Appreciate you help in advance. Nessus is reporting a list of shares on a Windows server available to a guest account.
Did you give Nessus administrative credentials to scan this host?
Is this host part of a domain? If so is it part of the same domain for which you (if you did) supplied admin credentials?
Howerver, the guest account has been renamed and disabled before the scan. I tried to map to the share using guest \ password. It either responds not able to find the share, or the guest account is locked. There are shares on the server - but guest is not given access to them.
If you are using administrative credentials you are accesing this host from another point of view different than "guest", rather from an insider or administrative pov.
How can this be tested and how is nessus getting the list of shares. The system admin believes this as a false positive - but nessus can list the shares.
Test it with and without admin credentials and compare the differences. Also, make sure this host is part of the same domain as that of the admin credentials you use.
-- Oscar Castaneda V. [EMAIL PROTECTED] _______________________________________________ Nessus mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus
