On Fri, Nov 07, 2003 at 04:37:19PM -0500, Beirne Konarski wrote:
> I'm using the msrpc_dcom2 script to look for unpatched systems. Things were
> going well until yesterday morning's 6am scan when a bunch of PCs showed up
> as vulnerable that were fixed a long time ago. I rescanned some of them by
> hand this afternoon and they don't show as vulnerable. Has anyone seen this
> or have any ideas as to what might be happening?
Maybe a bandwidth issue - try to increase checks_read_timeout in your
.nessusrc.
> On a losely related note, when selecting a number of hosts to scan in
> parallel, does accuracy suffer if the number is too high? What is a good
> criteria to adjust this number?
Accuracy will suffer if you configure Nessus in such a way that it uses
more bandwidth than your network can offer. While we have a pretty
conservative approach to packet loss and bandwidth issues, the default
timeout value of 5 seconds might be insufficient in some cases.
-- Renaud