families

Michel Arboi <[email protected]>
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
I know that this subject has been debated for a long time and that we
could not reach a compromise.
MHO, the current family sets sucks, mostly because it mixes several
things:
- effects, like "denial of service" or "gain root"
- target protocols, like "finger" or "RPC",
- target OS, like "windows"
- including the infamous "general" and "misc."

This kind of mixing is hard to avoid, but I suggest that we choose a
main "classification" and try to minimize the exceptions.
I think (but you are allowed to disagree :) that targets (protocols
and OS) are the best classification. 
Effects should be avoid, except "Denial of servce" maybe, although it
could better be handler by a more subtle "safe_checks" (instead of a
simple flag, we could have "all", all but DoS", "non intrusive /
safe_checks")

Things like "service identifications" could be in a special family,
because we already have many of them and I plan to split find_services
in small pieces.

Comments?

-- 
[email protected]	http://arboi.da.ru
FAQNOPI de fr.comp.securite http://faqnopi.da.ru/
_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.