Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: NASL Script for plugin ID 10330 |
|---|---|
| Date: | Tue, 18 Sep 2007 13:19:40 -0400 |
I believe I have found a DoS with a proprietary application, caused by the NASL Plugin ID 10330 "Services".
Oh my, not again! :-)
Your response would indicate that plugin has a history.... ;-) Or, are you recalling the btcpcom.nlm issue?
I am unable to identify this script in the plugins directory. Hence, can anyone provide the script?
10330 is one of the C-language plugins; it handles the basic service detection. If you're using 2.2.x and build from source, look for it under your source directory as nessus-plugins/plugins/find_service/find_service.c.
Thanks George, Running Nessus version 3.0.3 on Linux release 2.6.13-15.16-smp (SUSE) found the find_service.nes and find_service.nasl in /opt/nessus/lib/nessus/plugins/ I'll check it out.
George -- theall@tenablesecurity.com
Le Tue, 18 Sep 2007 11:14:56 -0400, "Joel Elwell" <joelel@homeproperties.com> a ?crit :
I believe I have found a DoS with a proprietary application, caused by the NASL Plugin ID 10330 "Services".
As George said, this is find_service.nes, a C plugin.
My hope is to review the plugin script to understand how it may be effecting the application.
What are your settings ("Prefs") for find_service? Especially, did you
enable SSL/TLS detection?
SSL detection is set for "Known Ports" only. NESSUSRC ----snip------ Services[entry]:Number of connections done in parallel : = 6 Services[entry]:Network connection timeout : = 5 Services[entry]:Network read/write timeout : = 5 Services[entry]:Wrapped service read timeout : = 2 Services[radio]:Test SSL based services = Known SSL ports;None;All ----snip------ Joel _______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: NASL Script for plugin ID 10330, Michel Arboi |
|---|---|
| Next by Date: | Re: NASL Script for plugin ID 10330, George A. Theall |
| Previous by Thread: | Re: NASL Script for plugin ID 10330, Michel Arboi |
| Next by Thread: | Re: NASL Script for plugin ID 10330, George A. Theall |
| Indexes: | [Date] [Thread] [Top] [All Lists] |