23
WinMX detection
Peer-to-Peer
2003/11/13
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.5
Corrected the trigger pattern in version 1.4 so the plugin should work now very well. Corrected the plugin structure and added the accuracy values in 1.5
tcp
6699
open|sleep|close|pattern_exists *
88
This plugin is experimental. Please verify the flaw with another security scanner (e.g. Nessus). Plugin version 1.2 seems to be as accurate as like the Nessus plugin is.
WinMX peer-to-peer clients
Configuration
WinMX is a peer-to-peer software to sharing files. An open port tcp/6699 and response after establishing the connection may indicate the existence of the utility. This kind of software may be illegal in the environment.
Disable the WinMX software if not allowed nor needed. If it should run then filter incoming traffic on port tcp/6699 to prevent unwanted access to the web service.
15 minutes
Yes
Yes
Yes
Medium
6
4
4
4
Low
Nessus is able to do the same check more accurate.
11847
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch