Re: BOSS project: Concept paper for Nessus improvements

"Boris Wolf" <[email protected]>
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
>
>On Tue, Sep 07, 2004 at 01:13:12PM +0200, Jan-Oliver Wagner wrote:
>> However, with SLAD we want to avoid having the whole nessus server
>> installed on a system that is suspected to be compromised itself.
>
>The Nessus local security checks don't require a nessusd server on the
>tested host, only sshd running (and an ssh account).

That's right. But since we are running local tests against a potentially
compromised system we cannot be sure that the various auditing and intrusion
detection tools installed locally have not been tampered with. SLAD delivers
the infrastructure plus all the tools we want to use in one single image
file which you can verify by checksum (see concept document for more
details). But it's a very valid question and I will add a section to the
concept document for clarification.

Boris

_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.