Re: "SSL Server Allows Anonymous Authentication Vulnerability"



First you need to work out what the vulnerability description actually means.

Some third party product has some unique way of describing a possible weakness or risk. You need to understand what this is, so you can explain it to us in technological terms.

Cheers
Ken


"criechton" <criechton@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:0F64DFD7-9B3F-43D0-922B-ACA552B60023@xxxxxxxxxxxxxxxx
I have two windows 2003/IIS 6.0 servers that are load balanced thru an F5
networks device, an ISS security scan of the URL that is shared by the two
servers is showing "SSL Server Allows Anonymous Authentication
Vulnerability". How do I address and remediate this vulnerability.


Thanks in advance.

.



Relevant Pages

  • Re: Risk Ranking...
    ... get his book The Tao of Network Security Monitoring. ... I had the same problem as you when I was trying to come up with some risk ... The vulnerability must be exploited locally. ... If a piece of malware is a blended threat (able to exploit multiple ...
    (Security-Basics)
  • Re: Risk metrics
    ... security management life cycle. ... more objective snapshot of a company's risk posture. ... > traditional risk metrics in pen-tests cannot be ... >> vulnerability works, and if an exploit is in the ...
    (Pen-Test)
  • Re: Spyware and RISC OS? Surely not?
    ... complacency might be placing you at increased risk. ... You have more than one bank account with more than one ... and appropriate to the vulnerability of the situation. ...
    (comp.sys.acorn.misc)
  • Re: Level of Exploitation
    ... But, for some companies, risk is ... Servers can always be replaced, reconfigured, updated and so one. ... Security Trends Report from Cenzic ... I think the Auditor's job is to assess vulnerability ...
    (Pen-Test)
  • Re: [Full-Disclosure] No Subject (re: openssh exploit code?)
    ... Now let's say you get a severe thunderstorm WATCH. ... not every vulnerability requires ... information and mitigating risk. ... delaying the fix, or even of not doing the fix at all sometimes. ...
    (Full-Disclosure)