Successful Shell Attack Detected - Windows 'fscan' Tool

high Nessus Network Monitor Plugin ID 6200

Synopsis

The results of an 'fscan' session were observed in a TCP session normally used for a standard service.

Description

The results of an 'fscan' session were observed in a TCP session normally used for a standard service. This may indicate a successful compromise of this service has occurred.

Solution

The command activity observed is indicative of a possible compromise. Consider performing a full audit of the system to investigate further.

See Also

https://www.foundstone.com/resources/proddesc/scanline.htm

Plugin Details

Severity: High

ID: 6200

Family: Generic

Published: 1/6/2012

Updated: 7/11/2018

Vulnerability Information

CPE: cpe:/o:microsoft:windows