-
Network Vulnerabilities
- IT-Grundschutz
- CD-ROM Autostart (Win)
- CD-ROM and FDDlocal User only access (Win)
- Check SSL on Apache
- Check Sendmail Configuration
- Check Sendmail Configuration over SSH
- Check accessrights of ps, finger, who, last and /var/log/?tmp*
- Check for SSIEnableCmdDirective at IIS (Win)
- Check for rlogin, rsh, rcp tools and configuration
- Check if DNS client is active and working
- Check if Disk Quota activated.
- Check if NTFS Access Control Lists and NTFS Alternate Data Streams supported
- Check if X11 tunnel in sshd_config is enabled, list 'xhost' rights
- Check if an TFTP Server is running and was start with -s Option
- Check login, sshd, gdm, xdm and kde PAM Config
- Check over WMI if Apache is installed (win)
- Check over WMI if IPSec Policy used for Windows (Win)
- Check security mechanisms for NFS
- Check the System if Opie-Server and Opie-Client installed
- Check write permissions of system-directorys
- Checks InternetExplorer Policy for Protected Mode over WMI (Win)
- Checks XP Internetcommunication of some Programs (Win)
- Checks over WMI, if hiberfile.sys exists (win)
- File and Folder ACL (Win)
- Find OS/2 and Posix Subsystem over WMI (win)
- Find Windows 2003 Client Funktionality over WMI (win)
- Find Windows Admin Tools over WMI if IIS installed (win)
- Find and list USB-Storage Modules, list pluged USB-Storage Devices.
- Get EFS Encrypted Files, Dirs and EFS-Encryption AlgorithmID (win)
- Get GnuPG and PGP Version and User they have an pubring (win)
- Get OS Version, OS Type, OS Servicepack and OS Name over WMI (win)
- Get Screensaver Status for ALL Users (Win)
- Get User without Password and User which have an PW and days since last Pasword change
- Get Windows Firewall Profile Status over WMI (win)
- Get Windows Terminal Server Settings
- Get all Windows Admin Users and Groups over WMI (win)
- Get all Windows Shares over WMI (win)
- Get all Windows non System Services, Service start modes and Eventlog Servicestate over WMI (win)
- IIS Metabase
- IIS Samplefiles and Scripte (Win)
- IT-Grundschutz: List reject Rule on Cisco Voip Devices over Telnet
- IT-Grundschutz: SSH and Telnet BruteForce attack
- Last Username (Win)
- List /etc/aliases
- List /var/adm and /lar/log accessrights, read /etc/rsylog.conf an /etc/syslog.conf
- List Files in Apache Script Alias Directorys over WMI (win)
- List Files with setuid-bit in / and /home, Check /tmp for sticky-bit
- List all Installed ODBC Driver over WMI (win)
- List an Verify umask entrys in /etc/profile and ~/.profile
- List executable and writable-executable Files, list path variable
- List iptables ruleset
- List time restriction in /etc/security/time.conf