[9441] in bugtraq
Re: ISS Internet Scanner Cannot be relied upon for conclusive
daemon@ATHENA.MIT.EDU (blkadder@VALUE.NET)
Tue Feb 9 16:40:14 1999
Date: Mon, 8 Feb 1999 09:55:03 -0800
Reply-To: blkadder@VALUE.NET
From: blkadder@VALUE.NET
X-To: David LeBlanc <dleblanc@MINDSPRING.COM>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <3.0.3.32.19990208110245.00ca8610@mail.mindspring.com>
On Mon, 8 Feb 1999, David LeBlanc wrote:
> One of the ways to check for this particular bug is to us SNMP to pull down
> the sysDescr information, and parse it to look for versions that we know
> have problems. _If_ we can get the system description, it is an easy and
> reliable way to find vulnerable machines. However, if SNMP isn't running,
> or won't respond (even after trying to guess the community string), then
> this method won't work.
Another method to check for that particular bug is to actually attempt the
exploit. And you are not doing that because.... ???