The most likely problem is Nessus is being run too hot and some packets are
getting dropped or ignored.

Lower the Max Threads value and raise the timeout values.

Although, I still predict you'll have some differences. On a given network
of any size you will always have dropped packets (by the switches, routers,
the workstations network cards, etc).

Normal network traffic accounts for this as they expect a connection to
occur and deal with dropped packets accordingly.

Forged traffic (as in the case of Nessus) may not deal as gracefully. It
doesn't know whether a packet was dropped or ignored by the end-point.

-rjf





-----Original Message-----
From: Wespe, Andreas [mailto:[EMAIL PROTECTED]] 
Sent: Thursday, January 24, 2002 3:11 AM
To: [EMAIL PROTECTED]
Subject: General Issues


Hello,

I have done several checks with nessus and repeated them twice. I thought
the results should me identical, but they werent:

>>>>>>>>>>>>>>>>>>>> Test 1

Start Time   : 24.01.2002 08:33:45
Finish Time  : 24.01.2002 08:44:05
Elapsed Time : 0 day(s) 00:10:20


Total security holes found : 163
             high severity : 5
              low severity : 86
             informational : 72


Scanned hosts:

Name                            High  Low   Info
------------------------------------------------
server01                    1     14    12   
server02                    0     14    12   
server03                    4     20    12   
server04                    0     11    12   
server05                    0     14    12   
server06                    0     13    12   

>>>>>>>>>>>>>>>>>>>> Test 2

Start Time   : 24.01.2002 08:45:15
Finish Time  : 24.01.2002 09:16:33
Elapsed Time : 0 day(s) 00:31:17


Total security holes found : 165
             high severity : 5
              low severity : 88
             informational : 72


Scanned hosts:

Name                            High  Low   Info
------------------------------------------------
server01                   1     16    12   
server02                   0     14    12   
server03                   4     20    12   
server04                   0     13    12   
server05                   0     13    12   
server06                   0     12    12   

>>>>>>>>>>>>>>>>>>>> Test 3

Start Time   : 24.01.2002 09:16:50
Finish Time  : 24.01.2002 09:34:35
Elapsed Time : 0 day(s) 00:17:45


Total security holes found : 151
             high severity : 2
              low severity : 77
             informational : 72


Scanned hosts:

Name                            High  Low   Info
------------------------------------------------
server01                   1     17   12   
server02                   0     12   12   
server03                   1     11   12   
server04                   0     12    12   
server05                   0     13    12   
server06                   0     13    12   

Any Ideas why this happens ??

mit freundlichen Gr��en

Andreas Wespe
BCC Braunschweiger Communication Carrier GmbH
Mittelweg 7-8, 38106 Braunschweig

Tel.: +49 531 / 383 4365
Fax: +49 531 / 383 4397
[EMAIL PROTECTED]
home: <http://www.bcc.de> 

Reply via email to