Tan Herng Hsi <[EMAIL PROTECTED]> writes:

>  Looking under the preferences tab of nessus client GUI, I noticed 2
> sections, HTTP NIDS evasion and libwhisker options.  They seem to
> have similar options  

Yes we planned to merge them. We definitely should do it. Then options that
do not make sense with libwhisker would be ignored.

> Are there any differences in these options?

libwhisker options set options for Whisker and Nikto (and any future
scanner based upon libwhisker)
You can only select *one* option.

The second preference is for Nessus internal HTTP library. You can use
several options (although this is probably a bad idea)

> Another question would be, where can I find information about how CGI.pm 
> semicolon separator can be used as an evasion tactic

http://www.nessus.org/doc/nids.html
http://www.wiretrip.net/rfp/pages/whitepapers/whiskerids.html
http://www.sans.org/rr/intrusion/anti-ids.php
http://www.phrack.com/phrack/54/P54-10
http://downloads.securityfocus.com/library/ids.ps

> and what is the "force protocol string" field for?

You can set your HTTP version to 1.2 by using "HTTP/1.2"
If you want to see the exact behaviour, recompile
nessus-libraries/libnessus/www_funcs.c with -DURL_DEBUG
The interesting function is build_encode_URL()

-- 
mailto:[EMAIL PROTECTED]
GPG Public keys: http://michel.arboi.free.fr/pubkey.txt
http://michel.arboi.free.fr/    http://arboi.da.ru/
FAQNOPI de fr.comp.securite : http://faqnopi.da.ru/

Reply via email to