Re: Nessus 2.0.12 and 2.1.1 available

Axel Thimm <[email protected]> Fri, 23 Jul 2004 09:43:02 +0200
Newsgroups gmane.comp.security.nessus.general,gmane.comp.security.nessus.announce
Message-ID <[email protected]>
--===============1191170954==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="/NkBOFFp2J2Af1nK"
Content-Disposition: inline


--/NkBOFFp2J2Af1nK
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi,

On Wed, Jul 21, 2004 at 08:16:44PM -0400, Renaud Deraison wrote:
> I just released Nessus 2.0.12 and Nessus 2.1.1. My apologies for such
> a quick 2.0.x release.
>=20
>=20
> Nessus 2.0.12

I have uploaded rpms for Red Hat/Fedora distributions at

		http://atrpms.net/name/nessus/

For RH9 upwards I used gtk2.

I have found two issues:
o gtk2: some modal dialogs are completely undecorated, perhaps this is
  due to my ancient wm (fvwm1)?

o RemotelyAnywhere: All security vulnerabilities and warnings end up
  having the description:

  "A vulnerability in RemotelyAnywhere's web interface allows a remote
   attacker to inject malicious text into the login screen, this can
   be used by an attacker to make the user do things he would
   otherwise not do (for example, change his password after a
   successful login to some string provided by the malicious
   text). Risk factor : Medium BID : 9202"

  Security Notes are not affected.

> Several bugs have been found in the utilities around Nessus 2.0.11 and
> have been fixed in Nessus 2.0.12 :
>=20
> - Fixed a bug in ./configure which would sometimes assume that GTK is
>   not installed whereas it actually is
>=20
> - Fixed a race condition in nessus-adduser for users who do not
>   configure their TMPDIR variable (thanks to Cyrille Barthelemy)
>=20
> - Fixed a bug in nessus-update-plugins which would not update the
>   plugins properly on all systems (thanks to Keith Butler)
>=20
> - Fixed the installer to compile Nessus with GTK support if gtk-config
>   OR pkg-config is installed.
>=20
>=20
> Please note that if you installed Nessus 2.0.11, it's very likely that
> nessus-update-plugins is not working properly on your system.=20
>=20
>=20
> Nessus 2.1.1 (experimental)
>=20
> The developement of Nessus 2.1.x is going extremely well. This new release
> contains the following changes :
>=20
> - Incorporated the fixes above
> - Added support for local Solaris checks
> - Added support for cryptographically signed scripts
>=20
>=20
> I will elaborate on that last item : several persons (legitimately)
> expressed concern over the new local security checks in Nessus 2.1,
> since they can execute arbitrary commands on the remote hosts : if
> www.nessus.org were to be compromised, then you do not want an attacker
> to modify ssh_get_info.nasl to execute 'shutdown -h now' instead of
> 'rpm -qa'.=20
>=20
> So what has changed in Nessus 2.1.1, is that a handful of NASL functions
> will refuse to run unless the script has been signed by a key recognized
> by nessusd (mostly, the functions having to do with handling the
> provided SSH key, and RSA/DSA signing of messages using that key, as
> well as the ability to read the files uploaded by the user).
>=20
> I have also enabled the functions pread() and find_in_path(), which
> also only run if the script has been signed, which allow nasl scripts
> to execute local commands. We intend to use them in the future to get
> rid of most of the remaining .nes plugins.
>=20
> The logic is the following :
>=20
> - If a script is signed and the signature is verified, it will run
> - If a script is signed and the signature is not verified, it will not run
> - If a script is not signed, it will run but will have access to less
> NASL commands. In particular, it will not be able to get access to the
> SSH private key uploaded by the user=20
>=20
> By default, the scripts are signed with my private key, and my public
> key now ships with libnasl. If you do not trust me enough to run the
> scripts I approve (but nevertheless trust me enough to use my code), you
> can always re-sign the scripts yourself, by running nasl -S.
>=20
> If you want to write you own scripts and do not want to bother with
> scripts signing, set the option 'nasl_no_signature_check' to 'yes'=20
> in nessusd.conf.
>=20
>=20
> Availability
>=20
> Nessus 2.0.12 : http://www.nessus.org/nessus_2_0.html
> Nessus 2.1.1  : http://www.nessus.org/nessus_2_1.html
>=20
>=20
> _______________________________________________
> Nessus mailing list
> [email protected]
> http://mail.nessus.org/mailman/listinfo/nessus

--=20
Axel.Thimm at ATrpms.net

--/NkBOFFp2J2Af1nK
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBAMGGQBVS1GOamfERAiIOAKCBwJFWKSikD5namkhqYHT3Dv+5pQCcD1TE
m7a8S00V9biWcKk7/bOGWDc=
=hXU3
-----END PGP SIGNATURE-----

--/NkBOFFp2J2Af1nK--

--===============1191170954==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus
--===============1191170954==--