Your Company Scan Results - April 2008

Global PCI Status: FAILED

Westpoint has determined that Your Company is NOT COMPLIANT with the PCI scan validation requirement.

 21
 26
 16
 15
 19
 1
 4
High risk vulnerabilities found.
Medium risk vulnerabilities found.
Low risk vulnerabilities found.
SANS vulnerabilities found.
New vulnerabilities found.
Urgent vulnerabilities found.
Overdue vulnerabilities found.
 9
 3
 0
 9
 12
 8
 1
 3
Systems (45%) had high risk vulnerabilities.
Systems (15%) had medium risk vulnerabilities.
Systems (0%) had low risk vulnerabilities.
Systems (45%) had SANS vulnerabilities.
Systems (60%) failed PCI criteria.
Systems (40%) passed PCI criteria.
Systems (5%) had urgent vulnerabilities.
Systems (15%) had overdue vulnerabilities.
Scan Type
Start Date
End Date
Systems Scanned
New Systems
Enterprise
13-Apr-08 11:54
13-Apr-08 21:31
20
2

Key Increase No change DecreaseHigh RiskMedium RiskLow RiskNo ServicesNo Ports/VulnsNot Subnet ScannedPCI Mapping

Filter Hosts: 

 

Systems

Download As CSV...
Download As PDF...
Host NameIP AddressCriticalReportPortsVulnerabilities 
www.your_company.nl  FAIL   SANS192.168.0.103View711 (5 New)
www.yourcompany.co.uk  FAIL192.168.0.100View59 (5 New)
www.example.com  FAIL   SANS192.168.0.112View311 (4 New)
mail.example.com  FAIL   SANS   URGENT192.168.0.111View85
dns0.example.com  FAIL   SANS   OVERDUE192.168.0.110View54
sql1.manc.yourcompany.com  FAIL   SANS   OVERDUE192.168.1.52View34
sql2.manc.yourcompany.com  FAIL   SANS192.168.1.53View24
www.yourcompany.com  FAIL   NEW192.168.0.101View122 (2 New)
www.your_company.fr  FAIL   SANS192.168.0.105View53 (3 New)
www.yourcompany.net  FAIL   SANS192.168.0.102View25
apollo.example.com  FAIL   SANS   OVERDUE192.168.0.81View33
www.yourcompany.com.my  FAIL192.168.0.106View22
www1.manc.yourcompany.com  PASS192.168.1.54View20
www2.manc.yourcompany.com  PASS192.168.1.55View20
mail1.manc.yourcompany.com  PASS192.168.1.50View10
mail2.manc.yourcompany.com  PASS192.168.1.51View10
192.168.0.104  PASS192.168.0.104View20
gopher.example.com  PASS192.168.0.93View00
192.168.100.9  PASS   NEW192.168.100.9 View10
laptop.yourcompany.com  PASS192.168.0.57 View00

All Vulnerabilities

FrequencyVulnerabilitySeverity 
6High Risk Ports OpenHigh Risk
3SNMP Default Community Names   SANSHigh Risk
1IIS WebDAV Buffer OverrunHigh Risk
1MySQL Database Accessible Without Password   OVERDUEHigh Risk
1Administration Interface with Weak Password   NEWHigh Risk
1Possible Compromise   NEWHigh Risk
1BIND < 8.2.3 Buffer Overrun   SANS   OVERDUEHigh Risk
1Authentication Bypass Through Cookie Manipulation   NEWHigh Risk
1Apache < 1.3.26 Chunked Encoding Vulnerability   SANSHigh Risk
1IIS ASP.NET Application Trace Enabled   NEWHigh Risk
1Sendmail < 8.12.8 Buffer Overrun   SANS   URGENTHigh Risk
1Sensitive Information Leakage   NEWHigh Risk
1Script Appears Vulnerable to SQL Injection   NEWHigh Risk
1Script Allows Arbitrary Command Execution   NEWHigh Risk
2Apache < 1.3.27 Multiple VulnerabilitiesMedium Risk
2Cross-Site ScriptingMedium Risk
2Globally Useable Name Server   SANSMedium Risk
2MySQL < 3.23.58, 4.0.15 Password Overflow   SANSMedium Risk
2MySQL < 3.23.56 Privilege Escalation   SANSMedium Risk
1OpenSSH < 3.6.1p2 PAM Timing AttackMedium Risk
1Lotus Domino < 5.0.9 Database Lock DoSMedium Risk
1MySQL < 3.23.55 Multiple Vulnerabilities   SANSMedium Risk
1SMTP Server Allows VRFY/EXPNMedium Risk
1Script Allows Arbitrary Redirection   NEWMedium Risk
1Apache < 1.3.31, 2.0.49 Multiple Vulnerabilities   SANSMedium Risk
1XPath Injection   NEWMedium Risk
1Lotus Domino Anonymous Database AccessMedium Risk
1OpenSSL < 0.9.6m, 0.9.7d Multiple Vulnerabilities   SANSMedium Risk
1Weak or Ineffective Authentication Mechanism   NEWMedium Risk
1SSL Certificate Problems   NEWMedium Risk
1Apache mod_ssl < 2.8.10 off by one VulnerabilityMedium Risk
1IIS .printer ISAPI Filter EnabledMedium Risk
1IIS global.asa AccessibleMedium Risk
1DNS Zone Transfer   OVERDUEMedium Risk
1Service Permits Unauthenticated Users to Send Arbitrary Emails   NEWMedium Risk
3TRACE and/or TRACK Methods EnabledLow Risk
3Holes Detected in Firewall ConfigurationLow Risk
2SSH Protocol Version 1 EnabledLow Risk
2Apache < 1.3.29 Multiple Local FlawsLow Risk
1NTP Information Leakage   NEWLow Risk
1DNS Cache SnoopingLow Risk
1Apache mod_userdir Information LeakLow Risk
1Microsoft Frontpage Extensions InstalledLow Risk
1Private IP Address LeakageLow Risk
1Script Calling phpinfo() Detected   OVERDUELow Risk

This report was generated by a PCI Approved Scanning Vendor, Westpoint Ltd., under certificate number 3974-01-03, within the guidelines of the PCI data security initiative.

A mapping between the Westpoint vulnerability severity levels and those of the PCI documentation is provided in the glossary.

Scans by Sec52