Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: nasl scripts / reliance / port-scanners

Subject: Re: nasl scripts / reliance / port-scanners
Date: Tue, 21 Dec 2004 22:48:46 +0100
On Tue Dec 21 2004 at 22:16, Stuart Kendrick wrote:

when i disable all port scanners ... i haven't detected any change in the 
number of attack NASLs which run ...

Because you don't "optimize" or "consider unscanned ports as closed". 
Anyway the results might be different.

so .... do all/most/some NASLs ignore the port scanner output ... and just
run anyway?  or do they run against default ports only, if port scanner 
output is unavailable?

They run on default port if there is one optimization options
are not set.

[and if port scanner output is available ... then 
do NASLs run against *all* open ports

No. They run on relevant ports.

at the price of running against things like sendmail listening on
port 25 ...

No. Only find_service and similar plugins run against every open port.

what does port scanning buy me, in terms of which NASLs get
launched?

More results.

_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>