146 Microsoft Windows Telnet Server detection Backdoors 2004/09/06 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.2 Corrected the plugin structure and added the accuracy values in 1.2 tcp 23 open|sleep|close|pattern_exists Welcome to Microsoft Telnet Server OR ÿý%ÿûÿûÿý'ÿýÿý 97 This plugin was written with the ATK Attack Editor. I don't know if the rubbish is saved as secondary pattern does really identify Microsofts Telnet service. Need to be verified. Microsoft Windows Telnet Daemon Other telnet daemons Configuration The target host is running a Telnet server by Microsoft Windows. This can be determined by the welcome banner of the application. An attacker may get additional data about the target. Also telnet connections are not encrypted and usually authenticated via simple username/password credentials. The telnet service, if not needed, should be disabled or if possible firewalled. Upgrade to the latest software version to be not vulnerable anymore. A server daemon should not advertise its version to the world. So disable or change the banner. To get more security, install SSH. Approx. 45 minutes Yes http://www.nessus.org Yes Yes Medium 7 8 6 7 Most vulnerability scanners are able to do a similar check. Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.computec.ch