Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Gain Root Remotely plugin (command line) |
|---|---|
| Date: | Fri, 22 Sep 2006 07:11:47 -0700 |
On Sep 22, 2006, at 12:00 AM, Gonzalez, Matthew wrote:
Well, taking a look in my plugins, i don't have one named "Gain Root Remotely". however, there is a family of plugins named gain root remotely. It's more than one though :)Hello Everyone,
I am currently taking a Network Defense and Countermeasures course for my degree. Anyway; one of our projects is to use Nessus to run a certain plugin. I am using the command- line version of Nessus on Mandriva, because some dependencies on packages for the GUI are giving me problems and time is against me so to speak. The plugin that I have to demo is the Gain Root Remotely plugin.
I was wondering if there is a way to choose just that plugin through the command line or if it’s a “dangerous plugin” to enable it to be pWell, i would pick a system that does have a gui and select the plugin, then save the .nessusrc file and pass that to nessus using the -c option. If you take a look at the nessusrc file, you'll see that the option to enable is merely changing a "no" to a "yes" on the plugin that you want to run - check after the part that says "begin (PLUGIN_SET)". In your case, it sounds more like you want to run a family of plugins, so it'll be a little harder, if you don't have a gui, as you'll have to dig out a lot of plugin ids. there are 245 according to my find and grep count. I was able to extract all the numbers with the following brief bash script (I apologize for the uglies):
art of the scan. This scan would be taking place on the loopback address (127.0.0.1) of the Mandriva system.
for i in `find ./ -exec grep -l "Gain root remotely" {} \;`
do
grep script_id $i | awk -F\( '{print $2}' | awk -F\) '{print $1}'
doneAlso, are there any tips to make the system be able to be picked up as gaining root remotely when the scan is run? This way when I run a demonstration it will work and show in the generated report. I would appreciate all help and comments.you're scan will show that it was able to gain root remotely in the report. You might also consider tailing the nessusd.dump and nessusd.messages log files using tail -f.
Thank you,
Matthew Gonzalez
Network Administration (BT)
Morrisville State College
Morrisville, NY
_______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
_______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Nessus reports patches as missing, Renaud Deraison |
|---|---|
| Next by Date: | Re: Gain Root Remotely plugin (command line), George A. Theall |
| Previous by Thread: | Gain Root Remotely plugin (command line), Gonzalez, Matthew |
| Next by Thread: | Re: Gain Root Remotely plugin (command line), George A. Theall |
| Indexes: | [Date] [Thread] [Top] [All Lists] |