Re: Nessus scripts and Moore's Law

Renaud Deraison <[email protected]> Fri, 12 Nov 2004 00:49:12 +0100
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
On Thu, Nov 11, 2004 at 03:59:14PM -0500, George Theall wrote:
> On Thu, Nov 11, 2004 at 06:06:29PM +0100, Michel Arboi wrote:
> 
> > I have come with several possibilities to reduce the overall scanning
> > time:
> 
> What are people's feelings about combining related plugins, especially
> those that rely on simple version strings? For example, I count 9

I don't feel good about this. The idea behind one script per
vulnerability is to give the users the ability to perform grep-like
research on vulnerabilities.

If you consider the overflow in Apache-mod_proxy as a non-issue for your
organization, you'll know that your Apache 2.0.0 is still vulnerable to
a great number of flaws. If you start to aggregate vulnerabilities under
one given plugin ID, you basically decide what is important instead of
the users, and it makes everyone's life more difficult.



				-- Renaud
_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel