RE: nessus which plug'in reports which vulnerability?

From: Vaccare, Anthony (rvaccare_at_ola.state.md.us)
Date: 02/25/04

  • Next message: Manning, Michael: "RE: which os version"
    Date: Wed, 25 Feb 2004 09:13:58 -0500
    To: <pen-test@securityfocus.com>
    
    

    No problem cissper. It was a good question, something I hadn't even
    thought about. So, it goes to show that there's always someone else out
    there that has the same questions as you. If you haven't already, I
    recommend that you join the Nessus ListServ (there is a link on Nessus'
    web site, www.nessus.org). It's a very busy ListServ, as you can
    imagine, so if you aren't fond of getting a lot of e-mails, then you may
    wish to abstain. I have all messages from that ListServ forwarded to a
    folder, where I can view them when I have time. A lot of them, I don't
    read, but I have an archive of topics in case I ever need some answers.
    Also, the owner of Nessus, Renaud Deraison, is VERY responsive to
    questions posed by ListServ members. Good Luck!

    -----Original Message-----
    From: cissper [mailto:cissper@yahoo.com.au]
    Sent: Tuesday, February 24, 2004 2:42 AM
    To: pen-test@securityfocus.com
    Subject: RE: nessus which plug'in reports which vulnerability?

    Dear all

    I thank you all for your responses and valuable help!!!

    To quickly summarise the conclusion:

    A HTML report generated by the nessus Windows client does not provide
    the nessusID for an identified vulnerability. A report generated on the
    Linux GUI does link a vulnerability to the nessus plug-in.

    So we just found another good reason for using Linux :-)

    Kind regards
    cissper

    ------------------------------------------------------------------------

    ---
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection
    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.
    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.
    Download 30-day evaluation at:
    http://www.securityfocus.com/sponsor/Astaro_pen-test_040219
    ------------------------------------------------------------------------
    ----
    *************************************************************
    Scanned by net.work.Maryland Antivirus Service ...
    the Backbone of eMaryland, the Digital State.
    *************************************************************
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Manning, Michael: "RE: which os version"

    Relevant Pages

    • RE: Windows XP SP2 and Security Tools
      ... I agree and also use Nessus scans from my windows nessus client ... Can you get to everything you need to if the Linux server is in the DMZ? ... If you going to have a security machine I would recommend it totally ... In my opinion you cannot perform a full penetration test from a windows ...
      (Pen-Test)
    • RE: Windows XP SP2 and Security Tools
      ... I agree and also use Nessus scans from my windows nessus client ... Can you get to everything you need to if the Linux server is in the DMZ? ... If you going to have a security machine I would recommend it totally ... In my opinion you cannot perform a full penetration test from a windows ...
      (Security-Basics)
    • Re: Political Challenges Using Nessus
      ... Subject: Political Challenges Using Nessus ... > processes within your organization is to have a WRITTEN corporate security ... > necessary to ascertain and promote your corporate security requirements. ... I am impatient...I hate politics ..I know I can pull this ...
      (Security-Basics)
    • RE: The Ultimate Toolkit...
      ... The Windows port of Nessus is called NEWT and is sold by Tenable ... Security, a company that was at least partially started by the original ... If you are not the intended recipient any ...
      (Pen-Test)
    • Re: Nessus - open or closed source?
      ... While I cannot state who I work for due to security reasons, ... whether it be nessus or others. ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
      (Pen-Test)