Re: What can a Remote Vulnerability Scanner do in Future?
"Aaron" <[email protected]> Wed, 15 Feb 2006 14:01:46 -0800
| Newsgroups | gmane.comp.security.full-disclosure,gmane.comp.security.bugtraq,gmane.comp.security.ntbugtraq |
|---|---|
| Message-ID | <[email protected]> |
Nessus can do local checks on windows/unix from remote.=20 nessus.org. Dont let the good looking web site scare you either. It=20 is still free afaik. :) --Aaron On Mon, 13 Feb 2006 10:16:22 +1100 (EST) Tim Nelson <[email protected]> wrote: > On Mon, 6 Feb 2006, Alice Bryson wrote: >=20 > ... >> Eeye scanner could not do remote local check too. So=20 >>I am consider >> what can Remote Vulnerability Scanner do? Will this=20 >>thing disappear in >> the future? >=20 > Scan for remote vulnerabilities. Scanning for local=20 > vulnerabilities can obviously only be done locally. >=20 > Basically you need to have a remote access method=20 >before you can=20 > do anything remotely. It might be useful to get a=20 >windows version of sshd or cfengine. Another possibility=20 >would be to make the local scanner executable available=20 >on the network, and then have each machine individually=20 >download it and run it locally. >=20 > Basically, to check for local vulnerabilities, you=20 >need: > 1. A deployment process (hopefully simple) > 2. An execution process >=20 > This is exactly what cfengine was designed to solve in=20 >the Unix=20 > world. >=20 > --=20 > Kind Regards, > =A0 > Tim Nelson > Server Administrator > =A0 > P: 03 9934 0888 >F: 03 9934 0899 > E: [email protected] > W: www.webalive.biz > =A0 > WebAlive Technologies > Level 1, Innovation Building > Digital Harbour > 1010 La Trobe Street > Docklands Melbourne VIC 3008 >=20 > This email (including all attachments) is intended=20 >solely for the named addressee. It is confidential and=20 >may contain legally privileged information. If > you receive it in error, please let us know by reply=20 >email, delete it from your system and destroy any copies.=20 >This email is also subject to copyright. No > part of it should be reproduced, adapted or transmitted=20 >without the written consent of the copyright owner. >=20 > Emails may be interfered with, may contain computer=20 >viruses or other defects and may not be successfully=20 >replicated on other systems. We give no > warranties in relation to these matters. If you have any=20 >doubts about the authenticity of an email purportedly=20 >sent by us, please contact us immediately. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/