Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | auto_enable_dependencies doesn't seem to work correctly for 2.0.12 |
|---|---|
| Date: | Mon, 23 Aug 2004 11:51:06 +1200 |
I run a daily scan of several networks using a very cut-down list of Windows-only vulnerability tests (about 20 in number). These are some of the options set begin(SERVER_PREFS) optimize_test = yes auto_enable_dependencies = yes safe_checks = no port_range = 1-1024 only_test_hosts_whose_kb_we_dont_have = no only_test_hosts_whose_kb_we_have = no kb_restore = no end(SERVER_PREFS) With XP SP2 now out and installed on some machines, I actually took the time to really see how well Nessus was reporting things: answer - not very :-( With this cut-down scan, it is reporting that XP SP2 boxes that are *completely* up-to-date (as far as Windows Update and lots of reboots are concerned) still has the following "Security Vulnerabilities": RPC/DCOM bugs (Nessus ID : 12206) Messenger Service hole (Nessus ID : 11888) missing a critical Microsoft Windows Security Update (Nessus ID : 12205) This Nessus scan was run as Domain Administrator, so it had total access to the registry. Also we disabled Firewall settings to ensure it had total access. If I then run a manual Nessus scan against this box - full scan with all safety turned off (still as administrator), I find a lot more "vulnerabilities", including all the ones listed above. But again, some are like "CAN-2003-XXXXX" - bugs found last year. These just can't be true - can they? Now of course I'm really confused. Is it that SP2 has changed so much of XP that the current tests are mis-diagnosing all sorts of things, or is it a more fundamental problem? i.e. could these be "false positives" for Windows 2000 and XP-SP1 machines too? Linux running Nessus-2.0.12 -- Cheers Jason Haar Information Security Manager, Trimble Navigation Ltd. Phone: +64 3 9635 377 Fax: +64 3 9635 417 PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1 _______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: running Nessus on a dual homed system, Jay Jacobson |
|---|---|
| Next by Date: | Re: Problem compiling Nessus 2.0.12 with GTK, Francisco José Candeias Figueiredo |
| Previous by Thread: | Bad signature error on nessusd startup for plugins?, Claude V. Lucas |
| Next by Thread: | Re: auto_enable_dependencies doesn't seem to work correctly for 2.0.12, Renaud Deraison |
| Indexes: | [Date] [Thread] [Top] [All Lists] |