Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: Resuming Scans

Subject: Re: Resuming Scans
Date: Thu, 11 Jan 2007 10:59:17 -0500
On Wed, Jan 10, 2007 at 09:24:06PM -0800, Larry Petty wrote:

I'm trying to figure out exactly how the knowledge base works. Below are my
current settings. If I launch a scan and then kill it half way through, I
can re-launch the scan and it skips over the addresses already scanned
picking up where the scan was stopped. I can then look at the output file
and have a complete report.

That sounds more or less right. The only quibble I have involves "a complete report". I'd expect the report would only contain information obtained from when you resumed the scan, not anything that was obtain before the scan was terminated half-way through. You should be able to verify this with the help of nessusd.messages.


If I launch another scan on the same hosts before the kb_max_age expires,
the scan doest not run. I end up having a blank output file.

That's because you're using the KB and you have the four kb_dont_replay* settings enabled. [Actually, you might still get a report if you add *new* plugins to the server and those generate a report.]


Is there any documentation that
explains how this works?

There's a full chapter about the Knowledge Base in "Nessus Network Auditing". Or you could refer to edgeos Security's Nessus Knowledge Base, <http://www.edgeos.com/nessuskb/> (and ignore the link to <http://www.nessus.org/doc/kb_saving.html>, which is no longer accurate).


George
--
theall@tenablesecurity.com
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>