-
Notifications
You must be signed in to change notification settings - Fork 242
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Windows XP False Positives? #6
Comments
Do you have an IP address I can use to connect to? Also, do you have a link to the WinXP patch? |
Unfortunately I don't, they are all internal RFC1918 addresses. I might be able to create a VM that I could send to you somehow? Let me know what could work. The WinXP patch can be downloaded here: |
Noticed something similar. About half of the tested WinXP VMs are still reported as vulnerable by rdpscan after KB4500331 has been applied and the machine was restarted, but none of the (few) physical WinXP machines. Unfortunately (or fortunately) all of the VMs are disconnected from the internet. |
I've been investigating this, and I think we can narrow down false positives to the following behaviour: True positive:
likely false positive (this machine was patched):
Note the extra line of output:
Also, in the case that the machine is patched, the tool times out at around 2 minutes. @robertdavidgraham can you look into this? |
Update: using the latest version v0.0.4 seems to fix this. |
I have the same issue. Two 2003 R2 servers already patched, one rdpscan says SAFE, and the other VULNERABLE. Using the latest version. rdpscan.exe 172.18.72.33 -dddd |
I'm seeing a discrepancy in the results between this rdpscan and the one put out by zerosum0x0.
This rdpscan seems to be reporting all Windows XP as vulnerable even after they are patched and rebooted. The rdpscan from zerosum0x0 reports the same Windows XP as patched. (rdpscan from zerosum0x0 had previously reported them as vulnerable before KB4500331 was applied to them)
I'm not sure what information I can provide to help solve this but let me know and I'll do what I can. I'd like to set this up as a scheduled task. Thanks
The text was updated successfully, but these errors were encountered: