Forums: Checking Veritas Backup Exec For Vuln ? - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Checking Veritas Backup Exec For Vuln ?

#1 User is offline   NeBoKaDnEzZaR 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 49
  • Joined: 11-March 04

Posted 16 July 2005 - 03:37 PM

HI out there

I searched Forum and also Google but doesnt found a vuln checker for Veritas Backup Exec. Does anybody know if there is one out ??

THX
0

#2 User is offline   apoc_neo 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 113
  • Joined: 17-September 04

Posted 16 July 2005 - 07:16 PM

There isn't realy a checker but what you do is scan for port 6101 then use the autohacker that FLX made it is posted in the downloads section so you should be able to find it.

Edit: Here is the link for the autohacker http://www.governmen...showtopic=13414

This post has been edited by apoc_neo: 16 July 2005 - 07:19 PM

0

#3 User is offline   NeBoKaDnEzZaR 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 49
  • Joined: 11-March 04

Posted 16 July 2005 - 09:27 PM

apoc_neo, on Jul 17 2005, 03:16 AM, said:

There isn't realy a checker but what you do is scan for port 6101 then use the autohacker that FLX made it is posted in the downloads section so you should be able to find it.

Edit: Here is the link for the autohacker http://www.governmen...showtopic=13414



HI apoc_neo

First thank you for the reply.
Maybe im wrong please tell me if !!
I read that i have to scan port 10000.
Does i got false infos ?
"Veritas Backup Exec Windows Remote Agent Overflow"

????
0

#4 User is offline   slb33 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 146
  • Joined: 30-August 03

Posted 16 July 2005 - 10:25 PM

There are 2 different exploits for veritas.
I believe apoc_neo is talking about the older one.
The newer one does use the port that you specified but I haven't heard of any checker for it and it is probably dead by now since it's been out for a while now.

Unless of course you haven't updated your servers with the newer versions of veritas! :blink:
0

#5 User is offline   sz0n 

  • Private
  • Icon
  • Group: Members
  • Posts: 12
  • Joined: 19-June 05

Posted 16 July 2005 - 11:58 PM

just make a simple ban check for port 10000. In dfind vuln ip will have banner like this , or if you check banners by sl they will look like this: [$ B ,]. After this you can get more precise infos using check command in metasploit.
0

#6 User is offline   nolimit 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 387
  • Joined: 27-January 04

Posted 17 July 2005 - 06:23 PM

or you could fuzz/dissemble and look for a new one
0

#7 User is offline   L0rD 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 30
  • Joined: 21-March 04

Posted 19 July 2005 - 07:23 AM

HelloW,

If I don't make a mistake, I think that metasploit can check vulnerable workstations after you scan the ports

c ya :ph34r:
0

#8 User is offline   slb33 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 146
  • Joined: 30-August 03

Posted 19 July 2005 - 09:31 AM

I think what he is really looking for is a way to detect the vulnerable ones and not just what version of remote agent it is.
As far as I know there is no scanner that will tell you if it's vulnerable or not.
You just have to check it with metasploit to see if it's really vulnerable.
0

#9 User is offline   sz0n 

  • Private
  • Icon
  • Group: Members
  • Posts: 12
  • Joined: 19-June 05

Posted 19 July 2005 - 12:23 PM

lol guys i wrote it in my previous post, just check the banners, however this vuln is already dead
0

#10 User is offline   apoc_neo 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 113
  • Joined: 17-September 04

Posted 19 July 2005 - 02:21 PM

just use scanline that will work.
0

#11 User is offline   slb33 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 146
  • Joined: 30-August 03

Posted 19 July 2005 - 05:42 PM

Yea, I use scanline myself since this exploit came out to check the banners.
I was only stating that just because you get the correct banner doesn't mean that it is vulnerable.
Most of these are now patched and not vulnerable but the still show the same kind of banner!
0

#12 User is offline   andi1983 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 24
  • Joined: 02-July 05

Posted 21 July 2005 - 12:11 AM

NeBoKaDnEzZaR, on Jul 16 2005, 11:37 PM, said:

HI out there

I searched Forum and also Google but doesnt found a vuln checker for Veritas Backup Exec. Does anybody know if there is one out ??

THX



just do a banner scan and check ips with banner with the exploit, so i did it.
scans without banned dont worked
0

#13 User is offline   NeBoKaDnEzZaR 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 49
  • Joined: 11-March 04

Posted 22 July 2005 - 08:00 PM

Thank you @ all

I tested it with bannerscann an metasploit. Looks like the whole network here is fine. Nice to know :D THX.
0

#14 User is offline   re_tlp21 

  • Private
  • Icon
  • Group: Members
  • Posts: 3
  • Joined: 08-July 05

Posted 13 August 2005 - 02:53 AM

I wanted to use Nmap to check the banner, but how can you define threads in Nmap. If i would use it like this
--max_hostgroup 150 --min_hostgroup 100 --max_parallelism 200 --min_par
allelism 50 192.168.1.*

for example, it still cheks only one ip at the same time.

thanks
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting