Re: Nessus scripts and Moore's Law

Michel Arboi <[email protected]> Fri, 12 Nov 2004 18:26:03 +0100
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
On Fri Nov 12 2004 at 17:50, Erik Stephens wrote:

> I agree.  I'd much rather have something obviously inaccurate than
> something that is inaccurate but appears accurate on the surface.

But you cannot never be sure that you did not miss something.
Renaud planned to implement adaptative network timeout; this might
help.

We could imagine that every Nessus test tries very hard to get an
answer from a previously identified service. This way, if there is a
network problem, we will not miss anything.
*However*, if the machine or the service gets down, then the scanner
will remain stucked on the port, waiting for an answer that will never
come. Anything could happen: somebody unplugged the wrong cable on the
switch, or a router was misconfigured, or the machine was rooted and
the cracker wants to "glue" your scanner here while he looks for other
vulnerable machines...

I don't think there is a silver bullet. But if you have any idea...

> On a side note, port scanning is the most sensitive and time consuming
> for us.

netstat and snmpwalk "pseudo port scanners" might help you.

> Another point of reference, our experience has been that network
> bandwidth is the critical resource.  Second would be memory, then cpu
> a distant third.  However, most of our assessments have been done over
> the Internet where we obviously don't have as much bandwidth to play
> with.

There are in fact several categories of people who run Nessus with
different goals. Fully satisfying everybody is impossible but it seems
that Nessus made a good compromise:
- some run it on quick LAN, other on Internet.
- some run it against at most a couple of machines at a time, others
watch a full class B network.
- some want an in-depth audit, others want only the biggest holes (and
no false positive).
- some can afford to crash any service (and will be happy to find an
unknown flaw before a 0-day exploit is out), others want their systems
to be up & running.

-- 
[email protected]	http://arboi.da.ru
NASL2 reference manual http://michel.arboi.free.fr/nasl2ref/
_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel