Hi List-

I’m doing a review of a few fairly simple web servers behind a firewall
(I’m guessing it’s a checkpoint).  Before using Nessus I ran Nmap - I did
a TCP connect scan looking for only a few specific ports
(80,443,23,22,21,8080) and the results were accurate (manually verified).  

However, when scanning using Nessus, the port scans do not pick up any
active ports.  I’ve tried using and setting all of the various options and
none seem to help, a FIN scan reports all ports as open (which I expected
since this is a windows shop) but syn and connect scans report nothing open,
and I know these are live hosts - the only result on the scan reports has
been that the host is up.

I’m hoping someone can take a look at this and clue me in on my newbie
error.  

I am running Nessus 2.0.9, Nmap 3.0, the WX client, and am scanning via 56K
modem.  I have pasted what I think are the relevant parts of my nessusWX
file below:  

begin(SERVER_PREFS)
max_hosts = 2
max_checks = 3
port_range = 21-23,53,69,80,111,119,137,139,443,445,593,1477,1478,3018,7937,
7938,8080,8081
checks_read_timeout = 5
non_simult_ports = 139, 445
plugins_timeout = 320
safe_checks = no
auto_enable_dependencies = yes
←-snip-→
begin(PLUGINS_PREFS)
 Nmap[radio]:TCP scanning technique : = SYN scan
 Nmap[checkbox]:UDP port scan = no
 Nmap[checkbox]:RPC port scan = no
 Nmap[checkbox]:Ping the remote host = no
 Nmap[checkbox]:Identify the remote OS = yes
 Nmap[checkbox]:Use hidden option to identify the remote OS = no
 Nmap[checkbox]:Fragment IP packets (bypasses firewalls) = yes
 Nmap[checkbox]:Get Identd info = no
 Nmap[radio]:Port range = User specified range
 Nmap[checkbox]:Do not randomize the  order  in  which ports are scanned =
yes
 Nmap[entry]:Source port : = any
 Nmap[entry]:Data length : = 
 Nmap[entry]:Ports scanned in parallel (max) = 
 Nmap[radio]:Timing policy : = Normal
 Nmap[entry]:Host Timeout (ms) : = 
 Nmap[entry]:Min RTT Timeout (ms) : = 
 Nmap[entry]:Max RTT Timeout (ms) : = 
 Nmap[entry]:Initial RTT timeout (ms) = 
 Nmap[entry]:Minimum wait between probes (ms) = 
 Ping the remote host[entry]:TCP ping destination port(s) : = 22;80;443
 Ping the remote host[checkbox]:Do a TCP ping = yes
 Ping the remote host[checkbox]:Do an ICMP ping = no
 Ping the remote host[entry]:Number of retries (ICMP) : = 3
 Ping the remote host[checkbox]:Make the dead hosts appear in the report =
no
 

Thanks in advance.  



----------------------------------------------------------------------------
This message contains information which is privileged and confidential and
is solely for the use of the intended recipient.  If you are not the
intended recipient, be aware that any review, disclosure, copying,
distribution, or use of the contents of this message is strictly prohibited.
If you have received this in error, please destroy it immediately and notify
us at [EMAIL PROTECTED]
_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to