Par ot the answer is in your post - the fact that ssh_insertion doesn't
report a vulnerability when run manually is because version 1.2.25
isn't vulnerable - only versions up to 1.2.23.

However, if you were to run ssh_crc32.nasl, THAT one should
report back positive.  Can't tell you why it didn't. (Try
running that one by hand. I confirmed it reports back positive
with your banner... in a testbed.

Thomas

Daniel Harrison wrote:
> # nc xxx.xxx.x.xxx 22
> SSH-1.5-1.2.27

Reply via email to