diff --git a/.gitignore b/.gitignore index 66f9c9a..783c53a 100644 --- a/.gitignore +++ b/.gitignore @@ -2,3 +2,5 @@ venv/ dump.rdb **/__pycache__ .DS_Store +reports/ +**/reports/*.html diff --git a/reports/report-e168ed57-2020-09-16.html b/reports/report-e168ed57-2020-09-16.html deleted file mode 100644 index 2a1a70f..0000000 --- a/reports/report-e168ed57-2020-09-16.html +++ /dev/null @@ -1,1282 +0,0 @@ - - - - - - - - -
-

NERVE 2.4.3

-
-

Overview

-
- -
- - - - - - - - - - - - - - - - - - - - - -
TIMESTAMP2020-09-16 21:28:27
ID9CACC065
NAMEDefault
ENGINEERDefault
SOURCE IP127.0.0.1
-
- -
- - - - - - - - - - - - - - - - - - - - - - - - -
CRITICAL0
HIGH4
MEDIUM2
LOW7
INFO19
-
- - -
- -

Vulnerabilities

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
SVC_Z115Checks for SMB Ports
TITLEChecks for SMB Ports
FINDINGSRemote Server Exposes SMB Port(s)
ADDRESS192.168.0.1
PORT445
DETAILSOpen Port: 445 (SMB)
MITIGATIONBind all possible network services to localhost, and configure only those which require remote clients on an external interface.
CFG_FOQWChecks if SSH password authentication is supported
TITLEChecks if SSH password authentication is supported
FINDINGSRemote Server Supports SSH Passwords
ADDRESS192.168.0.10
PORT22
DETAILSDropbear sshd
MITIGATIONSSH Allows Password authentication, this is considered bad security practice. -SSH Key based authentication should be enabled on the server, and passwords should be disabled.
SVC_6509Checks for Remote Management Ports
TITLEChecks for Remote Management Ports
FINDINGSRemote Server Exposes Administration Port(s)
ADDRESS192.168.0.10
PORT22
DETAILSOpen Port: 22 (SSH)
MITIGATIONBind all possible services to localhost, and confirm only those which require remote clients are allowed remotely.
SVC_6509Checks for Remote Management Ports
TITLEChecks for Remote Management Ports
FINDINGSRemote Server Exposes Administration Port(s)
ADDRESS192.168.0.1
PORT139
DETAILSOpen Port: 139 (NetBIOS)
MITIGATIONBind all possible services to localhost, and confirm only those which require remote clients are allowed remotely.
VLN_SKKFChecks for password forms in HTTP
TITLEChecks for password forms in HTTP
FINDINGSUnencrypted Login Form
ADDRESS192.168.0.10
PORT80
DETAILSLogin Page over HTTP
MITIGATIONWebsite login form should be done over SSL.
SVC_0C1ZChecks for Rare Ports
TITLEChecks for Rare Ports
FINDINGSRemote Server Exposes Rare Port(s)
ADDRESS192.168.0.14
PORT9999
DETAILSOpen Port: 9999 (distinct)
MITIGATIONBind all possible network services to localhost, and configure only those which require remote clients on an external interface.
SVC_ZGZAChecks for HTTP Ports
TITLEChecks for HTTP Ports
FINDINGSRemote Server Exposes HTTP Port(s)
ADDRESS192.168.0.10
PORT80
DETAILSOpen Port: 80 (HTTP)
MITIGATIONBind all possible network services to localhost, and configure only those which require remote clients on an external interface.
DSC_A4F1Checks if a Web Panel is exposed
TITLEChecks if a Web Panel is exposed
FINDINGSIdentified a Known Web Panel
ADDRESS192.168.0.1
PORT80
DETAILSGeneric Indicator: "Login" (Login Page)
MITIGATIONIdentify whether the application in question is supposed to be exposed to the local network.
DSC_A4F1Checks if a Web Panel is exposed
TITLEChecks if a Web Panel is exposed
FINDINGSIdentified a Known Web Panel
ADDRESS192.168.0.1
PORT443
DETAILSGeneric Indicator: "Login" (Login Page)
MITIGATIONIdentify whether the application in question is supposed to be exposed to the local network.
SVC_ZGZAChecks for HTTP Ports
TITLEChecks for HTTP Ports
FINDINGSRemote Server Exposes HTTP Port(s)
ADDRESS192.168.0.1
PORT80
DETAILSOpen Port: 80 (HTTP)
MITIGATIONBind all possible network services to localhost, and configure only those which require remote clients on an external interface.
DSC_A4F1Checks if a Web Panel is exposed
TITLEChecks if a Web Panel is exposed
FINDINGSIdentified a Known Web Panel
ADDRESS192.168.0.10
PORT80
DETAILSGeneric Indicator: "Login" (Login Page)
MITIGATIONIdentify whether the application in question is supposed to be exposed to the local network.
SVC_ZGZAChecks for HTTP Ports
TITLEChecks for HTTP Ports
FINDINGSRemote Server Exposes HTTP Port(s)
ADDRESS192.168.0.14
PORT8080
DETAILSOpen Port: 8080 (HTTP)
MITIGATIONBind all possible network services to localhost, and configure only those which require remote clients on an external interface.
SVC_ZGZAChecks for HTTP Ports
TITLEChecks for HTTP Ports
FINDINGSRemote Server Exposes HTTP Port(s)
ADDRESS192.168.0.1
PORT443
DETAILSOpen Port: 443 (HTTP)
MITIGATIONBind all possible network services to localhost, and configure only those which require remote clients on an external interface.
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.10
PORT80
DETAILSMissing Security Header: content-security-policy
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.10
PORT80
DETAILSMissing Security Header: x-xss-protection
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.10
PORT80
DETAILSMissing Security Header: x-frame-options
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.14
PORT8080
DETAILSMissing Security Header: content-security-policy
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.1
PORT443
DETAILSMissing Security Header: x-frame-options
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.14
PORT8080
DETAILSMissing Security Header: x-xss-protection
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.10
PORT80
DETAILSMissing Security Header: x-content-type-options
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.1
PORT443
DETAILSMissing Security Header: content-security-policy
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_DFFFChecks if CORS Headers support Wildcard Origins
TITLEChecks if CORS Headers support Wildcard Origins
FINDINGSWebserver is allowing all domains in CORS
ADDRESS192.168.0.14
PORT8080
DETAILSAccess-Control-Allow-Origin is set to: *
MITIGATIONConsider hardening your CORS Policy to define specific Origins
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.14
PORT8080
DETAILSMissing Security Header: x-content-type-options
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.1
PORT443
DETAILSMissing Security Header: referrer-policy
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.10
PORT80
DETAILSMissing Security Header: strict-transport-security
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.14
PORT8080
DETAILSMissing Security Header: x-frame-options
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.10
PORT80
DETAILSMissing Security Header: referrer-policy
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.14
PORT8080
DETAILSMissing Security Header: strict-transport-security
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.14
PORT8080
DETAILSMissing Security Header: referrer-policy
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.1
PORT443
DETAILSMissing Security Header: x-content-type-options
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.1
PORT443
DETAILSMissing Security Header: strict-transport-security
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
CFG_BS0FChecks if Security Headers exist
TITLEChecks if Security Headers exist
FINDINGSWebserver is missing Security Headers
ADDRESS192.168.0.1
PORT443
DETAILSMissing Security Header: x-xss-protection
MITIGATIONConsider using security headers for your server. https://www.keycdn.com/blog/http-security-headers
- - - - - \ No newline at end of file