Re: Multicast & NASL security

Guillaume Valadon <[email protected]>
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
hello,

How does this function works ?
Can you provide an example ?

> 1. Allowing the script to write on the socket is not good, because
>  a. It breaks the NASL model where the script is supposed to connect
>     to the "target" only

Yes, but there is no *single* target when you use multicast as in service 
discovery protocols as SLP, UPnP (HTTP/UDP over multicast in fact), 
Rendez-vous (dns over multi-cast).

> 3. Is it possible to ping the machines that joined a multicast group?
> If so, this could be a way to detect all running nessusd.

I think the answer is yes, but it did not check it.

In both case, I do not think that is a big issue because a malicious guy has to
know which multicast address nessus is *listening*. So, if it is possible to
*ping* that address, nesssus will only be *visible* during a specific script
execution.
The address used in SLP, Rendez-vous are not the same.

> The big question is: should multicast be restricted to "trusted"
> scripts?

As my answer is only focused on service discovery protocols (and *private*
multicast addresses), I would say no.

Guillaume
-- 
mailto:[email protected]
ICQ uin : 1752110

Page ouebe : http://guillaume.valadon.net

     "La reflexion est le premier ennemi de l'amour." - kozette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.