My understanding was that Nessus did not use the grepable (-oG) nmap format, just the normal (-oN).
-j On Thu, 25 Apr 2002, Michael Hornung wrote: > I'm positive this has been covered before, but somehow I can't find a post > that describes to me what I need to do. I want to separately scan with > Nmap, then fire up Nessus to run certain tests on certain boxes. It > doesn't appear to work the way I think it should. I'm currently doing > this: > > $ nessus -v > nessus (Nessus) 1.2.0 for Linux > # /usr/local/sbin/nessusd -v > nessusd (Nessus) 1.2.0 for Linux > > $ nmap -V > nmap V. 2.54BETA32 > $ nmap -O -sS -sU -Tinsane -oG nmap.out X.Y.Z.0/24 > > Then I want to slurp only the relevant results into nessus to fire off > some NASL scripts: > > $ grep "139/open" nmap.out | cut -d" " -f2 >> newtargets > $ nessus -V -c nessusrc -T nsr -q nessusd-server 1241 username \ > password newtargets output-`date +%y%m%d`.nsr > scan.log > > This is what I've got (regarding nmap) in my nessusrc: > > $ grep -i nmap nessusrc > Nmap[radio]:TCP scanning technique : = SYN scan > Nmap[checkbox]:UDP port scan = no > Nmap[checkbox]:RPC port scan = no > Nmap[checkbox]:Ping the remote host = yes > Nmap[checkbox]:Identify the remote OS = no > Nmap[checkbox]:Use hidden option to identify the remote OS = no > Nmap[checkbox]:Fragment IP packets (bypasses firewalls) = no > Nmap[checkbox]:Get Identd info = no > Nmap[checkbox]:Perform a fast scan = no > Nmap[checkbox]:Do not randomize the order in which ports are scanned = yes > Nmap[entry]:Source port : = any > Nmap[radio]:Timing policy : = Insane > Nmap[entry]:Host Timeout (ms) : = 1000 > Nmap[radio]:Port range = Default range (nmap-services + privileged ports) > Nmap[file]:File containing nmap's results : = >/home/hornung/windows-password/nmap.out > Nmap[entry]:Min RTT Timeout (ms) : = > Nmap[entry]:Max RTT Timeout (ms) : = > Nmap[entry]:Initial RTT timeout (ms) = > Nmap[entry]:Ports scanned in parallel = > Nmap[entry]:Minimum wait between probes (ms) = > > Can someone please tell me why this isn't working? If you need more > information I'd be happy to share. Nessus appears to ping all of the > hosts in question, and the scan.log indicates that it fired off a bunch of > scripts, but there is no output in the NSR file (it has size 0) when it is > finished. > > ____________________________________________________________________________ > Michael Hornung, University Computing Services, Computing & Communications > Email: [EMAIL PROTECTED] Phone: 206.221.4634 Fax: 206.221.6966 > PGP Public Key 0x82B06992 = http://staff.washington.edu/hornung/key.html > -- Joe Mondloch Network Security Engineer Berbee 5520 Research Park Drive Madison, WI 53711 [EMAIL PROTECTED] 608.298.1096 Fax 608.288.3007
