Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: Nessus 3.2 issue

Subject: Re: Nessus 3.2 issue
Date: Tue, 25 Mar 2008 10:43:14 -0400

For everyone's benefit, I'll post details of the solution to this  
problem here:

Short answer:  I rolled back to 3.0.6 and it works just fine.

Long answer:

Nessus 3.2 on FreeBSD 6.3 is broken.  Just to make sure I wasn't  
hallucinating the entire episode, I re-downloaded it (to make sure I  
was picking up the proper binaries--avoiding the whole "is it plugged  
in sir?" line of questioning) and re-installed it on the server in  
question, and on another server running the same OS and version, as  
well as a laptop.  I tested all three and was able to reproduce the  
results listed below perfectly.

Just to add to the mix, I tested with both local and remote clients  
(even third party linux stuff under binary emulation), and the results  
were the same---spike in CPU, perhaps a few results here and there  
depending on how the policy was set up (I tested ten of them  
each)...I've found nothing wonky in system logs, and the nessus logs  
themselves (including debug) just trail off without error.

All ten policies work perfectly--as long as I'm running 3.0.6 on  
Freebsd 6.3.

I have no problems at all running the 3.2 server on OS X 10.5.2 or  
Solaris 10.



On Mar 22, 2008, at 3:41 PM, James Birk wrote:

Has anyone seen this?

I'm running the Nessus 3.2 server on Freebsd 6.3 (upgraded from 3.0.6
and 6.2 freshly), and the 3.2 client on OS X 10.5.2.

I can connect to the remote server with the client fine, and it shows
up in both a netstat and a ps -aux on the server without issue.  The
problem happens when I begin a scan--nessusd churns heavily for about
5 seconds and then drops to 0% CPU usage, and the client either
receives no results at all, or just a few things greyed out.  I'm
running the same set of policies that I was under 3.0.6, and made a
few new ones, turning off pingers, trying different portscanners, etc,
to see if I could nail down the problem, but to no avail.

One interesting point, I did try nessuscmd on the server with the same
results---it throws up a few open ports and the number of a hit module
or two, but it never exits.

Any ideas?

Thanks,




James
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>