On Fri, 2004-02-13 at 01:26, alan donald wrote: > I have a few questions. Forgive me if I am naive but > just wanted to clear my mind about the following > questions. > > 1. What information does nessus need to test a > vulnerability. Only the service name, or the > application name or the complete application version. > I presume currently nessus is detecting in some cases > only the service, or the application name or sometimes > the exact application version.
there is no single answer to this question other than "it depends". Mostly it depends of the type of vulnerability but also on the OS and the type of application. There are many way to testing for vulnerabilities and nessus uses most of them, these range from simply grabbing the greeting banner and extracting version information from it, or even more simple simply determining that a certain port is open an from that inferring that some particular service is running and giving you warning that the service *may* be subject to certain vulnerabilities if the software is not up to date. At the other end of the spectrum nessus will effectively launch what amounts to an attack on the application to see if in can 'break' it. In between are techniques like logging into windows system and checking registry entries to see if specific patches have been applied. > > Why is it that the application version is not > completely made sure of before the vulnerability is > detected. In may cases it is not possible to find out the version without privileged access to the target machine. In many cases this is not an option. Even if you do know the version you may not be able to figure out if the patches have been applied. > > 2. Once it has this information how does it decide > whether to do an exploit or go through the registry. Largely on whether or not it has access to the registry, in many cases you won't. -- Russell Fulton /~\ The ASCII Network Security Officer \ / Ribbon Campaign The University of Auckland X Against HTML New Zealand / \ Email! _______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
