Thanks a lot. That was a very comprehensive answer. But I am still not clear about the service part of my question. Is it ever the case that nessus is able to find the service name and not the application and version information. If that ever happens then what does nessus do. I mean can it launch an attack only knowing the service name?
--- Paul Johnston <[EMAIL PROTECTED]> wrote: > Alan, > > There are several ways Nessus can test for a > vulnerability: > > 1) Directly exploiting it. This works very well for > information leakage > vulnerabilities, or ones like SQL injection and > cross-site scripting. > Unfortunately, testing buffer overrun or DoS > vulnerabilities this way > risks harming the target server and for most people > this is not > acceptable, so a most of the particularly serious > vulns cannot be tested > this way. > 2) Checking for software versions in the registry. > This works very well > (except a few issues relating to failed installs and > no reboots) but is > Windows only, relies on the SMB ports being open and > requires domain > admin privileges. This makes it only useful on > internal networks. > 3) Checking the banner. This works well when the > banner is present, but > false-negatives when the banner is disguised and > false-positives when a > patch is applied but the version number not changed. > This works better > on Unix as many Windows services have quite generic > banners. This is > becoming less useful as more people disguise > banners. > 4) Version fingerprinting. In general fingerprints > aren't sensitive > enough to distinguish particular versions where the > vuln is fixed. > However, you can sometime probe for side changes > related to the fix, > e.g. the recent OpenSSL ASN vuln and the Messenger > RPC overrun. I would > regard this type of testing as the cutting edge. > > I'm sure this analysis isn't complete. > > Paul > > > alan donald wrote: > > >I have a few questions. Forgive me if I am naive > but > >just wanted to clear my mind about the following > >questions. > > > >1. What information does nessus need to test a > >vulnerability. Only the service name, or the > >application name or the complete application > >version. > >I presume currently nessus is detecting in some > >cases > >only the service, or the application name or > >sometimes > >the exact application version. > > > >Why is it that the application version is not > >completely made sure of before the vulnerability is > >detected. > > > >2. Once it has this information how does it decide > >whether to do an exploit or go through the > registry. > > > > > >__________________________________ > >Do you Yahoo!? > >Yahoo! Finance: Get your refund fast by filing > online. > >http://taxes.yahoo.com/filing.html > >_______________________________________________ > >Nessus mailing list > >[EMAIL PROTECTED] > >http://mail.nessus.org/mailman/listinfo/nessus > > > > > > > > > > -- > Paul Johnston > Internet Security Specialist > Westpoint Limited > Albion Wharf, 19 Albion Street, > Manchester, M1 5LN > England > Tel: +44 (0)161 237 1028 > Fax: +44 (0)161 237 1031 > email: [EMAIL PROTECTED] > web: www.westpoint.ltd.uk > > __________________________________ Do you Yahoo!? Yahoo! Finance: Get your refund fast by filing online. http://taxes.yahoo.com/filing.html _______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
