|
![]() |
| 11/01/2006 |
| Report Summary | |||||||||||||||||||||||||
|
|
||||||||||||||||||||||||
|
|||||||||||||||||||||||||
|
|||||||||||||||||||||||||
|
|||||||||||||||||||||||||
|
|||||||||||||||||||||||||
|
|||||||||||||||||||||||||
| Summary of Vulnerabilities |
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Vulnerabilities by Severity | |
|
|
| Operating Systems Detected | |
|
|
| Services Detected | |
|
|
| Detailed Results |
| 192.168.1.1 (-, -) | Cisco IOS 11.3-12.4 |
|
|
|
|
|
ICMP Timestamp Request |
|
However, you should never filter ALL ICMP messages, as some of them ("Don't Fragment", "Destination Unreachable", "Source Quench", etc) are necessary for proper behavior of Operating System TCP/IP stacks.
It may be wiser to contact your network consultants for advice, since this issue impacts your overall network reliability and security.
|
|
|
|
|
Multiple Vendor H.323 Protocol Implementation Vulnerabilities |
port 1720/tcp
|
|
The H.225 subcomponent of the H.323 protocol was found to have multiple vulnerabilities in various vendor implementations of the protocol. H.225 is most commonly used as a component of Voice over IP (VoIP).
Microsoft has patches and a description of the problem in Microsoft Security Bulletin MS04-001.
Cisco has issued information in this Cisco security advisory.
Nortel reported some vulnerable products.
|
|
|
|
|
Operating System Detected |
|
1) TCP/IP Fingerprint: The operating system of a host can be identified from a remote system using TCP/IP fingerprinting. All underlying operating system TCP/IP stacks have subtle differences that can be seen in their responses to specially-crafted TCP packets. According to the results of this "fingerprinting" technique, the OS version is among those listed below.
Note that if one or more of these subtle differences are modified by a firewall or a packet filtering device between the scanner and the host, the fingerprinting technique may fail. Consequently, the version of the OS may not be detected correctly. If the host is behind a proxy-type firewall, the version of the operating system detected may be that for the firewall instead of for the host being scanned.
2) NetBIOS: Short for Network Basic Input Output System, an application programming interface (API) that augments the DOS BIOS by adding special functions for local-area networks (LANs). Almost all LANs for PCs are based on the NetBIOS. Some LAN manufacturers have even extended it, adding additional network capabilities. NetBIOS relies on a message format called Server Message Block (SMB).
3) PHP Info: PHP is a hypertext pre-processor, an open-source, server-side, HTML-embedded scripting language used to create dynamic Web pages. Under some configurations it is possible to call PHP functions like phpinfo() and obtain operating system information.
4) SNMP: The Simple Network Monitoring Protocol is used to monitor hosts, routers, and the networks to which they attach. The SNMP service maintains Management Information Base (MIB), a set of variables (database) that can be fetched by Managers. These include "MIB_II.system.sysDescr" for the operating system.
| Operating System | Technique | ID |
| Cisco IOS 11.3-12.4 | TCP/IP Fingerprint | U1053:5060 |
|
|
|
ICMP Replies Received |
|
We have sent the following types of packets to trigger the host to send us ICMP replies:
Echo Request (to trigger Echo Reply)
Timestamp Request (to trigger Timestamp Reply)
Address Mask Request (to trigger Address Mask Reply)
UDP Packet (to trigger Port Unreachable Reply)
IP Packet with Protocol >= 250 (to trigger Protocol Unreachable Reply)
Listed in the "Result" section are the ICMP replies that we have received.
| ICMP Reply Type | Triggered By | Additional Information |
| Echo (type=0 code=0) | Echo Request | Echo Reply |
| Time Stamp (type=14 code=0) | Time Stamp Request | 00:27:24 GMT |
|
|
|
DNS Host Name |
|
| IP address | Host name |
| 192.168.1.1 | No registered hostname |
|
|
|
Traceroute |
|
| Hops | IP | Round Trip Time | Probe |
| 1 | 167.216.252.1 | 0.53ms | ICMP |
| 2 | 216.34.3.57 | 0.32ms | ICMP |
| 3 | 208.173.55.49 | 0.98ms | ICMP |
| 4 | 208.175.172.170 | 2.72ms | ICMP |
| 5 | 152.63.57.102 | 2.76ms | ICMP |
| 6 | 152.63.68.117 | 77.15ms | ICMP |
| 7 | 152.63.18.30 | 77.34ms | ICMP |
| 8 | 152.63.23.37 | 80.73ms | ICMP |
| 9 | 63.111.120.102 | 81.90ms | ICMP |
| 10 | 66.155.218.1 | 81.77ms | ICMP |
| 11 | 64.80.254.182 | 82.25ms | TCP |
| 12 | 67.151.33.36 | 87.27ms | TCP |
| 13 | 192.168.1.1 | 91.88ms | TCP |
|
|
|
Target Network Information |
|
|
|
|
Internet Service Provider |
|
|
|
|
Host Scan Time |
|
The Host Scan Time does not have a direct correlation to the Duration time as displayed in the Report Summary section of a scan results report. The Duration is the period of time it takes the service to perform a scan task. The Duration includes the time it takes the service to scan all hosts, which may involve parallel scanning. It also includes the time it takes for a scanner appliance to pick up the scan task and transfer the results back to the service's Secure Operating Center. Further, when a scan task is distributed across multiple scanners, the Duration includes the time it takes to perform parallel host scanning on all scanners.
|
|
|
Open TCP Services List |
|
| Port | IANA Assigned Ports/Services | Description | Service Detected | OS On Redirected Port |
| 1720 | netmeeting | h323hostcall h323hostcall | h323 | |
| 5060 | sip | SIP | unknown |
|
|
|
IP ID Values Randomness |
|
Please note that for reliability reasons only the network traffic from open TCP ports is analyzed.
|
|
|
Host Name Not Available |
|
|
|
|
Degree of Randomness of TCP Initial Sequence Numbers |
|
| 192.168.1.2 (-, -) | Cisco IOS 11.3-12.4 |
|
|
|
|
|
ICMP Timestamp Request |
|
However, you should never filter ALL ICMP messages, as some of them ("Don't Fragment", "Destination Unreachable", "Source Quench", etc) are necessary for proper behavior of Operating System TCP/IP stacks.
It may be wiser to contact your network consultants for advice, since this issue impacts your overall network reliability and security.
|
|
|
|
|
Multiple Vendor H.323 Protocol Implementation Vulnerabilities |
port 1720/tcp
|
|
The H.225 subcomponent of the H.323 protocol was found to have multiple vulnerabilities in various vendor implementations of the protocol. H.225 is most commonly used as a component of Voice over IP (VoIP).
Microsoft has patches and a description of the problem in Microsoft Security Bulletin MS04-001.
Cisco has issued information in this Cisco security advisory.
Nortel reported some vulnerable products.
|
|
|
|
|
Operating System Detected |
|
1) TCP/IP Fingerprint: The operating system of a host can be identified from a remote system using TCP/IP fingerprinting. All underlying operating system TCP/IP stacks have subtle differences that can be seen in their responses to specially-crafted TCP packets. According to the results of this "fingerprinting" technique, the OS version is among those listed below.
Note that if one or more of these subtle differences are modified by a firewall or a packet filtering device between the scanner and the host, the fingerprinting technique may fail. Consequently, the version of the OS may not be detected correctly. If the host is behind a proxy-type firewall, the version of the operating system detected may be that for the firewall instead of for the host being scanned.
2) NetBIOS: Short for Network Basic Input Output System, an application programming interface (API) that augments the DOS BIOS by adding special functions for local-area networks (LANs). Almost all LANs for PCs are based on the NetBIOS. Some LAN manufacturers have even extended it, adding additional network capabilities. NetBIOS relies on a message format called Server Message Block (SMB).
3) PHP Info: PHP is a hypertext pre-processor, an open-source, server-side, HTML-embedded scripting language used to create dynamic Web pages. Under some configurations it is possible to call PHP functions like phpinfo() and obtain operating system information.
4) SNMP: The Simple Network Monitoring Protocol is used to monitor hosts, routers, and the networks to which they attach. The SNMP service maintains Management Information Base (MIB), a set of variables (database) that can be fetched by Managers. These include "MIB_II.system.sysDescr" for the operating system.
| Operating System | Technique | ID |
| Cisco IOS 11.3-12.4 | TCP/IP Fingerprint | U1053:1720 |
|
|
|
ICMP Replies Received |
|
We have sent the following types of packets to trigger the host to send us ICMP replies:
Echo Request (to trigger Echo Reply)
Timestamp Request (to trigger Timestamp Reply)
Address Mask Request (to trigger Address Mask Reply)
UDP Packet (to trigger Port Unreachable Reply)
IP Packet with Protocol >= 250 (to trigger Protocol Unreachable Reply)
Listed in the "Result" section are the ICMP replies that we have received.
| ICMP Reply Type | Triggered By | Additional Information |
| Echo (type=0 code=0) | Echo Request | Echo Reply |
| Time Stamp (type=14 code=0) | Time Stamp Request | 14:22:59 GMT |
|
|
|
DNS Host Name |
|
| IP address | Host name |
| 192.168.1.2 | No registered hostname |
|
|
|
Traceroute |
|
| Hops | IP | Round Trip Time | Probe |
| 1 | 167.216.252.1 | 0.18ms | ICMP |
| 2 | 216.34.3.57 | 0.29ms | ICMP |
| 3 | 208.173.55.49 | 0.86ms | ICMP |
| 4 | 208.175.172.170 | 2.81ms | ICMP |
| 5 | 152.63.57.102 | 2.83ms | ICMP |
| 6 | 152.63.68.117 | 76.97ms | ICMP |
| 7 | 152.63.18.30 | 76.95ms | ICMP |
| 8 | 152.63.22.253 | 205.38ms | ICMP |
| 9 | 63.111.120.102 | 214.12ms | ICMP |
| 10 | 66.155.218.33 | 206.46ms | ICMP |
| 11 | 64.80.254.182 | 201.24ms | ICMP |
| 12 | 67.151.33.6 | 193.98ms | ICMP |
| 13 | 192.168.1.2 | 222.88ms | TCP |
|
|
|
Target Network Information |
|
|
|
|
Internet Service Provider |
|
|
|
|
Host Scan Time |
|
The Host Scan Time does not have a direct correlation to the Duration time as displayed in the Report Summary section of a scan results report. The Duration is the period of time it takes the service to perform a scan task. The Duration includes the time it takes the service to scan all hosts, which may involve parallel scanning. It also includes the time it takes for a scanner appliance to pick up the scan task and transfer the results back to the service's Secure Operating Center. Further, when a scan task is distributed across multiple scanners, the Duration includes the time it takes to perform parallel host scanning on all scanners.
|
|
|
Open TCP Services List |
|
| Port | IANA Assigned Ports/Services | Description | Service Detected | OS On Redirected Port |
| 1720 | netmeeting | h323hostcall h323hostcall | h323 | |
| 5060 | sip | SIP | unknown |
|
|
|
IP ID Values Randomness |
|
Please note that for reliability reasons only the network traffic from open TCP ports is analyzed.
|
|
|
Degree of Randomness of TCP Initial Sequence Numbers |
|
|
|
|
Host Name Not Available |
|
| 192.168.1.3 (-, -) | Cisco IOS 11.3-12.4 |
|
|
|
|
|
NTP Information Disclosure Vulnerability |
port 123/udp
|
|
|
|
|
UDP Constant IP Identification Field Fingerprinting Vulnerability |
|