Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-17-2005, 04:29 PM
Doug Fox
Guest
 
Posts: n/a
Default GFI NSS - RPC.ypasswdd service in Windows Server 2003

I scanned a Windows Server 2003 by a NSS 5.0 with the latest update. It
reported that it has found two vulnerabilities, RPC.ypasswdd service
vulnerability and Samba buffer overflow.

According to CERT and Security Focus, they are more *IX based
vulnerabilities.

What cause NSS identify these two vulnerabilites? How can I resolve this
issue?

Could someone please shed some light? Any pointers/comments are appreciated.

Thanks,



Reply With Quote
  #2 (permalink)  
Old 10-22-2005, 11:32 PM
Donnie
Guest
 
Posts: n/a
Default Re: GFI NSS - RPC.ypasswdd service in Windows Server 2003


"Doug Fox" <dfox138-no-spam@hotmail.com> wrote in message
news:9sCdnTjrrJH1TM7eRVn-iQ@rogers.com...
> I scanned a Windows Server 2003 by a NSS 5.0 with the latest update. It
> reported that it has found two vulnerabilities, RPC.ypasswdd service
> vulnerability and Samba buffer overflow.
>
> According to CERT and Security Focus, they are more *IX based
> vulnerabilities.
>
> What cause NSS identify these two vulnerabilites? How can I resolve this
> issue?
>
> Could someone please shed some light? Any pointers/comments are

appreciated.
>
> Thanks,
>

#################################
RPC ypasswd is certainly unix related and pretty much outdated AFAIK. If
you have a Unix box run
rpcinfo IP_of_your_server. I'm sure that ypasswdd is not running although
RPC is. There are a few things in windows dependent on RPC. Was that on
port 111? That's was the port used in Unix. Are you running Samba? I
would try another scan using nmap or ostrosoft.. Also, is the server behind
a router and does it have an internal IP address?
donnie



Reply With Quote
  #3 (permalink)  
Old 10-23-2005, 01:57 AM
Donnie
Guest
 
Posts: n/a
Default Re: GFI NSS - RPC.ypasswdd service in Windows Server 2003


"Donnie" <queyosepa@quetejodas.net> wrote in message
news:G_z6f.168662$qY1.15832@bgtnsc04-news.ops.worldnet.att.net...
>
> "Doug Fox" <dfox138-no-spam@hotmail.com> wrote in message
> news:9sCdnTjrrJH1TM7eRVn-iQ@rogers.com...
> > I scanned a Windows Server 2003 by a NSS 5.0 with the latest update. It
> > reported that it has found two vulnerabilities, RPC.ypasswdd service
> > vulnerability and Samba buffer overflow.
> >
> > According to CERT and Security Focus, they are more *IX based
> > vulnerabilities.
> >
> > What cause NSS identify these two vulnerabilites? How can I resolve this
> > issue?
> >
> > Could someone please shed some light? Any pointers/comments are

> appreciated.
> >
> > Thanks,
> >

> #################################
> RPC ypasswd is certainly unix related and pretty much outdated AFAIK. If
> you have a Unix box run
> rpcinfo IP_of_your_server. I'm sure that ypasswdd is not running

although
> RPC is. There are a few things in windows dependent on RPC. Was that on
> port 111? That's was the port used in Unix. Are you running Samba? I
> would try another scan using nmap or ostrosoft.. Also, is the server

behind
> a router and does it have an internal IP address?
> donnie
>

##########################
Make that rcpinfo -p IP_of_your_server
donnie.



Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Secure Wireless for non-public network, Windows Server 2003 R2, Linksys APs bjriffel@hotmail.com alt.internet.wireless 3 01-25-2007 04:04 PM
HPSBMA02149 SSRT050968 rev.1 - HP OpenView Operations, Remote Unauthorized Access and Denial of Service (DoS) Security Alert comp.security.misc 0 09-13-2006 05:40 PM
Configuring ALi USB card in Windows 2003 Mr. Land alt.comp.hardware 7 08-17-2005 01:40 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 07-31-2005 04:25 AM
Dlink DWL-G122 and Win server 2003 Lars alt.internet.wireless 0 07-20-2005 11:03 AM


All times are GMT. The time now is 12:33 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45