Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: How to use Nessus 3.0.3 (Linux) with Nmap port scanning

Subject: Re: How to use Nessus 3.0.3 (Linux) with Nmap port scanning
Date: Wed, 20 Sep 2006 13:56:24 +0100 (BST)
On Wed, 20 Sep 2006, Michel Arboi wrote:

On Wed Sep 20 2006 at 14:21, A User wrote:

A find_service_udp would be much more intrusive.
But again - what about those devices where we can't get local accounts?

Can you afford to crash them?

In certain assignments - yes. For example, new virgin deployments where 
there is no production activity and we have the go-ahead to bring down 
unstable services.

 There are devices that run on non-standard UDP ports

You mean *standard* services or non standard ports??
If this is known, that we can enhance the detection of a couple of
protocols. e.g. if some company implements a DNS server on port 5353, 
we can add the necessary probe in dns_server.nasl

I mean both. But I cannot afford to modify NASLs for each scan.

Can you afford to run nmap -sU -sV for days to get this true picture?
netstat -p would give it instantly.

For a complete review that needs to be performed where I technically 
cannot or am prohibited by the system admin to do this, then yes!

I wonder how many people can afford that.

Well, I get the impression there are some diligent professionals who do 
have the time so as I've said before which seems to keep being passed 
over, having the *choice* is the key thing under discussion.

Cheers,

A.
----

_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>