Re: What can a Remote Vulnerability Scanner do in Future?

Tim Nelson <[email protected]> Mon, 13 Feb 2006 10:16:22 +1100 (EST)
Newsgroups gmane.comp.security.full-disclosure,gmane.comp.security.bugtraq,gmane.comp.security.ntbugtraq
Message-ID <[email protected]>
  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

--0-1984922602-1139786181=:8318
Content-Type: TEXT/PLAIN; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On Mon, 6 Feb 2006, Alice Bryson wrote:

...
>    Eeye scanner could not do remote local check too. So I am consider
> what can Remote Vulnerability Scanner do? Will this thing disappear in
> the future?

 	Scan for remote vulnerabilities.  Scanning for local=20
vulnerabilities can obviously only be done locally.

 	Basically you need to have a remote access method before you can=20
do anything remotely.  It might be useful to get a windows version of ssh=
d=20
or cfengine.  Another possibility would be to make the local scanner=20
executable available on the network, and then have each machine=20
individually download it and run it locally.

 	Basically, to check for local vulnerabilities, you need:
1.	A deployment process (hopefully simple)
2.	An execution process

 	This is exactly what cfengine was designed to solve in the Unix=20
world.

--=20
Kind Regards,
=A0
Tim Nelson
Server Administrator
=A0
P: 03 9934 0888
F: 03 9934 0899
E: [email protected]
W: www.webalive.biz
=A0
WebAlive Technologies
Level 1, Innovation Building
Digital Harbour
1010 La Trobe Street
Docklands Melbourne VIC 3008

This email (including all attachments) is intended solely for the named a=
ddressee. It is confidential and may contain legally privileged informati=
on. If
you receive it in error, please let us know by reply email, delete it fro=
m your system and destroy any copies. This email is also subject to copyr=
ight. No
part of it should be reproduced, adapted or transmitted without the writt=
en consent of the copyright owner.

Emails may be interfered with, may contain computer viruses or other defe=
cts and may not be successfully replicated on other systems. We give no
warranties in relation to these matters. If you have any doubts about the=
 authenticity of an email purportedly sent by us, please contact us immed=
iately.

--0-1984922602-1139786181=:8318
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
--0-1984922602-1139786181=:8318--