FIX client LOGON detection

Info Nessus Network Monitor Plugin ID 6740

Synopsis

The remote host is running the Financial Information eXchange (FIX) protocol.

Description

The remote client is running a Financial Information eXchange (FIX) application. This protocol is used by financial institutions to exchange data. The FIX protocol has very few built-in security controls and, instead, relies on industry standard encryption (PGP, SSL/TLS, etc.) to protect the stream. The PVS has just observed this client initiate a LOGON request without encryption set.

Solution

Ensure that FIX data is encrypted when passed over untrusted networks.

See Also

http://www.fixprotocol.org

Plugin Details

Severity: Info

ID: 6740

File Name: 6740.prm

Family: Policy

Published: 2013/04/05

Modified: 2015/06/01

Dependencies: 6737

Risk Information

Risk Factor: Info