Totally Zenned
- Join Date:
- Feb 2007
- Posts:
- 1,724
- Plugin Contributions:
- 0
Failed PCI Compliancy
**Website Failed PCI Complaincy Test!
openSSH X11 Session Hijacking Vulnerability**
OpenSSH is prone to a vulnerability that allows local attackers to hijack forwarded X connections. The system must have both IPv4 and IPv6 enabled at the same time for this to be exploited. Successfully exploiting this issue may allow an attacker run arbitrary shell commands with the privileges of the user running the affected application. This issue is known to affect OpenSSH 4.3p2, though other versions may also be affected. This vulnerability will trigger on any SSH banner version prior to 'openssh-5'. OpenSSH packages shipped with Red Hat Enterprise Linux 4 and 5 are not vulnerable to this issue. However, Red Hat Enterprise Linux 2.1 and 3 are affected.
remediation:
Due to the fact that this vulnerability is detected by analyzing the SSH banner version, an appeal must be submitted after following any remediation step other than upgrading to OpenSSH 5.0. There are several options for removing this issue: 1) Instruct OpenSSH to use only IPv4 or IPv6 by adding either "AddressFamily inet" or "AddressFamily inet6" to sshd_config. 2) Configure the operating system to only use IPv4 or IPv6, but not both. 3) Confirm with your vendor that your version of SSH is patched or CVE-2008-1483. 4) Upgrade to version 5.0 of OpenSSH, or acquire appropriate patches from your vendor. It is strongly recommended that the latest stable version with all of the appropriate patches be installed. 5) Disable X11 forwarding in the sshd_config if it is not needed.
OpenSSH Privilege Separation Monitor Weakness
Based on the version reported reported by OpenSSH running on this host, it is prone to a weakness that, under certain conditions, could allow an attacker to bypass authentication. This issue is due to a design error in the privilege separation monitor that could cause it to authenticate when it should not.
remediation:
This vulnerability was fixed with the release of OpenSSH 4.5, however it is recommended that you upgrade to the latest supported release. Confirm with your vendor that your version of SSH is patched or CVE-2006-5794.
**OpenSSH X11 Cookie Local Authentication Bypass Vulnerability
**OpenSSH is prone to a local authentication-bypass vulnerability because the software fails to properly manage trusted and untrusted X11 cookies. This vulnerability affects local SSH clients with trusted X11 forwarding enabled (enabled via the '-Y' ssh command line argument, or the ssh_config option "ForwardX11Trusted" set to "yes").
Successfully exploiting this issue allows local attackers to potentially launch a forwarded X11 session through SSH in an unauthorized manner. This issue is known to affect OpenSSH starting with version 3.8, and was fixed with the release of version 4.7.remediation:
This issue was fixed with the release of version 4.7 of OpenSSH. However, it is strongly recommended that the latest stable version with all of the appropriate patches be installed.
This issue did not affect the OpenSSH packages as distributed with Red Hat Enterprise Linux 2.1 or 3, as they do not support Trusted X11 forwarding.
OpenSSH < 4.4 Multiple Vulnerability
OpenSSH prior to version 4.4 is affected by multiple vulnerabilities that may allow for a remote attacker to execute arbitrary code on the affected device.
remediation:
This issue was fixed in OpenSSH version 4.4. Upgrade to a recent/stable version
OpenSSH Duplicate Block Denial of Service Vulnerability
A version of OpenSSH prior to 4.4 is running on this host. This version is affected by a Denial of Service vulnerability. However, an attack can only be performed if version 1 of the SSH protocol is enabled.
remediation:
SSH version 1 should be disabled, as it has inherent weaknesses that can be leveraged for man-in-the-middle attacks.
DB Accessibility
There is a port open on this server that is usually used for database connections. Payment industry policy forbids exposing databases containing cardholder data directly to the Internet.
remediation:
You may use the TrustKeeper Appeal process if the database server running on this host is not involved in the storage of cardholder data by your organization, or if you believe that this policy should be waived for any other reason. Please be sure to clearly describe what kind of information is stored in this database if it is associated with an e-commerce application.
MySQL Database Detected
The scanner was able to successfully connect to a MySQL server on this system.
remediation:
Databases should not be accessible from the Internet. Your web site should be re-architected so that the database is protected by a firewall or router access control list. In the short term, consider implementing database access control lists in order to prevent unauthorized IP addresses from connecting to MySQL.
Unsure what part of these i should change something on the site or which part i should contact my host for changes etc.
Any guideance would be great.