Hi,
May I know what is causing this on our cPanel server? Is it the cPhulkd daemon? How to resolve this, disable cPhulkd when running the scan?
May I know what is causing this on our cPanel server? Is it the cPhulkd daemon? How to resolve this, disable cPhulkd when running the scan?
Vulnerability Details: | Service: 22:TCP port(s) became closed during scan: 22,25,53,80,110,143,443,465,587,2082-2083,2086-2087,2095-2096 |
IP Address: | redacted |
Host: | redacted |
Path: | |
Threat Reference: | See pages 14-15 of the [https://www.pcisecuritystandards.org/documents/ASV_Program_Guide_v2.pdf] PCI DSS ASV Program Guide for more information on handling interference from an IPS during compliance scanning. |
Problem: | Since a vulnerability scan sends the target a large amount of traffic designed to detect vulnerabilities, an IPS could misinterpret the scan as malicious activity, and react by blocking the scanner. This scan may have been blocked by an IPS. Therefore the results of this scan are inconclusive and cannot be used to support compliance. |
Impact: | The scan results may be inconclusive. |
Resolution: | Temporarily disable the Intrusion Prevention System or configure an exception for the scanner's IP address before starting the scan. |