Re: BOSS project: Concept paper for Nessus improvements
Jan-Oliver Wagner <[email protected]> Thu, 9 Sep 2004 09:33:52 +0200
| Newsgroups | gmane.comp.security.nessus.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Sep 08, 2004 at 02:38:54PM +0200, Nicolas Pouvesle wrote: > > That's right. But since we are running local tests against a potentially > > compromised system we cannot be sure that the various auditing and intrusion > > detection tools installed locally have not been tampered with. SLAD delivers > > the infrastructure plus all the tools we want to use in one single image > > file which you can verify by checksum (see concept document for more > > details). But it's a very valid question and I will add a section to the > > concept document for clarification. > > Installing new security tools on a compromised system will not give you > more security than use compromised ones. For example, if a rootkit hacks > (or hooks) some kernel calls, i'm not sure your newly installed tools > will give you correct results. of course you can never be 100% save. Still I think the hurdle would be just a bit higher for the average crackers if we bring our own auditing tools with us. > But if you really want to do something like that, i don't think (just my > opinion) it should be integrated to nessus. > Do client/server communication and managment (modification of > configuration files) is not the goal of Nessus. > I did something like that to manage logs with ssh plugin. It worked but > had nothing to do in Nessus. > It should be added in higher level, for example in your boss managment > console. Nessus has a very nice and tested infrastucture like the protocol and KB. IMHO it makes sense to take advantage of this rather than to invent new things. SLAD is just another Plugin for Nessus Server. Nessus Server needs not to be modified, at least AFAIU. Jan -- Jan-Oliver Wagner http://intevation.de/~jan/ Intevation GmbH http://intevation.de/ FreeGIS http://freegis.org/ _______________________________________________ Nessus-devel mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus-devel