Tenable Network Security Podcast Episode 121 - "Enterprise Netstat, OS X Trojans"
by Paul Asadoorian on April 24, 2012
Announcements
- Tenable Selected for DISA’s ACAS Vulnerability Management Solution
- Check out our video channel on YouTube which contains new Nessus and SecurityCenter 4 tutorials.
- We're hiring! - Visit the Tenable website for more information about open positions.
- You can subscribe to the Tenable Network Security Podcast on iTunes!
- Tenable Tweets - You can find us on Twitter at http://twitter.com/tenablesecurity where we make product and company announcements, provide Nessus plugin statistics, and more!
- Want to ask questions about Nessus, SecurityCenter, LCE, and PVS and get answers from the experts at Tenable? Join Tenable's Discussion Forum for custom scripts, announcements, and more!
New & Notable Plugins
- Netstat Active Connections - Active connections are enumerated via the 'netstat' command.
- SSL Resume With Different Cipher Issue - I just can't help but wonder how many times we can poke holes in SSL. The protocol does not breed much confidence, and I'm curious if we will ever see a replacement.
- Citrix XenServer vSwitch Controller < 2.0.0+build11349 Multiple Vulnerabilities - While VMware clearly has a lion's share of the market, there are several other virtulization vendors in the market. Whatever platform you choose, security has to be one of the top priorities as reliability and integrity of your virtualization platform is of the utmost importance.
- HP System Management Homepage < 7.0 Multiple Vulnerabilities - Not only did HP miss a CSRF vulnerability, but they bundled in a vulnerable version of Apache, PHP, and OpenSSL. This is unacceptable.A company this large, producing the amount of software they do, must have a better process for securing software.
- Mac OS X OSX/Sabpab Trojan Detection - Make sure you are running this plugin often against your OS X hosts. They could be infected with new variants or become re-infected from a Time Machine backup.
IBM Tivoli Directory Server Web Administration Tool Unspecified XSS - More XSS in enterprise management applications.