Id |
Log ID |
Jvninfo Id |
Plugin ID |
CVE |
CVSS |
Risk |
Host |
Protocol |
Port |
Name |
Synopsis |
Description |
Solution |
See Also |
Plugin Output |
Actions |
9 |
19_tokyu_hikarie_20170118.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
119.75.229.147 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus497459490.html HTTP/1.1 Connection: Close Host: 119.75.229.147.brv.ne.jp Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Wed, 18 Jan 2017 02:15:24 GMT Server: Apache Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus497459490.html HTTP/1.1 Connection: Keep-Alive Host: 119.75.229.147.brv.ne.jp Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
5412 |
H28-MOJ-Online-Nara-16-seg-1-20161126-soga_ubl064.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.137.100 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus1173201860.html HTTP/1.1 Connection: Close Host: 172.27.137.100 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Sat, 26 Nov 2016 01:28:37 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus1173201860.html HTTP/1.1 Connection: Close Host: 172.27.137.100 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
5413 |
H28-MOJ-Online-Nara-16-seg-1-20161126-soga_ubl064.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.137.100 |
tcp |
443 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus1668962267.html HTTP/1.1 Connection: Close Host: 172.27.137.100 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.0 200 OK Date: Sat, 26 Nov 2016 01:28:37 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Content-Type: message/http TRACE /Nessus1668962267.html HTTP/1.1 Connection: Close Host: 172.27.137.100 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
6937 |
H28-MOJ-Online-Nara-16-seg-1-20161126-soga_ubl064.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.137.61 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus299503129.html HTTP/1.1 Connection: Close Host: 172.27.137.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Sat, 26 Nov 2016 01:28:20 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus299503129.html HTTP/1.1 Connection: Close Host: 172.27.137.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
6938 |
H28-MOJ-Online-Nara-16-seg-1-20161126-soga_ubl064.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.137.61 |
tcp |
443 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus787156680.html HTTP/1.1 Connection: Close Host: 172.27.137.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.0 200 OK Date: Sat, 26 Nov 2016 01:28:20 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Content-Type: message/http TRACE /Nessus787156680.html HTTP/1.1 Connection: Close Host: 172.27.137.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
9734 |
H28-MOJ-Online-Nara-16-seg-2-20161126-soga_e6g03u.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.137.62 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus29915179.html HTTP/1.1 Connection: Close Host: 172.27.137.62 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Sat, 26 Nov 2016 01:55:12 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus29915179.html HTTP/1.1 Connection: Close Host: 172.27.137.62 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
9735 |
H28-MOJ-Online-Nara-16-seg-2-20161126-soga_e6g03u.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.137.62 |
tcp |
443 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus766392723.html HTTP/1.1 Connection: Close Host: 172.27.137.62 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.0 200 OK Date: Sat, 26 Nov 2016 01:55:12 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Content-Type: message/http TRACE /Nessus766392723.html HTTP/1.1 Connection: Close Host: 172.27.137.62 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
18812 |
H28-MOJ-Teikyo-Nara-17-seg-1-20161128-w510.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.30.201.61 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus1631625430.html HTTP/1.1 Connection: Close Host: 172.30.201.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Mon, 28 Nov 2016 01:48:05 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus1631625430.html HTTP/1.1 Connection: Close Host: 172.30.201.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
18813 |
H28-MOJ-Teikyo-Nara-17-seg-1-20161128-w510.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.30.201.61 |
tcp |
443 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus885447978.html HTTP/1.1 Connection: Close Host: 172.30.201.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.0 200 OK Date: Mon, 28 Nov 2016 01:48:05 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Content-Type: message/http TRACE /Nessus885447978.html HTTP/1.1 Connection: Close Host: 172.30.201.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
29438 |
H28-MOJ-Online-Funa-12-seg-v1-161103.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.9.100 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus566643186.html HTTP/1.1 Connection: Close Host: 172.27.9.100 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Thu, 03 Nov 2016 00:58:04 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus566643186.html HTTP/1.1 Connection: Close Host: 172.27.9.100 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
29439 |
H28-MOJ-Online-Funa-12-seg-v1-161103.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.9.100 |
tcp |
443 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus467364639.html HTTP/1.1 Connection: Close Host: 172.27.9.100 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.0 200 OK Date: Thu, 03 Nov 2016 00:58:04 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Content-Type: message/http TRACE /Nessus467364639.html HTTP/1.1 Connection: Close Host: 172.27.9.100 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
30370 |
H28-MOJ-Online-Funa-12-seg-v1-161103.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.9.61 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus309921702.html HTTP/1.1 Connection: Close Host: 172.27.9.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Thu, 03 Nov 2016 00:58:12 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus309921702.html HTTP/1.1 Connection: Close Host: 172.27.9.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
30371 |
H28-MOJ-Online-Funa-12-seg-v1-161103.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.9.61 |
tcp |
443 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus2117161068.html HTTP/1.1 Connection: Close Host: 172.27.9.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.0 200 OK Date: Thu, 03 Nov 2016 00:58:12 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Content-Type: message/http TRACE /Nessus2117161068.html HTTP/1.1 Connection: Close Host: 172.27.9.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
32776 |
H28-MOJ-Online-Funa-12-seg-v2-161103.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.9.62 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus1339802698.html HTTP/1.1 Connection: Close Host: 172.27.9.62 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Thu, 03 Nov 2016 01:13:02 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus1339802698.html HTTP/1.1 Connection: Close Host: 172.27.9.62 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
32777 |
H28-MOJ-Online-Funa-12-seg-v2-161103.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.27.9.62 |
tcp |
443 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus1374930114.html HTTP/1.1 Connection: Close Host: 172.27.9.62 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.0 200 OK Date: Thu, 03 Nov 2016 01:13:02 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Content-Type: message/http TRACE /Nessus1374930114.html HTTP/1.1 Connection: Close Host: 172.27.9.62 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
45440 |
H28-MOJ-Teikyo-Yokohama-18-seg-02-21161121-abe_vilnov.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.30.138.61 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus1009331891.html HTTP/1.1 Connection: Close Host: 172.30.138.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Mon, 21 Nov 2016 03:35:17 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus1009331891.html HTTP/1.1 Connection: Close Host: 172.30.138.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
45441 |
H28-MOJ-Teikyo-Yokohama-18-seg-02-21161121-abe_vilnov.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
172.30.138.61 |
tcp |
443 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus1498599079.html HTTP/1.1 Connection: Close Host: 172.30.138.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.0 200 OK Date: Mon, 21 Nov 2016 03:35:17 GMT Server: Apache/2.2.15 (Red Hat) Connection: close Content-Type: message/http TRACE /Nessus1498599079.html HTTP/1.1 Connection: Close Host: 172.30.138.61 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
54155 |
nessus-scan-192-168-10-10#20170210#1.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
192.168.10.10 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus1403463481.html HTTP/1.1 Connection: Close Host: 192.168.10.10 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Sat, 11 Feb 2017 06:55:03 GMT Server: Apache/2.2.15 (CentOS) Connection: close Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus1403463481.html HTTP/1.1 Connection: Close Host: 192.168.10.10 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
54156 |
nessus-scan-192-168-10-10#20170210#1.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
192.168.10.10 |
tcp |
443 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus12504613.html HTTP/1.1 Connection: Close Host: 192.168.10.10 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.0 200 OK Date: Sat, 11 Feb 2017 06:55:03 GMT Server: Apache/2.2.15 (CentOS) Connection: close Content-Type: message/http TRACE /Nessus12504613.html HTTP/1.1 Connection: Close Host: 192.168.10.10 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
54447 |
1_Tokyu_remi_20170126.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
54.199.215.149 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus1040348985.html HTTP/1.1 Connection: Close Host: ec2-54-199-215-149.ap-northeast-1.compute.amazonaws.com Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Thu, 26 Jan 2017 01:24:14 GMT Server: Apache Connection: close Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus1040348985.html HTTP/1.1 Connection: Close Host: ec2-54-199-215-149.ap-northeast-1.compute.amazonaws.com Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|
55031 |
tokyu_12_bel-portal_20170116.csv |
11945 |
11213 |
CVE-2010-0386 |
5 |
Medium |
203.138.185.197 |
tcp |
80 |
HTTP TRACE / TRACK Methods Allowed |
Debugging functions are enabled on the remote web server. |
The remote web server supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods that are used to debug web server
connections. |
Disable these methods. Refer to the plugin output for more information. |
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://download.oracle.com/sunalerts/1000718.1.html |
To disable these methods, add the following lines for each virtual host in your configuration file : RewriteEngine on RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] Alternatively, note that Apache versions 1.3.34, 2.0.55, and 2.2 support disabling the TRACE method natively via the "TraceEnable" directive. Nessus sent the following TRACE request : ------------------------------ snip ------------------------------ TRACE /Nessus2048367938.html HTTP/1.1 Connection: Close Host: 203.138.185.197 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ and received the following response from the remote server : ------------------------------ snip ------------------------------ HTTP/1.1 200 OK Date: Mon, 16 Jan 2017 02:19:43 GMT Server: Apache/2.2.15 (CentOS) Keep-Alive: timeout=15, max=1000 Connection: Keep-Alive Transfer-Encoding: chunked Content-Type: message/http TRACE /Nessus2048367938.html HTTP/1.1 Connection: Keep-Alive Host: 203.138.185.197 Pragma: no-cache User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */* Accept-Language: en Accept-Charset: iso-8859-1,*,utf-8 ------------------------------ snip ------------------------------ |
|