Mailing List Archive

detect world writeable nfs shares on unix system services?
New user, running Nessus 3 on XP sp3.

The following plugins work correctly for me when attempting to identify
world writeable nfs shares in a small *nix environment:

Mountable NFS Shares
NFS export
User Mountable NFS shares

However, they do not seem to pick up on two MS servers running Unix System
Services. Using 'showmount -e ussserver1or2' from the *nix boxes clearly
shows exported directories (and one writeable to everyone) available. Is
there another plugin available that would display these as the 'nfs export'
plugin does? Or any suggestions on how to modify it so that it will include
them?

Thanks,
JC
Re: detect world writeable nfs shares on unix system services? [ In reply to ]
Hi Jeff,

On Dec 16, 2008, at 6:07 PM, Jeff Cranfill wrote:

> New user, running Nessus 3 on XP sp3.
>
> The following plugins work correctly for me when attempting to
> identify world writeable nfs shares in a small *nix environment:
>
> Mountable NFS Shares
> NFS export
> User Mountable NFS shares
>
> However, they do not seem to pick up on two MS servers running Unix
> System Services. Using 'showmount -e ussserver1or2' from the *nix
> boxes clearly shows exported directories (and one writeable to
> everyone) available. Is there another plugin available that would
> display these as the 'nfs export' plugin does? Or any suggestions
> on how to modify it so that it will include them?

First, could you make sure you're running the most up to date set of
plugins? We fixed some issues in NFS a month or so ago, maybe that
will solve your problem.

If not, could you send me (privately) a pcap of the traffic sent while
you do a 'showmount -e ussserver1or2' ?


Thanks,

-- Renaud




_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus