Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Testing virtual hosts |
|---|---|
| Date: | Thu, 24 Nov 2005 15:52:10 +0100 |
--
Jesper S. Jensen Basisnet og Sikkerhed Uni-C - Århus, Danmark +45 8937-6666
-------- Original Message -------- Subject: Testing virtual hosts Date: Tue, 08 Nov 2005 11:06:20 +0100 From: Jesper S. Jensen <jsj@uni-c.dk> To: nessus@list.nessus.org
I'm looking for a way to scan for vulnerable php-scripts and alike. I'm trying to scan my domain on my webserver, but I can't quite get Nessus to do it. It scans the webserver just fine, but it seems it's not able to scan the vhost running on it.
I've found the mail below in the mailing list archive, and from that I gather that I should just tell nessus to scan "127.0.0.1[www.foo.bar]" (with my IP/domain in it), and that's what I've tried. But it still just scans the webserver itself.
I'm wondering if I'm getting this wrong, and that Nessus arn't able to do what I want, or if I'm doing something wrong? I hope you guys can help me out.
-------- Original Message -------- Subject: Re: Testing virtual hosts Date: Tue, 21 Oct 2003 08:13:46 -0400 From: Renaud Deraison <deraison@nessus.org> To: nessus@list.nessus.org References: <Pine.LNX.4.44.0310210936110.9843-100000@courgette.jml.net> <20031021110726.D102338108@mail.secnap.net>
No, you just need to enter the name of the target host and that's it. If the DNS<->IP has not been done it (ie: because the server has not been put in production yet) you can force it in Nessus by giving the host name between brackets. Ie: "127.0.0.1[www.foo.bar]" will test 127.0.0.1 and all the HTTP requests will have the Host: header set to www.foo.bar.
-- Renaud
_______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: nessus help, Reggie David |
|---|---|
| Next by Date: | Re: Testing virtual hosts, Sullo |
| Previous by Thread: | Testing virtual hosts, Jesper S. Jensen |
| Next by Thread: | Re: Testing virtual hosts, Sullo |
| Indexes: | [Date] [Thread] [Top] [All Lists] |