Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Default password attempting |
|---|---|
| Date: | Wed, 22 Feb 2006 21:42:50 -0500 |
On Wed, Feb 22, 2006 at 01:10:16PM -0500, Youngstrom.Timothy wrote:
I need to verify the number of login attempts that a fresh unmodified install of Nessus makes.
There's no single answer; it depends on the plugins available on your server, which specific plugins you enable, how you configure your scan, which ports are determined to be open on the targets, etc.
If all Hydra brute force settings are configured to 'No' will there be ANY user ids and password combinations submitted to a machine including a blank password for login to the machine, ftp, mail etc?
Sure. There are plenty of plugins that will try to authenticate in some fashion using known or common credentials; eg, account_*.nasl and mssql_brute_force.nasl (despite its name, it tries only 10 user/password combinations). George -- theall@tenablesecurity.com _______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: update-nessusrc script usage, George A. Theall |
|---|---|
| Next by Date: | Re: need help for 2.2.6 GUI, Michel Arboi |
| Previous by Thread: | Default password attempting, Youngstrom.Timothy |
| Next by Thread: | update-nessusrc script usage, Ameet Zaveri |
| Indexes: | [Date] [Thread] [Top] [All Lists] |