Nessus NASL + Canned Exploit database
From: Joe Skaboika (caffeinex36_at_yahoo.com)
Date: 08/06/03
- Previous message: Ian: "Kerberos DoS (Windows 2000)"
- Next in thread: Muhammad Faisal Rauf Danka: "Re: Nessus NASL + Canned Exploit database"
- Maybe reply: Muhammad Faisal Rauf Danka: "Re: Nessus NASL + Canned Exploit database"
- Reply: Matt Foster: "RE: Nessus NASL + Canned Exploit database"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 6 Aug 2003 18:32:56 -0000 To: pen-test@securityfocus.com('binary' encoding is not supported, stored as-is)
Has anyone seen any project involving linking nessus .NASL scripts with a
canned exploit database of some sort.
For instance, I plug my .NBE file into this tool which spits me out known
public canned exploits (the actual exploit not links or info). I was
thinking about a pen-testing extention to nessus where I pipe output from
nessus into a tool that runs a canned exploit automagically (based on this
database)
I realize known canned exploits are buggy and architecture for something
like this would be a nightmare but I'm curious if anyone has started or
even started thinking of anything like this.
---------------------------------------------------------------------------
----------------------------------------------------------------------------
- Previous message: Ian: "Kerberos DoS (Windows 2000)"
- Next in thread: Muhammad Faisal Rauf Danka: "Re: Nessus NASL + Canned Exploit database"
- Maybe reply: Muhammad Faisal Rauf Danka: "Re: Nessus NASL + Canned Exploit database"
- Reply: Matt Foster: "RE: Nessus NASL + Canned Exploit database"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|