in

eEye Digital Security

The endpoint to vulnerability starts here.

 

null session and autorun update false positive findings

Last post 12-02-2009 8:16 AM by wrkidd. 13 replies.
Page 1 of 1 (14 items)
Sort Posts: Previous Next
  • 09-02-2009 6:39 AM

    null session and autorun update false positive findings

     I have a lot of these false positives. This means the system was not admin, or is there another possible problem? Thx.

  • 09-02-2009 12:55 PM In reply to

    Re: null session and autorun update false positive findings

  • 09-03-2009 7:11 AM In reply to

    • Wedge
    • Top 500 Contributor
    • Joined on 09-03-2009
    • Posts 3

    Re: null session and autorun update false positive findings

     No Vista over here and I got alot of the Null Sessions false positives.

  • 09-03-2009 12:11 PM In reply to

    • bpatten
    • Top 10 Contributor
    • Joined on 09-24-2007
    • Irvine, CA
    • Posts 155

    Re: null session and autorun update false positive findings

    Whats the audit ID?

  • 09-08-2009 7:03 AM In reply to

    • Wedge
    • Top 500 Contributor
    • Joined on 09-03-2009
    • Posts 3

    Re: null session and autorun update false positive findings

     163 Does it tie in with ID # 2913?

  • 09-08-2009 10:06 AM In reply to

    • bpatten
    • Top 10 Contributor
    • Joined on 09-24-2007
    • Irvine, CA
    • Posts 155

    Re: null session and autorun update false positive findings

     163 is different thand 2913. One is Null Session and one is Anonymous Registry Access.

  • 09-09-2009 5:59 AM In reply to

    • Wedge
    • Top 500 Contributor
    • Joined on 09-03-2009
    • Posts 3

    Re: null session and autorun update false positive findings

     Thanks... it just seemed odd thaqt Audit ID did not come until the recent upgrade. And not across the board on my network. No biggie. Gonna look around for any other false positives. I like the product, but seems interesting findings increased on this upgrade.

  • 09-09-2009 8:23 AM In reply to

    Re: null session and autorun update false positive findings

    Wedge:
    I like the product ...
     

    Retina in Blink 4.4.1?

  • 09-11-2009 9:24 AM In reply to

    Re: null session and autorun update false positive findings

     I have 163 for the Null Session.

    This one seems to be related to case sensitivity in the registry.  Even if the settings are correct it is a finding unless the registry entries are in the proper (per Retina) CamelCasing.  All lower case and it's a false positive.

    Is there any way to turn off case sensitivity in Retina?

    SPD

  • 09-11-2009 4:23 PM In reply to

    • bpatten
    • Top 10 Contributor
    • Joined on 09-24-2007
    • Irvine, CA
    • Posts 155

    Re: null session and autorun update false positive findings

    Retina uses Windows APIs so its simply based on the case sensitivity of Windows, which typically there is no case sensitivity.

    I'm not sure why SPD mentions this.

  • 09-14-2009 10:51 AM In reply to

    Re: null session and autorun update false positive findings

    I mentioned it because (oddly enough) if the registry entry is in all lower case its a finding. If I re-enter the registry entries using mixed case its not.  Sorry if I wasn't clear.  Could there be a setting in Windows that has been incorrectly configured and if so how do I correct that?

    Thanks for the help,

    SPD

     

  • 09-25-2009 5:41 AM In reply to

    Re: null session and autorun update false positive findings

    Microsoft has 3 registry entries for this particular item, please post the correct capitalization (per the Retina scanner) to eliminate this finding.

    Thanks

  • 11-06-2009 1:42 AM In reply to

    Re: null session and autorun update false positive findings

     This is in response to the false positives for audit 163, NULL sessions. Audit 2913 is totally unrelated.

    Audit 163 (NULL session connections expose sensitive info via Windows Net??? API calls) and 2091 (limited NULL session exposure through the SRVSVC and/or SAMR named pipes) deal with NULL session vulnerabilities.

    Funny that I just spent 11 hours today figuring out why we sometimes report false positives on 2003/XP and greater systems. Unlike 2000, NULL session connections are always allowed on 2003/XP which in conjunction with certain combinations of registry values result in false findings. The audits have been fixed and will be availble in late November or early December.

    I will be preparing a KB article tomorrow explaining the quirks in the 2003/XP MS solution to NULL session restrictions and the criteria we now use to report findings. Instructions on how to resolve the issue will also be updated with more detail.

     

    Craig

  • 12-02-2009 8:16 AM In reply to

    • wrkidd
    • Top 200 Contributor
    • Joined on 08-19-2009
    • Posts 4

    Re: null session and autorun update false positive findings

     Craig,

    Thanks for the response on audit 163. Is the KB article you referenced available?

    Thanks

Page 1 of 1 (14 items)
© 1995 - 2009 eEye Incorporated