|
Family: General --> Category: infos
SWAT allows user names to be obtained by brute force Vulnerability Scan
Vulnerability Scan Summary Detect SWAT server port
Detailed Explanation for this Vulnerability Test
The remote SWAT server replies with different error codes when
it is issued a bad user name or a bad password.
A possible hacker may use this flaw to obtain the list of
user names of the remote host by a brute force attack.
As SWAT does not log login attempts, a possible hacker may use
this flaw even more effectively
Solution : get the latest version of samba, or disable swat
Threat Level: Low
Click HERE for more information and discussions on this network vulnerability scan.
|