Re: What can a Remote Vulnerability Scanner do in Future?

"Aaron" <[email protected]> Wed, 15 Feb 2006 14:01:46 -0800
Newsgroups gmane.comp.security.full-disclosure,gmane.comp.security.bugtraq,gmane.comp.security.ntbugtraq
Message-ID <[email protected]>
Nessus can do local checks on windows/unix from remote.=20
 nessus.org.

Dont let the good looking web site scare you either.  It=20
is still free afaik.

:)

--Aaron


On Mon, 13 Feb 2006 10:16:22 +1100 (EST)
  Tim Nelson <[email protected]> wrote:
> On Mon, 6 Feb 2006, Alice Bryson wrote:
>=20
> ...
>>    Eeye scanner could not do remote local check too. So=20
>>I am consider
>> what can Remote Vulnerability Scanner do? Will this=20
>>thing disappear in
>> the future?
>=20
> 	Scan for remote vulnerabilities.  Scanning for local=20
> vulnerabilities can obviously only be done locally.
>=20
> 	Basically you need to have a remote access method=20
>before you can=20
> do anything remotely.  It might be useful to get a=20
>windows version of sshd or cfengine.  Another possibility=20
>would be to make the local scanner executable available=20
>on the network, and then have each machine individually=20
>download it and run it locally.
>=20
> 	Basically, to check for local vulnerabilities, you=20
>need:
> 1.	A deployment process (hopefully simple)
> 2.	An execution process
>=20
> 	This is exactly what cfengine was designed to solve in=20
>the Unix=20
> world.
>=20
> --=20
> Kind Regards,
> =A0
> Tim Nelson
> Server Administrator
> =A0
> P: 03 9934 0888
>F: 03 9934 0899
> E: [email protected]
> W: www.webalive.biz
> =A0
> WebAlive Technologies
> Level 1, Innovation Building
> Digital Harbour
> 1010 La Trobe Street
> Docklands Melbourne VIC 3008
>=20
> This email (including all attachments) is intended=20
>solely for the named addressee. It is confidential and=20
>may contain legally privileged information. If
> you receive it in error, please let us know by reply=20
>email, delete it from your system and destroy any copies.=20
>This email is also subject to copyright. No
> part of it should be reproduced, adapted or transmitted=20
>without the written consent of the copyright owner.
>=20
> Emails may be interfered with, may contain computer=20
>viruses or other defects and may not be successfully=20
>replicated on other systems. We give no
> warranties in relation to these matters. If you have any=20
>doubts about the authenticity of an email purportedly=20
>sent by us, please contact us immediately.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/