Submit a ticketCall us

Webinar: Web Help Desk for HR, Facilities and Accounting Departments
This webinar will focus on use cases for HR, Facilities and Accounting.

Having a unified ticketing and asset management system for all the departments in your company can provide end-users with a seamless experience and make things easier for your IT team. Yet, with different business tasks and objectives, many departments don’t fully understand the capabilities of Web Help Desk and how the software can be customized for effective use in their departments.
Register Now.

Home > Success Center > Netflow Traffic Analyzer (NTA) > Tenable security scan reports vulnerability on the NTA Flow Storage Database server

Tenable security scan reports vulnerability on the NTA Flow Storage Database server

Updated March 1, 2017

Overview

A Tenable vulnerability scan reports the following on the NTA Flow Storage Database server:

 

Synopsis:


The remote ASP.NET web server does not have custom errors set


Description:


The remote ASP.NET web server is configured to show verbose error messages, which might lead to the disclosure of potentially sensitive information about the remote installation (such as the path under which the remote web server resides) or about the remote ASP.NET applications.


Solution:


Configure the server so that the option 'customErrors mode' is set to 'On' instead of 'Off'


Plugin Text:


Plugin Output:

 

The following error message could be obtained :
[HttpException]: The type initializer for 'SolarWinds.Orion.Core.Common.ModulesCollector' threw an exception.
   at System.Web.HttpApplicationFactory.EnsureAppStartCalledForIntegratedMode(HttpContext context, HttpApplication app)
   at System.Web.HttpApplication.RegisterEventSubscriptionsWithIIS(IntPtr appContext, HttpContext context, MethodInfo[] handlers)
   at System.Web.HttpApplication.InitSpecial(HttpApplicationState state, MethodInfo[] handlers, IntPtr appContext, HttpContext context)
   at System.Web.HttpApplicationFactory.GetSpecialApplicationInstance(IntPtr appContext, HttpContext context)
   at System.Web.Hosting.PipelineRuntime.InitializeApplication(IntPtr appContext)
[HttpException]: The type initializer for 'SolarWinds.Orion.Core.Common.ModulesCollector' threw an exception.
   at System.Web.HttpRuntime.FirstRequestInit(HttpContext context)
   at System.Web.HttpRuntime.EnsureFirstRequestInit(HttpContext context)
   at System.Web.HttpRuntime.ProcessRequestNotificationPrivate(IIS7WorkerRequest wr, HttpContext context)

 

Environment

All NTA versions

 

Cause 

This is caused by IIS installed with specific settings on the NTA Flow Storage Database server after the initial NTA installation has occurred.

 

Resolution

Uninstall IIS from the NTA Flow Storage Database server.

 

 

 

Last modified
20:25, 28 Feb 2017

Tags

Classifications

Public