On Sunday 26 January 2003 19:24, Michel Arboi wrote:
> Tan Herng Hsi <[EMAIL PROTECTED]> writes:
> >  Looking under the preferences tab of nessus client GUI, I noticed 2
> > sections, HTTP NIDS evasion and libwhisker options.  They seem to
> > have similar options
>
> Yes we planned to merge them. We definitely should do it. Then options that
> do not make sense with libwhisker would be ignored.
>
> > Are there any differences in these options?
>
> libwhisker options set options for Whisker and Nikto (and any future
> scanner based upon libwhisker)
> You can only select *one* option.
>
> The second preference is for Nessus internal HTTP library. You can use
> several options (although this is probably a bad idea)
>
> > Another question would be, where can I find information about how CGI.pm
> > semicolon separator can be used as an evasion tactic
>
> http://www.nessus.org/doc/nids.html
> http://www.wiretrip.net/rfp/pages/whitepapers/whiskerids.html
> http://www.sans.org/rr/intrusion/anti-ids.php
> http://www.phrack.com/phrack/54/P54-10
> http://downloads.securityfocus.com/library/ids.ps
>
> > and what is the "force protocol string" field for?
>
> You can set your HTTP version to 1.2 by using "HTTP/1.2"
> If you want to see the exact behaviour, recompile
> nessus-libraries/libnessus/www_funcs.c with -DURL_DEBUG
> The interesting function is build_encode_URL()


Thanks for you fast reply,
However, I am not quite sure what you mean when you say " libwhisker options 
set options for Whisker and Nikto" and "The second preference is for Nessus 
internal HTTP library".
>From my understanding, am I correct to say that nessus has incorporated a 
whisker scanner in itself and also have its very own program that does NIDS 
evasion?

Thank you for your kind attention.
Tan Herng Hsi


Reply via email to