Submit a ticketCall us

Solarwinds & Cisco Live! Barcelona
Join us from the 29th of January to the 2nd of February at Cisco Live 2018 in Barcelona, where we will continue to show how monitoring the network with SolarWinds will keep you ahead of the game. At our booth (WEP 1A), we will demonstrate how SolarWinds network solutions can help. As a bonus, we are also hosting a pre-event webinar - Blame the Network, Hybrid IT Edition with our SolarWinds Head Geek™, Patrick Hubbard on January 24th - GMT (UTC+0): 10:00 a.m. to 11:00 a.m. There's still time to RSVP.

Home > Success Center > Netflow Traffic Analyzer (NTA) > Tenable security scan reports vulnerability on the NTA Flow Storage Database server

Tenable security scan reports vulnerability on the NTA Flow Storage Database server

Updated March 1, 2017

Overview

A Tenable vulnerability scan reports the following on the NTA Flow Storage Database server:

 

Synopsis:


The remote ASP.NET web server does not have custom errors set


Description:


The remote ASP.NET web server is configured to show verbose error messages, which might lead to the disclosure of potentially sensitive information about the remote installation (such as the path under which the remote web server resides) or about the remote ASP.NET applications.


Solution:


Configure the server so that the option 'customErrors mode' is set to 'On' instead of 'Off'


Plugin Text:


Plugin Output:

 

The following error message could be obtained :
[HttpException]: The type initializer for 'SolarWinds.Orion.Core.Common.ModulesCollector' threw an exception.
   at System.Web.HttpApplicationFactory.EnsureAppStartCalledForIntegratedMode(HttpContext context, HttpApplication app)
   at System.Web.HttpApplication.RegisterEventSubscriptionsWithIIS(IntPtr appContext, HttpContext context, MethodInfo[] handlers)
   at System.Web.HttpApplication.InitSpecial(HttpApplicationState state, MethodInfo[] handlers, IntPtr appContext, HttpContext context)
   at System.Web.HttpApplicationFactory.GetSpecialApplicationInstance(IntPtr appContext, HttpContext context)
   at System.Web.Hosting.PipelineRuntime.InitializeApplication(IntPtr appContext)
[HttpException]: The type initializer for 'SolarWinds.Orion.Core.Common.ModulesCollector' threw an exception.
   at System.Web.HttpRuntime.FirstRequestInit(HttpContext context)
   at System.Web.HttpRuntime.EnsureFirstRequestInit(HttpContext context)
   at System.Web.HttpRuntime.ProcessRequestNotificationPrivate(IIS7WorkerRequest wr, HttpContext context)

 

Environment

All NTA versions

 

Cause 

This is caused by IIS installed with specific settings on the NTA Flow Storage Database server after the initial NTA installation has occurred.

 

Resolution

Uninstall IIS from the NTA Flow Storage Database server.

 

 

 

Last modified

Tags

Classifications

Public