Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: netstat scanner

Subject: Re: netstat scanner
Date: Wed, 25 Aug 2004 22:22:30 +0200
On Tue Aug 24 2004 at 23:57, Pavel Kankovsky wrote:

Well, you can always give the customer a copy of Nessus, let them run it
themselves and charge money for the interpretation of its output. :)

And you'll be responsible because you gave him the software bomb :)

Well...if you have a banking application transfering billions of dollars
every day, then every piece of the system must be triplicated (at least).

Unfortunately, a bad cluster is worse than nothing. 
The only thing that is sure is that redundancy adds complexity,
ie. fragility.  Then if the system is well designed, you will increase
the global reliability. Maybe.

I have some horror stories:
- some old versions of IBM HACMP crashed when you run snmpwalk on the
shared IP address (IIRC). The bug is referenced by IBM in their
archives, but not widely known.
- I've seen an asymetric cluster where the application took more
than an hour to rebuild its database after a switch from the master to
the slave machine.
- with Nessus, I crashed a load balancer while scanning machines
behing it. The load balancing function had been switched off during
the test, I was scanning the offline machines, and the gizmo was
supposed to act as a simple router. The attack was 3+ year old
(stream?) but the bug was not known

-- 
arboi@alussinan.org     http://arboi.da.ru
FAQNOPI de fr.comp.securite http://faqnopi.da.ru/
NASL2 reference manual http://michel.arboi.free.fr/nasl2ref/
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>