NNTP Service Cleartext Login Permitted

This script is Copyright (C) 2011-2015 Tenable Network Security, Inc.


Synopsis :

The remote NNTP server allows cleartext logins.

Description :

The remote host is running an NNTP server that advertises that it
allows cleartext logins over unencrypted connections. An attacker may
be able to uncover user names and passwords by sniffing traffic to the
server if a less secure authentication mechanism (i.e. LOGIN or
PLAIN) is used.

See also :

http://tools.ietf.org/html/rfc3977
http://tools.ietf.org/html/rfc4643

Solution :

Configure the service to support less secure authentication
mechanisms only over an encrypted channel.

Risk factor :

Low / CVSS Base Score : 2.6
(CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N)

Family: Misc.

Nessus Plugin ID: 57335 ()

Bugtraq ID:

CVE ID:

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial