Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.10940
Kategorie:Useless services
Titel:Windows Terminal Service Enabled
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The Terminal Services are enabled on the remote host.

Terminal Services allow a Windows user to remotely obtain
a graphical login (and therefore act as a local user on the
remote host).

If an attacker gains a valid login and password, he may
be able to use this service to gain further access
on the remote host. An attacker may also use this service
to mount a dictionnary attack against the remote host to try
to log in remotely.

Note that RDP (the Remote Desktop Protocol) is vulnerable
to Man-in-the-middle attacks, making it easy for attackers to
steal the credentials of legitimates users by impersonating the
Windows server.

Solution : Disable the Terminal Services if you do not use them, and
do not allow this service to run across the internet

Risk factor : Medium

Querverweis: BugTraq ID: 3099
BugTraq ID: 7258
Common Vulnerability Exposure (CVE) ID: CVE-2001-0540
http://www.securityfocus.com/bid/3099
Microsoft Security Bulletin: MS01-040
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-040
XForce ISS Database: win-terminal-rdp-dos(6912)
https://exchange.xforce.ibmcloud.com/vulnerabilities/6912
CopyrightThis script is Copyright (C) 2002 Renaud Deraison

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.