Par ot the answer is in your post - the fact that ssh_insertion doesn't report a vulnerability when run manually is because version 1.2.25 isn't vulnerable - only versions up to 1.2.23.
However, if you were to run ssh_crc32.nasl, THAT one should report back positive. Can't tell you why it didn't. (Try running that one by hand. I confirmed it reports back positive with your banner... in a testbed. Thomas Daniel Harrison wrote: > # nc xxx.xxx.x.xxx 22 > SSH-1.5-1.2.27
