Re: Nessus scripts and Moore's Law
Michel Arboi <[email protected]> Fri, 12 Nov 2004 18:26:03 +0100
| Newsgroups | gmane.comp.security.nessus.devel |
|---|---|
| Message-ID | <[email protected]> |
On Fri Nov 12 2004 at 17:50, Erik Stephens wrote: > I agree. I'd much rather have something obviously inaccurate than > something that is inaccurate but appears accurate on the surface. But you cannot never be sure that you did not miss something. Renaud planned to implement adaptative network timeout; this might help. We could imagine that every Nessus test tries very hard to get an answer from a previously identified service. This way, if there is a network problem, we will not miss anything. *However*, if the machine or the service gets down, then the scanner will remain stucked on the port, waiting for an answer that will never come. Anything could happen: somebody unplugged the wrong cable on the switch, or a router was misconfigured, or the machine was rooted and the cracker wants to "glue" your scanner here while he looks for other vulnerable machines... I don't think there is a silver bullet. But if you have any idea... > On a side note, port scanning is the most sensitive and time consuming > for us. netstat and snmpwalk "pseudo port scanners" might help you. > Another point of reference, our experience has been that network > bandwidth is the critical resource. Second would be memory, then cpu > a distant third. However, most of our assessments have been done over > the Internet where we obviously don't have as much bandwidth to play > with. There are in fact several categories of people who run Nessus with different goals. Fully satisfying everybody is impossible but it seems that Nessus made a good compromise: - some run it on quick LAN, other on Internet. - some run it against at most a couple of machines at a time, others watch a full class B network. - some want an in-depth audit, others want only the biggest holes (and no false positive). - some can afford to crash any service (and will be happy to find an unknown flaw before a 0-day exploit is out), others want their systems to be up & running. -- [email protected] http://arboi.da.ru NASL2 reference manual http://michel.arboi.free.fr/nasl2ref/ _______________________________________________ Nessus-devel mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus-devel