23 WinMX detection Peer-to-Peer 2003/11/13 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.5 Corrected the trigger pattern in version 1.4 so the plugin should work now very well. Corrected the plugin structure and added the accuracy values in 1.5 tcp 6699 open|sleep|close|pattern_exists * 88 This plugin is experimental. Please verify the flaw with another security scanner (e.g. Nessus). Plugin version 1.2 seems to be as accurate as like the Nessus plugin is. WinMX peer-to-peer clients Configuration WinMX is a peer-to-peer software to sharing files. An open port tcp/6699 and response after establishing the connection may indicate the existence of the utility. This kind of software may be illegal in the environment. Disable the WinMX software if not allowed nor needed. If it should run then filter incoming traffic on port tcp/6699 to prevent unwanted access to the web service. 15 minutes Yes Yes Yes Medium 6 4 4 4 Low Nessus is able to do the same check more accurate. 11847 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.computec.ch