Submit a ticketCall us

Get a crash course on Network Monitoring delivered right to your inbox
This free 7-day email course provides a primer to the philosophy, theory, and fundamental concepts involved in IT monitoring. Lessons will explain not only how to perform various monitoring tasks, but why and when you should use them. Sign up now.

Home > Success Center > Netflow Traffic Analyzer (NTA) > Tenable security scan reports vulnerability on the NTA Flow Storage Database server

Tenable security scan reports vulnerability on the NTA Flow Storage Database server

Updated March 1, 2017

Overview

A Tenable vulnerability scan reports the following on the NTA Flow Storage Database server:

 

Synopsis:


The remote ASP.NET web server does not have custom errors set


Description:


The remote ASP.NET web server is configured to show verbose error messages, which might lead to the disclosure of potentially sensitive information about the remote installation (such as the path under which the remote web server resides) or about the remote ASP.NET applications.


Solution:


Configure the server so that the option 'customErrors mode' is set to 'On' instead of 'Off'


Plugin Text:


Plugin Output:

 

The following error message could be obtained :
[HttpException]: The type initializer for 'SolarWinds.Orion.Core.Common.ModulesCollector' threw an exception.
   at System.Web.HttpApplicationFactory.EnsureAppStartCalledForIntegratedMode(HttpContext context, HttpApplication app)
   at System.Web.HttpApplication.RegisterEventSubscriptionsWithIIS(IntPtr appContext, HttpContext context, MethodInfo[] handlers)
   at System.Web.HttpApplication.InitSpecial(HttpApplicationState state, MethodInfo[] handlers, IntPtr appContext, HttpContext context)
   at System.Web.HttpApplicationFactory.GetSpecialApplicationInstance(IntPtr appContext, HttpContext context)
   at System.Web.Hosting.PipelineRuntime.InitializeApplication(IntPtr appContext)
[HttpException]: The type initializer for 'SolarWinds.Orion.Core.Common.ModulesCollector' threw an exception.
   at System.Web.HttpRuntime.FirstRequestInit(HttpContext context)
   at System.Web.HttpRuntime.EnsureFirstRequestInit(HttpContext context)
   at System.Web.HttpRuntime.ProcessRequestNotificationPrivate(IIS7WorkerRequest wr, HttpContext context)

 

Environment

All NTA versions

 

Cause 

This is caused by IIS installed with specific settings on the NTA Flow Storage Database server after the initial NTA installation has occurred.

 

Resolution

Uninstall IIS from the NTA Flow Storage Database server.

 

 

 

Last modified
20:25, 28 Feb 2017

Tags

Classifications

Public