I've recently compiled the newest "stable" release of Nessus and have run several tests against some web servers. The results from the scan show a huge number, at least 40 each, of false positives on port 80. Most of the false positives involve cgi-bin. None of the servers have a cgi-bin directory, real or virtual.
Nessus also incorrectly identifies the operating system of each of the servers. They are all running NT. Nessus, or rather Queso seems to think that they're Reliant Unix. I have tried changing the checks_read_timeout value anywhere from 5 to 25 but still get similar results. As a sanity check I have compared the scans with a recent cybercop scan run against the same machines. Cybercop reports 21 infos and/or holes. Nessus is reporting 68 infos and/or holes. Any ideas on this? The nessus server portion is running on Solaris 8. I am also having issues with nessus processes going to sleep on the server. This problem occurs when a scan is run against a larger number of hosts. The number varies from 20 to 60, depending on the checks_read_timeout setting. I have looked through the list archives and found a suggestion to compile without the cipher layer. I have tried this and still get the same results, so I am using the cipher layer again. Thanks in advance for any feedback ======================= Joe Zurba Security Engineer NaviSite, Inc. 400 Minuteman Rd. Andover, MA. 01810 (978) 946-5869 mailto:[EMAIL PROTECTED] http://www.navisite.com =======================
