0% found this document useful (0 votes)
15 views8 pages

Anarock VAPT Report

The document lists various security risks associated with multiple hosts running Linux Kernel 2.6, primarily focusing on SSL certificate trust issues and SSH server configurations. The risks are categorized as medium or low, with specific ports and protocols noted for each host. Recommendations for addressing these vulnerabilities include obtaining valid SSL certificates and disabling CBC mode in SSH configurations.

Uploaded by

suroojusaikiran
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views8 pages

Anarock VAPT Report

The document lists various security risks associated with multiple hosts running Linux Kernel 2.6, primarily focusing on SSL certificate trust issues and SSH server configurations. The risks are categorized as medium or low, with specific ports and protocols noted for each host. Recommendations for addressing these vulnerabilities include obtaining valid SSL certificates and disabling CBC mode in SSH configurations.

Uploaded by

suroojusaikiran
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
You are on page 1/ 8

Risk Host Port Protocol Hostname

Medium 192.168.0.8 443 tcp Linux Kernel 2.6


Medium 192.168.0.8 4343 tcp Linux Kernel 2.6
Low 192.168.0.8 22 tcp Linux Kernel 2.6
Low 192.168.0.8 2322 tcp Linux Kernel 2.6
Medium 192.168.0.9 443 tcp Linux Kernel 2.6
Medium 192.168.0.9 4343 tcp Linux Kernel 2.6
Low 192.168.0.9 22 tcp Linux Kernel 2.6
Low 192.168.0.9 2322 tcp Linux Kernel 2.6
Medium 192.168.0.14 443 tcp Linux Kernel 2.6
Medium 192.168.0.14 4343 tcp Linux Kernel 2.6
Low 192.168.0.14 22 tcp Linux Kernel 2.6
Low 192.168.0.14 2322 tcp Linux Kernel 2.6
Medium 192.168.0.18 443 tcp Linux Kernel 2.6
Medium 192.168.0.18 4343 tcp Linux Kernel 2.6
Low 192.168.0.18 22 tcp Linux Kernel 2.6
Low 192.168.0.18 2322 tcp Linux Kernel 2.6
Medium 192.168.0.20 443 tcp Linux Kernel 2.6
Medium 192.168.0.20 4343 tcp Linux Kernel 2.6
Low 192.168.0.20 22 tcp Linux Kernel 2.6
Low 192.168.0.20 2322 tcp Linux Kernel 2.6
Medium 192.168.0.22 443 tcp Linux Kernel 2.6
Medium 192.168.0.22 4343 tcp Linux Kernel 2.6
Low 192.168.0.22 22 tcp Linux Kernel 2.6
Low 192.168.0.22 2322 tcp Linux Kernel 2.6
Medium 192.168.0.29 443 tcp Linux Kernel 2.6
Medium 192.168.0.29 4343 tcp Linux Kernel 2.6
Low 192.168.0.29 22 tcp Linux Kernel 2.6
Low 192.168.0.29 2322 tcp Linux Kernel 2.6
Medium 10.10.110.107 443 tcp Linux Kernel 2.6
Medium 10.10.110.107 4343 tcp Linux Kernel 2.6
Low 10.10.110.107 22 tcp Linux Kernel 2.6
Low 10.10.110.107 2322 tcp Linux Kernel 2.6
Medium 10.10.110.147 443 tcp Linux Kernel 2.6
Medium 10.10.110.147 4343 tcp Linux Kernel 2.6
Low 10.10.110.147 22 tcp Linux Kernel 2.6
Low 10.10.110.147 2322 tcp Linux Kernel 2.6
Medium 10.10.110.226 443 tcp Linux Kernel 2.6
Medium 10.10.110.226 4343 tcp Linux Kernel 2.6
Low 10.10.110.226 22 tcp Linux Kernel 2.6
Low 10.10.110.226 2322 tcp Linux Kernel 2.6
Medium 10.10.137.10 443 tcp Linux Kernel 2.6
Medium 10.10.137.10 4343 tcp Linux Kernel 2.6
Low 10.10.137.10 22 tcp Linux Kernel 2.6
Low 10.10.137.10 2322 tcp Linux Kernel 2.6
Medium 10.10.137.77 443 tcp Linux Kernel 2.6
Medium 10.10.137.77 4343 tcp Linux Kernel 2.6
Low 10.10.137.77 22 tcp Linux Kernel 2.6
Low 10.10.137.77 2322 tcp Linux Kernel 2.6
Medium 10.10.137.80 443 tcp Linux Kernel 2.6
Medium 10.10.137.80 4343 tcp Linux Kernel 2.6
Low 10.10.137.80 22 tcp Linux Kernel 2.6
Low 10.10.137.80 2322 tcp Linux Kernel 2.6
Medium 10.10.143.146 21 tcp Linux Kernel 2.6
Medium 10.10.143.146 443 tcp Linux Kernel 2.6
Medium 10.10.143.146 1883 tcp Linux Kernel 2.6
Medium 10.10.143.146 9998 tcp Linux Kernel 2.6
Name of the Vulnerability Synopsis
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSL Certificate Cannot Be Trusted The SSL certificate for this servi
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
SSH Server CBC Mode Ciphers Enabled The SSH server is configured to
TLS Version 1.0 Protocol Detection The remote service encrypts traff
TLS Version 1.0 Protocol Detection The remote service encrypts traff
TLS Version 1.0 Protocol Detection The remote service encrypts traff
TLS Version 1.0 Protocol Detection The remote service encrypts traff
Description Solution
The server's X.509 certificate cannot bePurchase
trusted. This
or generate
situationacan
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust
trusted. This can
or generate be
situationacan
proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker cipher
to recover
The server's X.509 certificate cannot bePurchase encryption,
the plaintext
and
or generate
trusted. This enable
message
situationacan CTR or GCM cipher mode encryption.
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust can
or generate
trusted. This be
situationacan
proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker cipher
to recover
The server's X.509 certificate cannot bePurchase encryption,
the plaintext
and
or generate
trusted. This enable
message
situationacan CTR or GCM cipher mode encryption.
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust can
or generate
trusted. This be
situationacan
proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker cipher
to recover
The server's X.509 certificate cannot bePurchase encryption,
the
trusted. This plaintext
and enable
message
situationacan
or generate CTR or GCM cipher mode encryption.
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust
trusted. This can be
situationacan
or generate proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker cipher
to recover
The server's X.509 certificate cannot bePurchase encryption,
the
trusted. This plaintext
and enable
message
situationacan
or generate CTR or GCM cipher mode encryption.
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust
trusted. This can be
situationacan
or generate proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker cipher
to recover
The server's X.509 certificate cannot bePurchase encryption,
the
trusted. This plaintext
and
or generate enable
message
situationacan CTR or GCM cipher mode encryption.
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust
trusted. This can
or generate be
situationacan
proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker cipher
to recover
The server's X.509 certificate cannot bePurchase encryption,
the plaintext
and
or generate
trusted. This enable
message
situationacan CTR or GCM cipher mode encryption.
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust can
or generate
trusted. This be
situationacan
proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker cipher
to recover
The server's X.509 certificate cannot bePurchase encryption,
the plaintext
and
or generate
trusted. This enable
message
situationacan CTR or GCM cipher mode encryption.
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust can
or generate
trusted. This be
situationacan
proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker cipher
to recover
The server's X.509 certificate cannot bePurchase encryption,
the
trusted. This plaintext
and enable
message
situationacan
or generate CTR or GCM cipher mode encryption.
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust
trusted. This can be
situationacan
or generate proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker cipher
to recover
The server's X.509 certificate cannot bePurchase encryption,
the
trusted. This plaintext
and enable
message
situationacan
or generate CTR or GCM cipher mode encryption.
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust
trusted. This can be
situationacan
or generate proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker cipher
to recover
The server's X.509 certificate cannot bePurchase encryption,
the
trusted. This plaintext
and
or generate enable
message
situationacan CTR or GCM cipher mode encryption.
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust
trusted. This can
or generate be
situationacan
proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker cipher
to recover
The server's X.509 certificate cannot bePurchase encryption,
the
trusted. This plaintext
and
or generate enable
message
situationacan CTR or GCM cipher mode encryption.
proper SSL certificate for this service.
occur in three different ways, in which the chain
The server's X.509 certificate cannot bePurchase of trust can
or generate
trusted. This be
situationacan
proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContactchain of
Cipher Blocktrust
the vendorcan
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. This may allow an attacker cipher
to recover
encryption,
the plaintext
and enable
message
CTR or GCM cipher mode encryption.
The SSH server is configured to supportContactCipher Block
the vendor
Chainingor consult
(CBC) product documentation to disable CBC mode
encryption. This may allow an attacker cipher
to
The server's X.509 certificate cannot bePurchaserecover
encryption,
the
trusted. This plaintext
or generate and enable
situationacanmessage
proper CTR
SSL or GCM cipher
certificate mode
for this encryption.
service.
occur in three
The server's different
X.509 ways,cannot
certificate in which
bethe chain This
Purchase
trusted. of
or trust can be
generate
situation acan
proper SSL certificate for this service.
occur in three different ways, in which the
The SSH server is configured to supportContact chain of
Cipher Block trust
the vendor can
Chaining be
or consult
(CBC) product documentation to disable CBC mode
encryption. Thisis may
The SSH server allow an
configured toattacker
supportcipher
to recover
Contact
Cipherencryption,
thethe
Block plaintext
vendor and
Chaining enable
message
or consult
(CBC) CTR or GCM
product cipher modetoencryption.
documentation disable CBC mode
encryption. This may allow an attacker
The remote service accepts connectionsEnable cipher
to recover
encryption,
the
support
encrypted plaintext
using and
forTLS enable
message
TLS1.0.
1.2TLS CTR
and1.0 or
1.3,has
andGCM cipher mode encryption.
a disable support for TLS 1.0.
number of cryptographic design flaws.
The remote service accepts connectionsEnableModern implementations
support
encrypted usingforTLS
TLS1.0. of
1.2TLS TLS
and1.01.0
1.3,has
anda disable support for TLS 1.0.
number of cryptographic design flaws.
The remote service accepts connectionsEnableModern implementations
support
encrypted usingforTLS
TLS1.0. of
1.2TLS TLS
and1.01.0
1.3,has
anda disable support for TLS 1.0.
number of cryptographic
The remote service accepts design flaws. Modern
connections Enable implementations
support
encrypted usingforTLS 1.2of
TLS1.0. TLS
and
TLS 1.0
1.3,
1.0 and
has a disable support for TLS 1.0.
number of cryptographic design flaws. Modern implementations of TLS 1.0
o disable CBC mode
oencryption.
disable CBC mode
encryption.

o disable CBC mode


oencryption.
disable CBC mode
encryption.

o disable CBC mode


oencryption.
disable CBC mode
encryption.

o disable CBC mode


oencryption.
disable CBC mode
encryption.

o disable CBC mode


oencryption.
disable CBC mode
encryption.

o disable CBC mode


oencryption.
disable CBC mode
encryption.

o disable CBC mode


oencryption.
disable CBC mode
encryption.

o disable CBC mode


oencryption.
disable CBC mode
encryption.

o disable CBC mode


oencryption.
disable CBC mode
encryption.

o disable CBC mode


oencryption.
disable CBC mode
encryption.

o disable CBC mode


oencryption.
disable CBC mode
encryption.

o disable CBC mode


encryption.
o disable CBC mode
encryption.

o disable CBC mode


oencryption.
disable CBC mode
encryption.

You might also like