Re: families

Paul Johnston <[email protected]>
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
Hi,

I would favor arranging the families by "how the plugin works". For example:

service_detection
banner_check
registry_check
http_file_existence
cross_site_scripting

This would result in a fair few more families than we currently have.

Paul


Michel Arboi wrote:

>I know that this subject has been debated for a long time and that we
>could not reach a compromise.
>MHO, the current family sets sucks, mostly because it mixes several
>things:
>- effects, like "denial of service" or "gain root"
>- target protocols, like "finger" or "RPC",
>- target OS, like "windows"
>- including the infamous "general" and "misc."
>
>This kind of mixing is hard to avoid, but I suggest that we choose a
>main "classification" and try to minimize the exceptions.
>I think (but you are allowed to disagree :) that targets (protocols
>and OS) are the best classification. 
>Effects should be avoid, except "Denial of servce" maybe, although it
>could better be handler by a more subtle "safe_checks" (instead of a
>simple flag, we could have "all", all but DoS", "non intrusive /
>safe_checks")
>
>Things like "service identifications" could be in a special family,
>because we already have many of them and I plan to split find_services
>in small pieces.
>
>Comments?
>
>  
>

-- 
Paul Johnston
Internet Security Specialist
Westpoint Limited
Albion Wharf, 19 Albion Street,
Manchester, M1 5LN
England
Tel: +44 (0)161 237 1028
Fax: +44 (0)161 237 1031
email: [email protected]
web: www.westpoint.ltd.uk


_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.