, network interface configuration, etc.
Without this information Nessus may not be able to identify installed software or security vunerabilities that exist on the remote host.
See Also
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2020/04/21, Modified: 2025/03/31
Plugin Output
[Link] (tcp/445/cifs)
Synopsis
The SSH server on the remote host accepts password authentication.
Description
The SSH server on the remote host accepts password authentication.
[Link] 85/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
See Also
[Link]
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/05/07, Modified: 2021/05/07
Plugin Output
[Link] (tcp/22/ssh)
153588 (1) - SSH SHA-1 HMAC Algorithms Enabled -
Synopsis
The remote SSH server is configured to enable SHA-1 HMAC algorithms.
Description
The remote SSH server is configured to enable SHA-1 HMAC algorithms.
Although NIST has formally deprecated use of SHA-1 for digital signatures, SHA-1 is still considered secure for HMAC as the security of HMAC does not rely on the
underlying hash function being resistant to collisions.
Note that this plugin only checks for the options of the remote SSH server.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2021/09/23, Modified: 2022/04/05
Plugin Output
[Link] (tcp/22/ssh)
The following client-to-server SHA-1 Hash-based Message Authentication Code (HMAC) algorithms are supported :
hmac-sha1
hmac-sha1-96
The following server-to-client SHA-1 Hash-based Message Authentication Code (HMAC) algorithms are supported :
hmac-sha1
hmac-sha1-96
Synopsis
An OpenSSH-based SSH server was detected on the remote host.
Description
An OpenSSH-based SSH server was detected on the remote host.
See Also
[Link]
Solution
n/a
Risk Factor
None
[Link] 86/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
Plugin Information
Published: 2023/09/14, Modified: 2025/04/28
Plugin Output
[Link] (tcp/22/ssh)
Service : ssh
Version : 4.7p1
Banner : SSH-2.0-OpenSSH_4.7p1 Debian-8ubuntu1
Synopsis
Multiple OS fingerprints were detected.
Description
Using a combination of remote probes (TCP/IP, SMB, HTTP, NTP, SNMP, etc), it was possible to gather one or more fingerprints from the remote system. While the
highest-confidence result was reported in plugin 11936, “OS Identification”, the complete set of fingerprints detected are reported here.
Solution
n/a
Risk Factor
None
Plugin Information
Published: 2025/02/26, Modified: 2025/03/03
Plugin Output
[Link] (tcp/0)
Système d'exploitation distant : Noyau Linux 2.6 sur Ubuntu 8.04 (hardy)
Niveau de confiance : 95
Méthode : SSH
Type : usage général
Empreinte digitale : SSH:SSH-2.0-OpenSSH_4.7p1 Debian-8ubuntu1
Système d'exploitation distant : Noyau Linux 2.6 sur Ubuntu 8.04 (gutsy)
Niveau de confiance : 95
Méthode : HTTP
Type : usage général
Empreinte digitale : inconnue
Les empreintes digitales suivantes n'ont pas pu être utilisées pour déterminer le système d'exploitation :
[Link] 87/88
05/05/2025 10:49 Scan_service_reseau_metasploitable
SMTP:!:220 [Link] ESMTP Postfix (Ubuntu)
SSLcert:!:i/CN:[Link]/O:OCOSAi/OU:Bureau de complication des affaires autrement simpless/CN:ubuntu804-
[Link]/O:OCOSAs/OU:Bureau de complication des affaires autrement simples
ed093088706603bfd5dc237399b498da2d4d31c6
i/CN:[Link]/O:OCOSAi/OU:Bureau de complication des affaires autrement simpless/CN:ubuntu804-
[Link]/O:OCOSAs/OU:Bureau de complication des affaires autrement simples
ed093088706603bfd5dc237399b498da2d4d31c6
[Link] 88/88