> From: Renaud Deraison [mailto:[EMAIL PROTECTED]]
> Sent: Friday, April 26, 2002 3:30 AM
> To: '[EMAIL PROTECTED]'
> Subject: Re: Reporting from the KB
> 
> 
> On Thu, Apr 25, 2002 at 10:24:38PM -0400, Dion Stempfley wrote:
> > I have had a few problems with a series of tests and had to 
> break up the
> > scans and rerun some portions.  Not every test resulted in 
> an output file.
> > (I'm still working on what happened).
> > 
> > What I'm really looking for is the ability to produce a 
> full report from the
> > knowlege base only.  
> 
> use grep to extract the keys "SentData/" and you will be able 
> to produce
> a session out of it, then you'll be able to restore it.
> 
Thanks, I'll try that

> 
> >I want to combine the target lists from all my scans
> > and set the server to not replay any attacks.  When I do 
> this I don't seem
> > to get any results. 
> 
> What do you .nessusrc look like ? What version of Nessus are 
> you using ?
> What is being said in nessusd.messages ?
> 
most of .nessusrc is below.  The nessusd.messages looks normal to me.  It
shows plugins with messages that say the plugin has been run before.  But
after all the work is done I get an nbe with only timestamp entries in it,
no results.  If I add a plugin or a host, then I get results for the test
that ran only.  I'm sure I'm doing something wrong.

Dion
> 
>                               -- Renaud
> 
#### NESSUSRC
# This file was automagically created by nessus
trusted_ca = /usr/local/com/nessus/CA/cacert.pem
nessusd_host = 127.0.0.1
nessusd_user = username
paranoia_level = 1
begin(SCANNER_SET)
 10180 = yes
 10277 = no
 10278 = no
 10331 = no
 10335 = no
 10841 = yes
 10336 = yes
 10796 = no
end(SCANNER_SET)

begin(SERVER_PREFS)
 auto_enable_dependencies = no
 save_session = no
 save_empty_sessions = no
 host_expansion = ip
 ping_hosts = no
 reverse_lookup = no
 optimize_test = yes
 safe_checks = yes
 use_mac_addr = no
 detached_scan = no
 continuous_scan = no
 unscanned_closed = no
 save_knowledge_base = yes
 only_test_hosts_whose_kb_we_dont_have = no
 only_test_hosts_whose_kb_we_have = no
 kb_restore = yes
 kb_dont_replay_scanners = yes
 kb_dont_replay_info_gathering = yes
 kb_dont_replay_attacks = yes
 kb_dont_replay_denials = yes
 diff_scan = no
 kb_max_age = 864000
 max_hosts = 30
 max_checks = 10
 log_whole_attack = yes
 cgi_path = /cgi-bin:/scripts
 port_range = 1-15000
 language = english
 per_user_base = /usr/local/var/nessus/users
 checks_read_timeout = 15
 delay_between_tests = 1
 non_simult_ports = 139
 plugins_timeout = 320
 plugin_upload = no
 plugin_upload_suffixes = .nasl
end(SERVER_PREFS)

begin(SERVER_INFO)
 server_info_nessusd_version = 1.2.0
 server_info_libnasl_version = 1.2.0
 server_info_libnessus_version = 1.2.0
 server_info_thread_manager = fork
 server_info_os = Linux
 server_info_os_version = 2.4.9-13
end(SERVER_INFO)

begin(RULES)
end(RULES)

begin(PLUGIN_SET)
<REMOVED>
end(PLUGIN_SET)

begin(PLUGINS_PREFS)
 BlackIce DoS (ping flood)[entry]:Flood length : = 500
 HTTP NIDS evasion[checkbox]:Use HTTP HEAD instead of GET = no
 HTTP NIDS evasion[radio]:URL encoding = none
 HTTP NIDS evasion[radio]:Absolute URI type = none
 HTTP NIDS evasion[radio]:Absolute URI host = none
 HTTP NIDS evasion[checkbox]:Double slashes = no
 HTTP NIDS evasion[radio]:Reverse traversal = none
 HTTP NIDS evasion[checkbox]:Self-reference directories = no
 HTTP NIDS evasion[checkbox]:Premature request ending = no
 HTTP NIDS evasion[checkbox]:CGI.pm semicolon separator = no
 HTTP NIDS evasion[checkbox]:Parameter hiding = no
 HTTP NIDS evasion[checkbox]:Dos/Windows syntax = no
 HTTP NIDS evasion[checkbox]:Null method = no
 HTTP NIDS evasion[checkbox]:TAB separator = no
 HTTP NIDS evasion[checkbox]:HTTP/0.9 requests = no
 NIDS evasion[radio]:TCP evasion technique = none
 NIDS evasion[checkbox]:Send fake RST when establishing a TCP connection =
no
 Logins configuration[entry]:FTP account : = anonymous
 Logins configuration[password]:FTP password (sent in clear) : =
[EMAIL PROTECTED]
 Logins configuration[entry]:FTP writeable directory : = /incoming
 SMB Scope[checkbox]:Request information about the domain = yes
 SMB use host SID to enumerate local users[entry]:Start UID : = 1000
 SMB use host SID to enumerate local users[entry]:End UID : = 1200
 SMB use domain SID to enumerate users[entry]:Start UID : = 1000
 SMB use domain SID to enumerate users[entry]:End UID : = 1200
 Web mirroring[entry]:Number of pages to mirror : = 10
 Web mirroring[entry]:Start page : = /
 Default accounts[entry]:Simultaneous connections : = 10
 Services[radio]:Test SSL based services = All
 Services[checkbox]:Quick SOCKS proxy checking = yes
 ftp writeable directories[radio]:How to check if directories are writeable
: = Trust the permissions (drwxrwx---)
 Brute force login (Hydra)[entry]:Number of simultaneous connections : = 4
 Brute force login (Hydra)[checkbox]:Brute force telnet = yes
 Brute force login (Hydra)[checkbox]:Brute force FTP = yes
 Brute force login (Hydra)[checkbox]:Brute force POP3 = yes
 Brute force login (Hydra)[checkbox]:Brute force IMAP = yes
 Brute force login (Hydra)[checkbox]:Brute force cisco = yes
 Brute force login (Hydra)[checkbox]:Brute force VNC = yes
 Brute force login (Hydra)[checkbox]:Brute force SOCKS 5 = yes
 Brute force login (Hydra)[checkbox]:Brute force rexec = yes
 Brute force login (Hydra)[checkbox]:Brute force NNTP = yes
 Brute force login (Hydra)[checkbox]:Brute force HTTP = yes
 Brute force login (Hydra)[checkbox]:Brute force ICQ = yes
 Brute force login (Hydra)[checkbox]:Brute force PCNFS = yes
 Brute force login (Hydra)[checkbox]:Brute force SMB = yes
 Whisker[checkbox]:Also test HTTPS servers (SSL patch by H.D. Moore) = yes
 Whisker[radio]:IDS evasive mode: = X (none)
 Whisker[radio]:Method: = 1 HEAD method (default)
 Whisker[radio]:Alternate database format: = X standard
 Whisker[checkbox]:Brute force usernames via directories = no
 Ping the remote host[entry]:TCP ping destination port : = 80
 Ping the remote host[checkbox]:Do a TCP ping = yes
 Ping the remote host[checkbox]:Do an ICMP ping = no
 Ping the remote host[entry]:Number of retries (ICMP) : = 10
 Ping the remote host[checkbox]:Make the dead hosts appear in the report =
no
 FTP bounce scan[entry]:FTP server to use : = localhost
 Nmap[radio]:TCP scanning technique : = SYN scan
 Nmap[checkbox]:UDP port scan = no
 Nmap[checkbox]:RPC port scan = no
 Nmap[checkbox]:Ping the remote host = no
 Nmap[checkbox]:Identify the remote OS = yes
 Nmap[checkbox]:Use hidden option to identify the remote OS = no
 Nmap[checkbox]:Fragment IP packets (bypasses firewalls) = no
 Nmap[checkbox]:Get Identd info = no
 Nmap[radio]:Port range = Fast scan (nmap-services)
 Nmap[checkbox]:Do not randomize the  order  in  which ports are scanned =
yes
 Nmap[entry]:Source port : = any
 Nmap[radio]:Timing policy : = Normal
 Nmap[file]:File containing nmap's results : = /tmp/scan.nmap
 SNMP port scan[entry]:Community name : = public
 SNMP port scan[radio]:SNMP protocol : = 1
 SNMP port scan[radio]:SNMP transport layer : = udp
 Services[entry]:Network connection timeout : = 5
 Services[entry]:Network read/write timeout : = 5
 Login configurations[entry]:FTP account : = anonymous
 Login configurations[password]:FTP password (sent in clear) : =
[EMAIL PROTECTED]
 Login configurations[entry]:FTP writeable directory : = /incoming
 Login configurations[entry]:SMB account : = 
 Login configurations[password]:SMB password (sent in clear) : = 
 Services[file]:SSL certificate : = 
 Services[file]:SSL private key : = 
 Services[password]:PEM password : = 
 Services[file]:CA file : = 
 Brute force login (Hydra)[file]:Logins file : = 
 Brute force login (Hydra)[file]:Passwords file : = 
 Brute force login (Hydra)[entry]:Web page to brute force : = 
 Login configurations[entry]:HTTP account : = 
 Login configurations[password]:HTTP password (sent in clear) : = 
 Login configurations[entry]:POP2 account : = 
 Login configurations[password]:POP2 password (sent in clear) : = 
 Login configurations[entry]:POP3 account : = 
 Login configurations[password]:POP3 password (sent in clear) : = 
 Login configurations[entry]:IMAP account : = 
 Login configurations[password]:IMAP password (sent in clear) : = 
 Login configurations[entry]:SMB domain (optional) : = 
 Nmap[entry]:Host Timeout (ms) : = 
 Nmap[entry]:Min RTT Timeout (ms) : = 
 Nmap[entry]:Max RTT Timeout (ms) : = 
 Nmap[entry]:Initial RTT timeout (ms) = 
 Nmap[entry]:Ports scanned in parallel = 
 Nmap[entry]:Minimum wait between probes (ms) = 
 SNMP port scan[entry]:TCP/UDP port : = 
 SNMP port scan[entry]:Number of retries : = 
 SNMP port scan[entry]:Timeout between retries : = 
 Whisker[file]:script database: = 
 Whisker[file]:Password file: = 
end(PLUGINS_PREFS)


Reply via email to