Re: Help with local security checks

Renaud Deraison <[email protected]>
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
On Fri, Aug 20, 2004 at 02:31:08PM -0400, George Theall wrote:
> On Fri, Aug 20, 2004 at 08:04:20PM +0200, Renaud Deraison wrote:
> 
> > No. The idea of the trusted scripts is to make sure that the scripts you
> > obtain (as a user) are the one we wrote (as the authors). Nothing else.
> 
> If that's the case, wouldn't it have been simpler to just sign the
> plugin distribution file? 

There are other ways to obtain new scripts (ie: fetch them using CVS)
and we may move away from a gigantic tar archive in later releases in
favor of something else. By signing the scripts themselves, we pave the
way for more flexibility in the future.

> And why is the new nasl function pread() only
> available to trusted scripts?

Because you don't want an untrusted script to execute arbitrary commands
on your local system.

	
				-- Renaud
_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.