Re: Multicast & NASL security
Guillaume Valadon <[email protected]>
| Newsgroups | gmane.comp.security.nessus.devel |
|---|---|
| Message-ID | <[email protected]> |
hello, How does this function works ? Can you provide an example ? > 1. Allowing the script to write on the socket is not good, because > a. It breaks the NASL model where the script is supposed to connect > to the "target" only Yes, but there is no *single* target when you use multicast as in service discovery protocols as SLP, UPnP (HTTP/UDP over multicast in fact), Rendez-vous (dns over multi-cast). > 3. Is it possible to ping the machines that joined a multicast group? > If so, this could be a way to detect all running nessusd. I think the answer is yes, but it did not check it. In both case, I do not think that is a big issue because a malicious guy has to know which multicast address nessus is *listening*. So, if it is possible to *ping* that address, nesssus will only be *visible* during a specific script execution. The address used in SLP, Rendez-vous are not the same. > The big question is: should multicast be restricted to "trusted" > scripts? As my answer is only focused on service discovery protocols (and *private* multicast addresses), I would say no. Guillaume -- mailto:[email protected] ICQ uin : 1752110 Page ouebe : http://guillaume.valadon.net "La reflexion est le premier ennemi de l'amour." - kozette