SSL Revoked Certificate Detection

Critical Nessus Network Monitor Plugin ID 5838


The remote host has been compromised and is running a 'Backdoor' program


The remote SSL server is using a certificate which has been revoked. The particular SSL certificate has a serial number of '\xe9\x02\x8b\x95\x78\xe4\x15\xdc\x1a\x71\x0a\x2b\x88\x15\x44\x47' and an Issuer of USERTRUST.


There is a high probability that your server has been compromised. You should manually inspect and fix this system.

See Also

Plugin Details

Severity: Critical

ID: 5838

Family: Backdoors

Published: 2011/03/23

Modified: 2016/01/15

Dependencies: 5620

Risk Information

Risk Factor: Critical