Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: nessusd.rules

Subject: Re: nessusd.rules
Date: Thu, 26 Oct 2006 10:30:47 -0500
Thanks for answering my question. I may go the plug in route but adding the
IP addresses is a great fix for now.

I checked the logs and it appears that nessus does indeed scan the address's
that are allowed and skips the reject/denied ones. the WX Gui is a bit
misleading, I receive the E2002 error when the audit is complete but
the interface still states that its scanning.


On 10/25/06, Renaud Deraison <deraison@nessus.org> wrote:


On Oct 24, 2006, at 9:38 PM, Jeff T wrote:

> Hello all.
>
> First I would like to say I appsoluly love this project. Nessus is
> a wonderful tool.
>
> I'm trying to be creative and deny close to 60 host from being
> scanned during our audits. I want to utilize the nessusd.rules file
> keep track rather then having to brake apart my subnets when
> inputting them for the audit.
>
> I'm trying to figure out why my scan is hanging with error "E2002 -
> These hosts could not be tested because you are not allowed to do
> so." after adding deny addresses to the nessusd.rules file. I want
> to scan the subnet and have purposely denied IP address. Should I
> be using reject instead of deny? Is their an error log I should be
> looking at.
>
> My scan works flawlessly until it hits a deny host and then just
> stops.

The scan does not stop when an attempt to scan a "forbidden" IP is
made. In other words, the error message you're seeing is displayed
only at the end of the scan, but every other IP in your network
should have been scanned (check nessusd.messages to have more details
about what is going on).



                                       -- Renaud
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus
<Prev in Thread] Current Thread [Next in Thread>