Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: Validation

Subject: Re: Validation
Date: Fri, 14 Dec 2007 06:30:15 -0500
First Last wrote:
How do you validate vulnerabilities Nessus finds? I've been working with a 
server for awhile that all of the sudden supposedly has a bunch of 
vulnerabilities. Below are a few of the ID's. How do I validate that the 
vulnerability exists or not?

Nessus ID : 11760
                      Nessus ID : 11694
                      Nessus ID : 15908



Many things can change on a network or on a server. Software can be
loaded without your knowledge by administrators, and services that
weren't running before may start on reboot if they've been disabled but
not turned off completely.

The plugins in question have to do with CSS issues on a variety of web
server applications that are also much older. Is there any chance that a
new PHP application has been loaded, how the web server responds to bad
queries or older software been reverted to?

Ron Gula
Tenable Network Security

_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>