Sunday 13 April 2008 - 646 read - ( Keywords : Penetration testing & Ethical Hacking , Saint , Vulnerability Scanner )
SAINT is the Security Administrator’s Integrated Network Tool. It is used to non-intrusively detect security vulnerabilities on any remote target, including servers, workstations, networking devices, and other types of nodes. It will also gather information such as operating system types and open ports. The SAINT graphical user interface provides access to SAINT’s data management, scan configuration, scan scheduling, and data analysis capabilities through a web browser. Different aspects of the scan results are presented in hyperlinked HTML pages, and reports on complete scan results can be generated and savedNew feature in 6.7.7::
Configuration options to customize password policy checks:
Password length - the required number of characters in the password
Password history - number of previous passwords which cannot be re-used
Maximum Age - days after which the user must change the password
Minimum Age - days before which the user cannot change the password
Lockout - the number of failed logins before the account is locked out
New vulnerability checks in version 6.7.7:
cumulative Internet Explorer vulnerability (MS08-024)
GDI remote code execution vulnerability (MS08-021)
CUPS
Firefox, Thunderbird and SeaMonkey
Novell eDirectory LDAP DelRequest Message Handling Buffer Overflow
Asterisk vulnerabilities
Ruby
Acrobat Reader Linux vulnerability
OpenSSH
Java Web Start vulnerabilities
Internet Explorer vulnerabilities involving setRequestHeader
additional Aurigma vulnerabilities
ASUS Remote Console DPC Proxy Service Buffer Overflow
solidDB vulnerabilities
McAfee ePolicy Orchestrator Framework Services HTTP Buffer Overflow
Cisco IOS vulnerabilities
HP OpenView Network Node Manager HTTP Handling Buffer Overflow
OpenVMS ssh
QuickTime vulnerabilities
Opera vulnerabilities
Macrovision InstallShield OCI Untrusted Library Loading Vulnerability
phpMyAdmin vulnerability
Lighttpd
Wireshark
Asterisk Invalid RTP Payload Type Number Memory Corruption
Windows DNS Spoofing vulnerability (MS08-020)
hxvz.dll ActiveX vulnerability (MS08-023)
Microsoft Project vulnerability (MS08-018)
Windows kernel user mode callback vulnerability (MS08-025)
Visio vulnerabilities (MS08-019)
VBScript and JScript engine script decoding vulnerability (MS08-022)
New exploits in this version:
Solaris rpc.ypupdated exploit
MDaemon IMAP FETCH exploit
Microsoft Office memory corruption exploit
Cisco UCP CSuserCGI.exe exploit
POSTSCRIPTUM
COMPLIANCE MANDATES
Penetration testing & Ethical Hacking : PCI DSS 11.3, SOX A13.3, GLBA 16 CFR Part 314.4 (c), HIPAA 164.308(a)(8), FISMA RA-5, SI-2, ISO 27001/27002 12.6, 15.2.2
Vulnerability Scanner : PCI DSS 11.2, 6.6, SOX A13.3, GLBA 16CFR Part 314.4(c), HIPAA 164.308(a)(8), FISMA RA-5, SI-2, ISO 27001-27002 12.6, 15.2.2RELATED ARTICLES
Penetration testing & Ethical Hacking,
Saint,
Vulnerability Scanner,
15 April 2010 : SAINT® 7.3.3 Released
9 April 2010 : SARA-7.9.2a the final version released
1 April 2010 : SAINT® v7.3.2 Released
16 March 2010 : Saint Vulnerability Scanner v7.3 on the wild
27 February 2010 : Saint Vulnerability Scanner and Exploiter v7.2.7 released
Security Dashboard







