Well, now find_service.nes is running, but I still see no packets sent against the 
target?

What else should we be looking for to help you?

Jim
(nessusd.log of the scan with "Services" also enabled)

[Fri Jun 20 10:19:46 2003][24565] connection from 127.0.0.1 
[Fri Jun 20 10:19:46 2003][24625] Client requested protocol version 12. 
[Fri Jun 20 10:19:47 2003][24625] successful login of hendrick from 127.0.0.1 
[Fri Jun 20 10:19:51 2003][24625] Redirecting debugging output to 
/usr/local/var/nessus/logs/nessusd.dump 
[Fri Jun 20 10:21:49 2003][24625] user hendrick starts a new attack. Target(s) : 
192.168.0.6, with max_hosts = 30 and max_checks = 10 
[Fri Jun 20 10:21:49 2003][24625] user hendrick : testing 192.168.0.6 (192.168.0.6) 
[24626] 
[Fri Jun 20 10:21:49 2003][24626] user hendrick : new KB will be saved as 
/usr/local/var/nessus/users/hendrick/kbs/192.168.0.6
[Fri Jun 20 10:21:49 2003][24626] user hendrick : launching find_service.nes against 
192.168.0.6 [24627] 
[Fri Jun 20 10:21:49 2003][24626] user hendrick : launching hydra.nes against 
192.168.0.6 [24628] 
[Fri Jun 20 10:21:49 2003][24626] find_service.nes (process 24627) finished its job in 
0.021 seconds 
[Fri Jun 20 10:21:49 2003][24626] hydra.nes (process 24628) finished its job in 0.018 
seconds 
[Fri Jun 20 10:21:49 2003][24626] Finished testing 192.168.0.6. Time : 0.08 secs 
[Fri Jun 20 10:21:49 2003][24625] user hendrick : test complete
[Fri Jun 20 10:21:49 2003][24625] user hendrick : Kept alive connection


> -----Original Message-----
> From: Renaud Deraison [mailto:[EMAIL PROTECTED]
> Sent: Friday, June 20, 2003 10:16 AM
> To: [EMAIL PROTECTED]
> Subject: Re: how to use Hydra plugin in nessus
> 
> 
> On Fri, Jun 20, 2003 at 09:58:58AM -0400, James R. Hendrick wrote:
> > Then I started nessus & logged in, making the following selections:
> > Under "Plugins"
> >   disabled all plugins
> >   enabled Brute Force Login (within Misc.)
> 
> 
> >   enabled add dependencies at runtime
> 
> Okay, I found the issue : hydra has no dependencie on 
> find_service.nes,
> and if a service is not identified, it does not fall back to 
> its default
> port.
> 
> Short term solution : in 'Misc.', enable 'Services' as well as 'Brute
> force Login'.
> 
> Long term : Nessus 2.0.7 will have a fixed hydra (proper dependencie,
> proper fallback).
> 

Reply via email to