RE: Scanning Linux box with Credentials

"Mercer, Jeff C - Raleigh, NC" <[email protected]> Wed, 28 Jan 2009 07:58:29 -0600
Newsgroups gmane.comp.security.nessus.general
Message-ID <B4FAD131405849469A8FE9C9162AC026035A62FB@EAGNMNSXM12>
This is a multi-part message in MIME format.

--===============1175596149==
Content-class: urn:content-classes:message
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C98150.7FAFE594"

This is a multi-part message in MIME format.

------_=_NextPart_001_01C98150.7FAFE594
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hey Mark, I've had problems like that before too, though not with all
unix/linux systems.
=20
Ultimately what we ended up doing was using public key authentication
instead, which works fine. Go figure.
=20

--------
Jeff Mercer - CISO - Security Vulnerability Assessments
 =20

=20


________________________________

	From: [email protected]
[mailto:[email protected]] On Behalf Of Lambert, Mark
	Sent: Tuesday, January 27, 2009 3:04 PM
	To: [email protected]
	Subject: Scanning Linux box with Credentials
=09
=09
	All,   =20
	    I have having a problem with SSH credentials on an internal
Linux box I'm trying to scan. The box I'm scanning is a RedHat box and I
can manually SSH with any SSH2 client to it.=20
	I supply the credentials and I get logged in just fine. BUT.....
When I configure the settings below in my nessus rules file,
	=20
	-SSH settings[entry]:SSH user name : =3D XYZ
	-SSH settings[entry]:Preferred SSH port : =3D 22
	-SSH settings[password]:SSH password (unsafe!) : =3D XYZPassword
	=20
	    I get the response below:
	=20
	The local security checks are disabled. Description: The
credentials provided for the scan did not allow us to log into the
remote host, or the remote operating system is not supported. Risk
factor : None Plugin output : It was not possible to log into the remote
host via ssh
	=20
	    Am I missing some dependencies somewhere in the rules file?
Just for grins also, I have turned on ALL plugins. I know that is not
desirable, but I was trying anything to get it to log in properly.=20
	=20
	Sincerely,
	Mark
	=20
	=20
	=20
	=20

=09
______________________________________________________________________
=09
	For information pertaining to Willis' email confidentiality and
monitoring policy, usage restrictions, or for specific company
registration and regulatory status information, please visit
http://www.willis.com/email_trailer.aspx
=09
______________________________________________________________________
=09


------_=_NextPart_001_01C98150.7FAFE594
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<META content=3D"MSHTML 6.00.2900.5726" name=3DGENERATOR></HEAD>
<BODY>
<DIV dir=3Dltr align=3Dleft><SPAN class=3D695405713-28012009><FONT =
face=3DArial=20
color=3D#0000ff size=3D2>Hey Mark, I've had problems like that before =
too, though=20
not with all unix/linux systems.</FONT></SPAN></DIV>
<DIV dir=3Dltr align=3Dleft><SPAN class=3D695405713-28012009><FONT =
face=3DArial=20
color=3D#0000ff></FONT></SPAN>&nbsp;</DIV>
<DIV dir=3Dltr align=3Dleft><SPAN class=3D695405713-28012009><FONT =
face=3DArial=20
color=3D#0000ff>Ultimately what we ended up doing was using public key=20
authentication instead, which works fine. Go figure.</FONT></SPAN></DIV>
<DIV>&nbsp;</DIV><!-- Converted from text/plain format -->
<P><FONT size=3D2>--------<BR>Jeff Mercer - CISO - Security =
Vulnerability=20
Assessments<BR>&nbsp;</FONT> </P>
<DIV>&nbsp;</DIV><BR>
<BLOCKQUOTE=20
style=3D"PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #0000ff 2px =
solid; MARGIN-RIGHT: 0px">
  <DIV class=3DOutlookMessageHeader lang=3Den-us dir=3Dltr align=3Dleft>
  <HR tabIndex=3D-1>
  <FONT face=3DTahoma size=3D2><B>From:</B> =
[email protected]=20
  [mailto:[email protected]] <B>On Behalf Of </B>Lambert,=20
  Mark<BR><B>Sent:</B> Tuesday, January 27, 2009 3:04 PM<BR><B>To:</B>=20
  [email protected]<BR><B>Subject:</B> Scanning Linux box with=20
  Credentials<BR></FONT><BR></DIV>
  <DIV></DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20
  size=3D2>All,&nbsp;&nbsp;&nbsp; </FONT></SPAN></DIV>
  <DIV><SPAN class=3D609525119-27012009>&nbsp;&nbsp;&nbsp; <FONT =
face=3DArial=20
  size=3D2>I have having a problem with SSH credentials on an internal =
Linux box=20
  I'm trying to scan. The box I'm scanning is a RedHat box and I can =
manually=20
  SSH with any SSH2 client to it. </FONT></SPAN></DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial size=3D2>I =
supply the=20
  credentials and I get logged in just fine. BUT..... When I configure =
the=20
  settings below in my nessus rules file,</FONT></SPAN></DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20
  size=3D2></FONT></SPAN>&nbsp;</DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial size=3D2>-SSH =

  settings[entry]:SSH user name : =3D XYZ</FONT></SPAN></DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial size=3D2>-SSH =

  settings[entry]:Preferred SSH port : =3D 22</FONT></SPAN></DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial size=3D2>-SSH =

  settings[password]:SSH password (unsafe!) : =3D =
XYZPassword</FONT></SPAN></DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20
  size=3D2></FONT></SPAN>&nbsp;</DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial =
size=3D2>&nbsp;&nbsp;&nbsp;=20
  I get the response below:</FONT></SPAN></DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20
  size=3D2></FONT></SPAN>&nbsp;</DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial size=3D2>The =
local security=20
  checks are disabled. Description: The credentials provided for the =
scan did=20
  not allow us to log into the remote host, or the remote operating =
system is=20
  not supported. Risk factor : None Plugin output : It was not possible =
to log=20
  into the remote host via ssh</FONT></SPAN></DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20
  size=3D2></FONT></SPAN>&nbsp;</DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial =
size=3D2>&nbsp;&nbsp;&nbsp;=20
  Am I missing some dependencies somewhere in the rules file? Just for =
grins=20
  also, I have turned on ALL plugins. I know that is not desirable, but =
I was=20
  trying anything to get it to log in properly. </FONT></SPAN></DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20
  size=3D2></FONT></SPAN>&nbsp;</DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20
  size=3D2>Sincerely,</FONT></SPAN></DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20
  size=3D2>Mark</FONT></SPAN></DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20
  size=3D2></FONT></SPAN>&nbsp;</DIV>
  <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20
  size=3D2></FONT></SPAN>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV align=3Dleft><FONT face=3DArial=20
  =
size=3D2></FONT>&nbsp;</DIV><BR>_________________________________________=
_____________________________<BR><BR>For=20
  information pertaining to Willis' email confidentiality and monitoring =
policy,=20
  usage restrictions, or for specific company registration and =
regulatory status=20
  information, please visit=20
  =
http://www.willis.com/email_trailer.aspx<BR>_____________________________=
_________________________________________<BR></BLOCKQUOTE></BODY></HTML>

------_=_NextPart_001_01C98150.7FAFE594--

--===============1175596149==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus
--===============1175596149==--