Ncat TLS Listener

Critical Nessus Plugin ID 122316

Synopsis

The remote host may have been compromised.

Description

This host seems to be running an instance of Ncat that is listening over TLS. Ncat is an open source networking tool that can be used as a backdoor to allow unauthorized entry and control of the remote host

An attacker may use it to steal your passwords, modify your data, and prevent you from working properly.

Solution

Reinstall your operating system or restore your system from known clean backups.

Plugin Details

Severity: Critical

ID: 122316

File Name: ncat_tls_listener.nasl

Version: 1.1

Type: remote

Family: Backdoors

Published: 2019/02/19

Updated: 2019/02/19

Dependencies: 57571, 11153, 17975

Risk Information

Risk Factor: Critical

CVSS Score Source: manual

CVSS Score Rationale: The presence of a backdoor is an indicator of complete system compromise.

CVSS v2.0

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS v3.0

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H