Re: BOSS project: Concept paper for Nessus improvements
Jan-Oliver Wagner <[email protected]>
| Newsgroups | gmane.comp.security.nessus.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi David, [ I am answering to nessus-devel as it might be of general interest ] On Tue, Sep 07, 2004 at 12:58:52PM +0200, David Maciejak wrote: > I just quickly read your pdf, > > I dont understand why you want to do SLAD agent which need to be compiled > on target system. > > You can do that (launch commands and return results) from local security > check that comes with nessus devel branch I am not the designer of BOSS - Lukas can give a detailed answer for sure. However, with SLAD we want to avoid having the whole nessus server installed on a system that is suspected to be compromised itself. To my understanding it makes sense to have nessusd only on a system where you are pretty sure it is not compromised - otherwise the reported results could already be faked. But your question is a very valid one. We should add a section to the concept that exactly explains this question: Why don't we use nessusd's new features for local security check. Thanks a lot Jan -- Jan-Oliver Wagner http://intevation.de/~jan/ Intevation GmbH http://intevation.de/ FreeGIS http://freegis.org/ _______________________________________________ Nessus-devel mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus-devel