Possible fales positives for MS04-007

Russell Fulton r.fulton at auckland.ac.nz
Tue Mar 2 04:34:58 GMT 2004

We are getting some apparent false +ves from both Nessus and 007scan. 
Both say boxes are vulnerable but admins swear they are patched.  In at
least one case it turned out the admin was patching the wrong box but I
have asked them all to check this and make quite sure of the IP of the
box they are working on. Numbers are low -- 3 or 4 machines out of
several thousand machines and I am inclined to lay it to human error,

Anyone else seeing this?


