Okay. Wrong plugin...damn I hate that. Trying the crc one from the
command line returned success but (with that one enabled now and the
safe check set to no) nessus, using the gui still doesn't report it.
=/

-dan

Thomas Reinke wrote:
> 
> Par ot the answer is in your post - the fact that ssh_insertion doesn't
> report a vulnerability when run manually is because version 1.2.25
> isn't vulnerable - only versions up to 1.2.23.
> 
> However, if you were to run ssh_crc32.nasl, THAT one should
> report back positive.  Can't tell you why it didn't. (Try
> running that one by hand. I confirmed it reports back positive
> with your banner... in a testbed.
> 
> Thomas
> 
> Daniel Harrison wrote:
> > # nc xxx.xxx.x.xxx 22
> > SSH-1.5-1.2.27

-- 
Daniel Harrison    Security Engineer    Loudcloud, Inc.
408.744.7809
"Past performance does not guarantee future results."

Reply via email to