Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Reports: Problem.... solution.... |
|---|---|
| Date: | Wed, 7 Nov 2007 08:18:38 +0100 |
On Nov 7, 2007, at 3:54 AM, Bob Babcock wrote:
Issue 1: Upgrade to Firefox 2.0.0.3 Issue 2: Upgrade to Firefox 2.0.0.4 ...I tune the list of plugins to only scan for the latest version. This cleans up my reports, but it makes maintaining the scan rules a real chore. Perhaps another way of handling this would be to have the plugin that scans for version N have something inside it that marks it as superseding plugins that look for version N-1, N-2,...
The problem with this approach is that not every organization is going to rate these vulnerabilities as being equally important. This seems obvious for something like firefox where basically every new version patches a remote critical flaw, but this is much less trivial for other advisories where version N+1 fixes a flaw which is critical in your organization and directly affects you, whereas version N+2 patches a flaw which is not critical in a feature which has been disabled in your organization. Depending on how your organization handles IT and wether there's a patch approval process or not, this can make a good chunk of our user base and the other chunk very unhappy.
A scan option would be to use or not use this information to turn off the supersceded plugins.
This indeed would be the minimum requirement, but that makes this
feature even harder to implement (it's not impossible though).
-- Renaud
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Reports: Problem.... solution...., Bob Babcock |
|---|---|
| Next by Date: | RE: Reports: Problem.... solution...., Mercer, Jeff C - Raleigh, NC |
| Previous by Thread: | Re: Reports: Problem.... solution...., Bob Babcock |
| Next by Thread: | Re: Reports: Problem.... solution...., Bob Babcock |
| Indexes: | [Date] [Thread] [Top] [All Lists] |