RE: Scanning Linux box with Credentials
"Mercer, Jeff C - Raleigh, NC" <[email protected]> Wed, 28 Jan 2009 07:58:29 -0600
| Newsgroups | gmane.comp.security.nessus.general |
|---|---|
| Message-ID | <B4FAD131405849469A8FE9C9162AC026035A62FB@EAGNMNSXM12> |
This is a multi-part message in MIME format. --===============1175596149== Content-class: urn:content-classes:message Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C98150.7FAFE594" This is a multi-part message in MIME format. ------_=_NextPart_001_01C98150.7FAFE594 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Hey Mark, I've had problems like that before too, though not with all unix/linux systems. =20 Ultimately what we ended up doing was using public key authentication instead, which works fine. Go figure. =20 -------- Jeff Mercer - CISO - Security Vulnerability Assessments =20 =20 ________________________________ From: [email protected] [mailto:[email protected]] On Behalf Of Lambert, Mark Sent: Tuesday, January 27, 2009 3:04 PM To: [email protected] Subject: Scanning Linux box with Credentials =09 =09 All, =20 I have having a problem with SSH credentials on an internal Linux box I'm trying to scan. The box I'm scanning is a RedHat box and I can manually SSH with any SSH2 client to it.=20 I supply the credentials and I get logged in just fine. BUT..... When I configure the settings below in my nessus rules file, =20 -SSH settings[entry]:SSH user name : =3D XYZ -SSH settings[entry]:Preferred SSH port : =3D 22 -SSH settings[password]:SSH password (unsafe!) : =3D XYZPassword =20 I get the response below: =20 The local security checks are disabled. Description: The credentials provided for the scan did not allow us to log into the remote host, or the remote operating system is not supported. Risk factor : None Plugin output : It was not possible to log into the remote host via ssh =20 Am I missing some dependencies somewhere in the rules file? Just for grins also, I have turned on ALL plugins. I know that is not desirable, but I was trying anything to get it to log in properly.=20 =20 Sincerely, Mark =20 =20 =20 =20 =09 ______________________________________________________________________ =09 For information pertaining to Willis' email confidentiality and monitoring policy, usage restrictions, or for specific company registration and regulatory status information, please visit http://www.willis.com/email_trailer.aspx =09 ______________________________________________________________________ =09 ------_=_NextPart_001_01C98150.7FAFE594 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD> <META http-equiv=3DContent-Type content=3D"text/html; = charset=3Dus-ascii"> <META content=3D"MSHTML 6.00.2900.5726" name=3DGENERATOR></HEAD> <BODY> <DIV dir=3Dltr align=3Dleft><SPAN class=3D695405713-28012009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>Hey Mark, I've had problems like that before = too, though=20 not with all unix/linux systems.</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D695405713-28012009><FONT = face=3DArial=20 color=3D#0000ff></FONT></SPAN> </DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D695405713-28012009><FONT = face=3DArial=20 color=3D#0000ff>Ultimately what we ended up doing was using public key=20 authentication instead, which works fine. Go figure.</FONT></SPAN></DIV> <DIV> </DIV><!-- Converted from text/plain format --> <P><FONT size=3D2>--------<BR>Jeff Mercer - CISO - Security = Vulnerability=20 Assessments<BR> </FONT> </P> <DIV> </DIV><BR> <BLOCKQUOTE=20 style=3D"PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #0000ff 2px = solid; MARGIN-RIGHT: 0px"> <DIV class=3DOutlookMessageHeader lang=3Den-us dir=3Dltr align=3Dleft> <HR tabIndex=3D-1> <FONT face=3DTahoma size=3D2><B>From:</B> = [email protected]=20 [mailto:[email protected]] <B>On Behalf Of </B>Lambert,=20 Mark<BR><B>Sent:</B> Tuesday, January 27, 2009 3:04 PM<BR><B>To:</B>=20 [email protected]<BR><B>Subject:</B> Scanning Linux box with=20 Credentials<BR></FONT><BR></DIV> <DIV></DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20 size=3D2>All, </FONT></SPAN></DIV> <DIV><SPAN class=3D609525119-27012009> <FONT = face=3DArial=20 size=3D2>I have having a problem with SSH credentials on an internal = Linux box=20 I'm trying to scan. The box I'm scanning is a RedHat box and I can = manually=20 SSH with any SSH2 client to it. </FONT></SPAN></DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial size=3D2>I = supply the=20 credentials and I get logged in just fine. BUT..... When I configure = the=20 settings below in my nessus rules file,</FONT></SPAN></DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20 size=3D2></FONT></SPAN> </DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial size=3D2>-SSH = settings[entry]:SSH user name : =3D XYZ</FONT></SPAN></DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial size=3D2>-SSH = settings[entry]:Preferred SSH port : =3D 22</FONT></SPAN></DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial size=3D2>-SSH = settings[password]:SSH password (unsafe!) : =3D = XYZPassword</FONT></SPAN></DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20 size=3D2></FONT></SPAN> </DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial = size=3D2> =20 I get the response below:</FONT></SPAN></DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20 size=3D2></FONT></SPAN> </DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial size=3D2>The = local security=20 checks are disabled. Description: The credentials provided for the = scan did=20 not allow us to log into the remote host, or the remote operating = system is=20 not supported. Risk factor : None Plugin output : It was not possible = to log=20 into the remote host via ssh</FONT></SPAN></DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20 size=3D2></FONT></SPAN> </DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial = size=3D2> =20 Am I missing some dependencies somewhere in the rules file? Just for = grins=20 also, I have turned on ALL plugins. I know that is not desirable, but = I was=20 trying anything to get it to log in properly. </FONT></SPAN></DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20 size=3D2></FONT></SPAN> </DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20 size=3D2>Sincerely,</FONT></SPAN></DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20 size=3D2>Mark</FONT></SPAN></DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20 size=3D2></FONT></SPAN> </DIV> <DIV><SPAN class=3D609525119-27012009><FONT face=3DArial=20 size=3D2></FONT></SPAN> </DIV> <DIV><FONT face=3DArial size=3D2></FONT> </DIV> <DIV align=3Dleft><FONT face=3DArial=20 = size=3D2></FONT> </DIV><BR>_________________________________________= _____________________________<BR><BR>For=20 information pertaining to Willis' email confidentiality and monitoring = policy,=20 usage restrictions, or for specific company registration and = regulatory status=20 information, please visit=20 = http://www.willis.com/email_trailer.aspx<BR>_____________________________= _________________________________________<BR></BLOCKQUOTE></BODY></HTML> ------_=_NextPart_001_01C98150.7FAFE594-- --===============1175596149== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Nessus mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus --===============1175596149==--