Hi Srikanth,

On 18 Nov 2010, at 14:34, Srikanth Sridhar wrote:

Possible Database Connection String (ODBC DSN or OleDB for Access, MS SQL,

ORACLE, IBM DB2, MySQL, Sybase, Informix, or Interbase ) ( 3185 )

View Description

Page:



This page comes up as script as given below I need to disable it or
display an error page in palce of this

High I/*  Prototype JavaScript framework, version 1.6.1
*  (c) 2005-2009 Sam Stephenson
[snipped]

I'm not sure what the vulnerability here is. Can you explain further?

I notice you are hitting port 3000. Usually, you put an apache proxy server at the front to deliver the static files. Debian instructions here:http://docs.opsview.com/doku.php?id=opsview-community:debian-installation#using_apache_as_a_proxy_server



****************************************************************************************************************************************************
How to encrypt this url or if this is not required i can stop this from loading

HTTP Basic Logins Sent Over Unencrypted Connection ( 10512 )

View Description

Page:

http://10.226.11.35:3000/atom

This is the atom feed on a per user basis. This uses basic authentication as most RSS readers support only basic auth.

http://docs.opsview.com/doku.php?id=opsview-community:notify_by_rss



**************************************************************************************************************************************************
How do i remove persistent cookies

Persistent Cookies ( 4728 )

View Description

Page:

http://10.226.11.35:3000/atom

Page:

http://10.226.11.35:3000/about/

Page:

http://10.226.11.35:3000/baddir123/

http://10.226.11.35:3000/javascript/prototype.js?ov=3.9.1.5340

Cookies are required for the authentication process:

http://docs.opsview.com/doku.php?id=opsview-community:webauthentication


For all these points, I'm not sure what we can change for you.

Ton

_______________________________________________
Opsview-users mailing list
[email protected]
http://lists.opsview.org/lists/listinfo/opsview-users

Reply via email to