RE: nessus which plug'in reports which vulnerability?

From: Harshul Nayak (harshul.nayak_at_patni.com)
Date: 02/23/04

  • Next message: Vaccare, Anthony: "RE: nessus which plug'in reports which vulnerability?"
    To: "'cissper'" <cissper@yahoo.com.au>
    Date: Mon, 23 Feb 2004 12:02:22 +0530
    
    

    Hi cissper,
    many of the nessus plugins are written using NASL,
    and each nessus plugin is assigned a unique nessus id..
    when a test is conducted using Nessus , a temporary file get generated in
    the "temp" or "/tmp" folder.. u can use it as reference to know which
    ".nasl" file was called and for which vulnerability ;)
    regs
    Harshul

    -----Original Message-----
    From: cissper [mailto:cissper@yahoo.com.au]
    Sent: Monday, February 23, 2004 7:54 AM
    To: pen-test@securityfocus.com
    Subject: nessus which plug'in reports which vulnerability?

    Hi all

    One of my favourite general purpose scanner is nessus for obvious
    reasons. However, I do struggle with the interpretation and evaluation
    of the results:
    After the scan, I use the report function to generate a HTML type
    report. The vulnerabilities listed in that report are not associated
    with the plug-in's that detected them in the first place. How can I
    possible know which plug-in detected which vulnerability? I need to
    validate the identified vulnerabilities in order to eliminate false
    positives, therefore I would like to know which script was used to
    identify a certain vulnerability.

    One simple example:
    nessus reports that a DNS zone transfer was possible. However, when I
    try to manually perform a zone transfer, I am not able to do so!
    The conclusion would be a false positive - but - maybe the script is
    using a more sophisticated approach and is successful! The next step
    would be to look at the plug' in which detected the vulnerability in the
    first place - and I don't know which one it is.

    Any ideas guys?

    Thank you for your help.

    Kind regards,
    cissper

    ---------------------------------------------------------------------------
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.

    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.

    Download 30-day evaluation at:
    http://www.securityfocus.com/sponsor/Astaro_pen-test_040219
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.

    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.

    Download 30-day evaluation at:
    http://www.securityfocus.com/sponsor/Astaro_pen-test_040219
    ----------------------------------------------------------------------------


  • Next message: Vaccare, Anthony: "RE: nessus which plug'in reports which vulnerability?"

    Relevant Pages

    • Re: MBSA scanner
      ... all the suggestions on how to fix a vulnerability that a report might ... > Nessus is another example; the GPL has the same restrictions on distribution ... And also read the GPL FAQ: ...
      (Pen-Test)
    • Re: Vulnerability Assessment
      ... levels based on current patch data and such. ... Scanners have evolved through marketing to being the means to a vulnerability assessment rather than a tool of one. ... Maybe it's the "final" report that throws so many people off-- that once the report is generated the work is done and not just the job. ... You know many IT security professionals can't even tell you why Nessus runs a traceroute to each and every host in the list. ...
      (Pen-Test)
    • RE: MBSA scanner
      ... the license must state clearly what is restricted. ... that referred to the nature of the vulnerability or exploit itself would be ... > all the suggestions on how to fix a vulnerability that a report might ... > nothing preventing Nessus, Internet Scanner, Cybercop, Retina, ...
      (Pen-Test)
    • RE: MBSA scanner
      ... regard to how you wish to license Nessus reports. ... And while I am not familiar with the inner workings of Nessus, ... the text for the report, if a vulnerability is found. ...
      (Pen-Test)
    • nessus gtk yields empty scan
      ... nessus-libnasl-2.2.9_1 Nessus Attack Scripting Language ... The discovery may be accidental or through directed research; the vulnerability, in various levels of detail, is then released to the security community. ... the plug-ins should be updated. ... The native Unix GUI version is installed at server install time. ...
      (freebsd-hackers)