Greetings,
I am doing security audits on various machines at the University where I work using Nessus. I decided to go ahead and give my e-smith box a go and was very suprised to find vulnerabilities.
I found 9 holes in the machine (according to nessus). Most of them were in SMTP with no less than like 4 or 5 buffer overflows that allowed attackers to execute code.
I understand that there are changes in file locations under e-smith and that this may confuse nessus into thinking there is something wrong when there isn't, but I would just like to see what people have to say about this.
I wonder if others have had similar results with nessus or iss when doing scans against their e-smith machines.
Thanks for your imput,
Daniel