Mailing List Archive

Nessus script id 10759 misses Oracle Enterprise Manager
We have an Oracle Enterprise Manager that triggers plugin 10759. Looking
at the nasl and the header info, it makes sense. The nasl looks for
10.x.x.x except for "Oracle.*/10\." The header looks like this:

Protocol version : HTTP/1.1
SSL : no
Pipelining : yes
Keep-Alive : yes
Options allowed : (Not implemented)
Headers :
Content-Type: text/html
charset=UTF-8
Transfer-Encoding: chunked
Connection: Keep-Alive
X-ORCL-EMSV: 10.1.0.4.1
X-ORCL-EMCT: 2008-02-06 09:26:47

The "private ip" being complained of is 10.1.0.4. I don't know what
headers are standard, but it looks to me as if the
X-ORCL-EMSV: 10.1.0.4.1
line needs to be checked for.

Cheryl

_______________________________________________
Plugins-writers mailing list
Plugins-writers@list.nessus.org
http://mail.nessus.org/mailman/listinfo/plugins-writers
Re: Nessus script id 10759 misses Oracle Enterprise Manager [ In reply to ]
On Feb 6, 2008, at 4:04 PM, Cheryl Ammann wrote:

> We have an Oracle Enterprise Manager that triggers plugin 10759.
...
> The "private ip" being complained of is 10.1.0.4. I don't know what
> headers are standard, but it looks to me as if the
> X-ORCL-EMSV: 10.1.0.4.1
> line needs to be checked for.

Thanks for the report. Revision 1.27 of the plugin should correct this
and become available in the next couple of hours.

George
--
theall@tenablesecurity.com



_______________________________________________
Plugins-writers mailing list
Plugins-writers@list.nessus.org
http://mail.nessus.org/mailman/listinfo/plugins-writers