> From: Renaud Deraison [mailto:[EMAIL PROTECTED]] > Sent: Friday, April 26, 2002 3:30 AM > To: '[EMAIL PROTECTED]' > Subject: Re: Reporting from the KB > > > On Thu, Apr 25, 2002 at 10:24:38PM -0400, Dion Stempfley wrote: > > I have had a few problems with a series of tests and had to > break up the > > scans and rerun some portions. Not every test resulted in > an output file. > > (I'm still working on what happened). > > > > What I'm really looking for is the ability to produce a > full report from the > > knowlege base only. > > use grep to extract the keys "SentData/" and you will be able > to produce > a session out of it, then you'll be able to restore it. > Thanks, I'll try that
> > >I want to combine the target lists from all my scans > > and set the server to not replay any attacks. When I do > this I don't seem > > to get any results. > > What do you .nessusrc look like ? What version of Nessus are > you using ? > What is being said in nessusd.messages ? > most of .nessusrc is below. The nessusd.messages looks normal to me. It shows plugins with messages that say the plugin has been run before. But after all the work is done I get an nbe with only timestamp entries in it, no results. If I add a plugin or a host, then I get results for the test that ran only. I'm sure I'm doing something wrong. Dion > > -- Renaud > #### NESSUSRC # This file was automagically created by nessus trusted_ca = /usr/local/com/nessus/CA/cacert.pem nessusd_host = 127.0.0.1 nessusd_user = username paranoia_level = 1 begin(SCANNER_SET) 10180 = yes 10277 = no 10278 = no 10331 = no 10335 = no 10841 = yes 10336 = yes 10796 = no end(SCANNER_SET) begin(SERVER_PREFS) auto_enable_dependencies = no save_session = no save_empty_sessions = no host_expansion = ip ping_hosts = no reverse_lookup = no optimize_test = yes safe_checks = yes use_mac_addr = no detached_scan = no continuous_scan = no unscanned_closed = no save_knowledge_base = yes only_test_hosts_whose_kb_we_dont_have = no only_test_hosts_whose_kb_we_have = no kb_restore = yes kb_dont_replay_scanners = yes kb_dont_replay_info_gathering = yes kb_dont_replay_attacks = yes kb_dont_replay_denials = yes diff_scan = no kb_max_age = 864000 max_hosts = 30 max_checks = 10 log_whole_attack = yes cgi_path = /cgi-bin:/scripts port_range = 1-15000 language = english per_user_base = /usr/local/var/nessus/users checks_read_timeout = 15 delay_between_tests = 1 non_simult_ports = 139 plugins_timeout = 320 plugin_upload = no plugin_upload_suffixes = .nasl end(SERVER_PREFS) begin(SERVER_INFO) server_info_nessusd_version = 1.2.0 server_info_libnasl_version = 1.2.0 server_info_libnessus_version = 1.2.0 server_info_thread_manager = fork server_info_os = Linux server_info_os_version = 2.4.9-13 end(SERVER_INFO) begin(RULES) end(RULES) begin(PLUGIN_SET) <REMOVED> end(PLUGIN_SET) begin(PLUGINS_PREFS) BlackIce DoS (ping flood)[entry]:Flood length : = 500 HTTP NIDS evasion[checkbox]:Use HTTP HEAD instead of GET = no HTTP NIDS evasion[radio]:URL encoding = none HTTP NIDS evasion[radio]:Absolute URI type = none HTTP NIDS evasion[radio]:Absolute URI host = none HTTP NIDS evasion[checkbox]:Double slashes = no HTTP NIDS evasion[radio]:Reverse traversal = none HTTP NIDS evasion[checkbox]:Self-reference directories = no HTTP NIDS evasion[checkbox]:Premature request ending = no HTTP NIDS evasion[checkbox]:CGI.pm semicolon separator = no HTTP NIDS evasion[checkbox]:Parameter hiding = no HTTP NIDS evasion[checkbox]:Dos/Windows syntax = no HTTP NIDS evasion[checkbox]:Null method = no HTTP NIDS evasion[checkbox]:TAB separator = no HTTP NIDS evasion[checkbox]:HTTP/0.9 requests = no NIDS evasion[radio]:TCP evasion technique = none NIDS evasion[checkbox]:Send fake RST when establishing a TCP connection = no Logins configuration[entry]:FTP account : = anonymous Logins configuration[password]:FTP password (sent in clear) : = [EMAIL PROTECTED] Logins configuration[entry]:FTP writeable directory : = /incoming SMB Scope[checkbox]:Request information about the domain = yes SMB use host SID to enumerate local users[entry]:Start UID : = 1000 SMB use host SID to enumerate local users[entry]:End UID : = 1200 SMB use domain SID to enumerate users[entry]:Start UID : = 1000 SMB use domain SID to enumerate users[entry]:End UID : = 1200 Web mirroring[entry]:Number of pages to mirror : = 10 Web mirroring[entry]:Start page : = / Default accounts[entry]:Simultaneous connections : = 10 Services[radio]:Test SSL based services = All Services[checkbox]:Quick SOCKS proxy checking = yes ftp writeable directories[radio]:How to check if directories are writeable : = Trust the permissions (drwxrwx---) Brute force login (Hydra)[entry]:Number of simultaneous connections : = 4 Brute force login (Hydra)[checkbox]:Brute force telnet = yes Brute force login (Hydra)[checkbox]:Brute force FTP = yes Brute force login (Hydra)[checkbox]:Brute force POP3 = yes Brute force login (Hydra)[checkbox]:Brute force IMAP = yes Brute force login (Hydra)[checkbox]:Brute force cisco = yes Brute force login (Hydra)[checkbox]:Brute force VNC = yes Brute force login (Hydra)[checkbox]:Brute force SOCKS 5 = yes Brute force login (Hydra)[checkbox]:Brute force rexec = yes Brute force login (Hydra)[checkbox]:Brute force NNTP = yes Brute force login (Hydra)[checkbox]:Brute force HTTP = yes Brute force login (Hydra)[checkbox]:Brute force ICQ = yes Brute force login (Hydra)[checkbox]:Brute force PCNFS = yes Brute force login (Hydra)[checkbox]:Brute force SMB = yes Whisker[checkbox]:Also test HTTPS servers (SSL patch by H.D. Moore) = yes Whisker[radio]:IDS evasive mode: = X (none) Whisker[radio]:Method: = 1 HEAD method (default) Whisker[radio]:Alternate database format: = X standard Whisker[checkbox]:Brute force usernames via directories = no Ping the remote host[entry]:TCP ping destination port : = 80 Ping the remote host[checkbox]:Do a TCP ping = yes Ping the remote host[checkbox]:Do an ICMP ping = no Ping the remote host[entry]:Number of retries (ICMP) : = 10 Ping the remote host[checkbox]:Make the dead hosts appear in the report = no FTP bounce scan[entry]:FTP server to use : = localhost Nmap[radio]:TCP scanning technique : = SYN scan Nmap[checkbox]:UDP port scan = no Nmap[checkbox]:RPC port scan = no Nmap[checkbox]:Ping the remote host = no Nmap[checkbox]:Identify the remote OS = yes Nmap[checkbox]:Use hidden option to identify the remote OS = no Nmap[checkbox]:Fragment IP packets (bypasses firewalls) = no Nmap[checkbox]:Get Identd info = no Nmap[radio]:Port range = Fast scan (nmap-services) Nmap[checkbox]:Do not randomize the order in which ports are scanned = yes Nmap[entry]:Source port : = any Nmap[radio]:Timing policy : = Normal Nmap[file]:File containing nmap's results : = /tmp/scan.nmap SNMP port scan[entry]:Community name : = public SNMP port scan[radio]:SNMP protocol : = 1 SNMP port scan[radio]:SNMP transport layer : = udp Services[entry]:Network connection timeout : = 5 Services[entry]:Network read/write timeout : = 5 Login configurations[entry]:FTP account : = anonymous Login configurations[password]:FTP password (sent in clear) : = [EMAIL PROTECTED] Login configurations[entry]:FTP writeable directory : = /incoming Login configurations[entry]:SMB account : = Login configurations[password]:SMB password (sent in clear) : = Services[file]:SSL certificate : = Services[file]:SSL private key : = Services[password]:PEM password : = Services[file]:CA file : = Brute force login (Hydra)[file]:Logins file : = Brute force login (Hydra)[file]:Passwords file : = Brute force login (Hydra)[entry]:Web page to brute force : = Login configurations[entry]:HTTP account : = Login configurations[password]:HTTP password (sent in clear) : = Login configurations[entry]:POP2 account : = Login configurations[password]:POP2 password (sent in clear) : = Login configurations[entry]:POP3 account : = Login configurations[password]:POP3 password (sent in clear) : = Login configurations[entry]:IMAP account : = Login configurations[password]:IMAP password (sent in clear) : = Login configurations[entry]:SMB domain (optional) : = Nmap[entry]:Host Timeout (ms) : = Nmap[entry]:Min RTT Timeout (ms) : = Nmap[entry]:Max RTT Timeout (ms) : = Nmap[entry]:Initial RTT timeout (ms) = Nmap[entry]:Ports scanned in parallel = Nmap[entry]:Minimum wait between probes (ms) = SNMP port scan[entry]:TCP/UDP port : = SNMP port scan[entry]:Number of retries : = SNMP port scan[entry]:Timeout between retries : = Whisker[file]:script database: = Whisker[file]:Password file: = end(PLUGINS_PREFS)
