OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Nessus-devel] iis_nat.nasl and propfind_internal_ip.nasl false positives on Oracle

From: Martin Mačok (martin.macokunderground.cz)
Date: Thu Dec 22 2005 - 14:54:53 CST


I have an Oracle HTTP server that identifies itself through headers as

Server: Oracle-Application-Server-10g/10.1.2.0.0 Oracle-HTTP-Server OracleAS-Web-Cache-10g/10.1.2.0.0

and through HTTP error responses in bodies with

Oracle-Application-Server-10g/10.1.2.0.0 Oracle-HTTP-Server Server at ...

Both mentioned plugins thinks that "10.1.2.0" is the leaked private IP.

Martin Mačok
ICT Security Consultant
_______________________________________________
Nessus-devel mailing list
Nessus-devellist.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus-devel