Re: BOSS project: Concept paper for Nessus improvements

Nicolas Pouvesle <[email protected]> Wed, 08 Sep 2004 14:38:54 +0200
Newsgroups gmane.comp.security.nessus.devel
Message-ID <1094647134.3274.44.camel@debian>
> That's right. But since we are running local tests against a potentially
> compromised system we cannot be sure that the various auditing and intrusion
> detection tools installed locally have not been tampered with. SLAD delivers
> the infrastructure plus all the tools we want to use in one single image
> file which you can verify by checksum (see concept document for more
> details). But it's a very valid question and I will add a section to the
> concept document for clarification.

Installing new security tools on a compromised system will not give you
more security than use compromised ones. For example, if a rootkit hacks
(or hooks) some kernel calls, i'm not sure your newly installed tools
will give you correct results.


You can use sshd as SLAD listenner. It will be easier than create a new
network protocol. Maybe you will need to add sftp support, though. 

But if you really want to do something like that, i don't think (just my
opinion) it should be integrated to nessus.
Do client/server communication and managment (modification of
configuration files) is not the goal of Nessus.
I did something like that to manage logs with ssh plugin. It worked but
had nothing to do in Nessus.
It should be added in higher level, for example in your boss managment
console.

Regards,

Nicolas

_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel