On Fri, 2004-02-13 at 01:26, alan donald wrote:
> I have a few questions. Forgive me if I am naive but
> just wanted to clear my mind about the following
> questions.
> 
> 1. What information does nessus need to test a
> vulnerability. Only the service name, or the
> application name or the complete application version.
> I  presume currently nessus is detecting in some cases
> only the service, or the application name or sometimes
> the exact application version. 

there is no single answer to this question other than "it depends".

Mostly it depends of the type of vulnerability but also on the OS and
the type of application.  There are many way to testing for
vulnerabilities and nessus uses most of them, these range from simply
grabbing the greeting banner and extracting version information from it,
or even more simple simply determining that a certain port is open an
from that inferring that some particular service is running and giving
you warning that the service *may* be subject to certain vulnerabilities
if the software is not up to date.

At the other end of the spectrum nessus will effectively launch what
amounts to an attack on the application to see if in can 'break' it.

In between are techniques like logging into windows system and checking
registry entries to see if specific patches have been applied.
> 
> Why is it that the application version is not
> completely made sure of before the vulnerability is
> detected. 

In may cases it is not possible to find out the version without
privileged access to the target machine.  In many cases this is not an
option.  Even if you do know the version you may not be able to figure
out if the patches have been applied.

> 
> 2. Once it has this information how does it decide
> whether to do an exploit or go through the registry. 

Largely on whether or not it has access to the registry, in many cases
you won't.

-- 
Russell Fulton                                    /~\  The ASCII
Network Security Officer                          \ /  Ribbon Campaign
The University of Auckland                         X   Against HTML
New Zealand                                       / \  Email!


_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to