I am trying to test a remote client on the network for Anti Virus using nessus. Specifically Norton(12106) and Mcafee(12107).

I select only these plugins, then enable dependencies, disable optimize test, and configure the plugins to use a valid SMB account name and password.

I initiate the scan against a well known client that never had Norton or Mcafee installed. I would expect that I should see a failure / vulnerability due to the lack of anti virus software installed. The problem is that I don't.

The output of the nessusd.messages is listed below.

Any Ideas what else I need to configure or what I might be doing wrong?

Thanks,

Mike

Output for the Norton Scan:

[Tue Apr 13 11:42:36 2004][23401] user root starts a new scan. Target(s) : 192.168.10.121, with max_hosts = 16 and max_checks = 10
[Tue Apr 13 11:42:36 2004][23401] user root : testing 192.168.10.121 (192.168.10.121) [24223]
[Tue Apr 13 11:42:36 2004][24223] user root : launching ping_host.nasl against 00.10.7a.68.e8.2d [24224]
[Tue Apr 13 11:42:36 2004][24223] ping_host.nasl (process 24224) finished its job in 0.003 seconds
[Tue Apr 13 11:42:36 2004][24223] user root : launching nmap_tcp_connect.nes against 00.10.7a.68.e8.2d [24225]
[Tue Apr 13 11:42:38 2004][24223] nmap_tcp_connect.nes (process 24225) finished its job in 2.190 seconds
[Tue Apr 13 11:42:38 2004][24223] user root : launching logins.nasl against 00.10.7a.68.e8.2d [24226]
[Tue Apr 13 11:42:38 2004][24223] user root : launching find_service.nes against 00.10.7a.68.e8.2d [24227]
[Tue Apr 13 11:42:38 2004][24223] logins.nasl (process 24226) finished its job in 0.011 seconds
[Tue Apr 13 11:42:45 2004][24223] find_service.nes (process 24227) finished its job in 7.061 seconds
[Tue Apr 13 11:42:45 2004][24223] user root : launching cifs445.nasl against 00.10.7a.68.e8.2d [24233]
[Tue Apr 13 11:42:45 2004][24223] cifs445.nasl (process 24233) finished its job in 0.023 seconds
[Tue Apr 13 11:42:45 2004][24223] user root : launching netbios_name_get.nasl against 00.10.7a.68.e8.2d [24234]
[Tue Apr 13 11:42:45 2004][24223] netbios_name_get.nasl (process 24234) finished its job in 0.013 seconds
[Tue Apr 13 11:42:45 2004][24223] user root : launching smb_login.nasl against 00.10.7a.68.e8.2d [24235]
[Tue Apr 13 11:42:45 2004][24223] smb_login.nasl (process 24235) finished its job in 0.086 seconds
[Tue Apr 13 11:42:45 2004][24223] user root : launching smb_registry_access.nasl against 00.10.7a.68.e8.2d [24236]
[Tue Apr 13 11:42:45 2004][24223] smb_registry_access.nasl (process 24236) finished its job in 0.027 seconds
[Tue Apr 13 11:42:45 2004][24223] user root : launching smb_enum_services.nasl against 00.10.7a.68.e8.2d [24237]
[Tue Apr 13 11:42:45 2004][24223] smb_enum_services.nasl (process 24237) finished its job in 0.025 seconds
[Tue Apr 13 11:42:45 2004][24223] user root : launching smb_registry_full_access.nasl against 00.10.7a.68.e8.2d [24238]
[Tue Apr 13 11:42:45 2004][24223] smb_registry_full_access.nasl (process 24238) finished its job in 0.029 seconds
[Tue Apr 13 11:42:45 2004][24223] user root : launching nav_installed.nasl against 00.10.7a.68.e8.2d [24239]
[Tue Apr 13 11:42:45 2004][24223] nav_installed.nasl (process 24239) finished its job in 0.016 seconds
[Tue Apr 13 11:42:45 2004][24223] Finished testing 00.10.7a.68.e8.2d. Time : 9.56 secs
[Tue Apr 13 11:42:45 2004][23401] user root : test complete
[Tue Apr 13 11:42:45 2004][23401] user root : Kept alive connection



Output for the Mcafee Scan:
[Tue Apr 13 11:49:02 2004][23401] user root starts a new scan. Target(s) : 192.168.10.121, with max_hosts = 16 and max_checks = 10
[Tue Apr 13 11:49:02 2004][23401] user root : testing 192.168.10.121 (192.168.10.121) [24272]
[Tue Apr 13 11:49:02 2004][24272] user root : launching logins.nasl against 00.10.7a.68.e8.2d [24273]
[Tue Apr 13 11:49:02 2004][24272] user root : launching find_service.nes against 00.10.7a.68.e8.2d [24274]
[Tue Apr 13 11:49:02 2004][24272] logins.nasl (process 24273) finished its job in 0.005 seconds
[Tue Apr 13 11:49:02 2004][24272] find_service.nes (process 24274) finished its job in 0.009 seconds
[Tue Apr 13 11:49:02 2004][24272] user root : launching cifs445.nasl against 00.10.7a.68.e8.2d [24275]
[Tue Apr 13 11:49:02 2004][24272] cifs445.nasl (process 24275) finished its job in 0.029 seconds
[Tue Apr 13 11:49:02 2004][24272] user root : launching netbios_name_get.nasl against 00.10.7a.68.e8.2d [24276]
[Tue Apr 13 11:49:02 2004][24272] netbios_name_get.nasl (process 24276) finished its job in 0.013 seconds
[Tue Apr 13 11:49:02 2004][24272] user root : launching smb_login.nasl against 00.10.7a.68.e8.2d [24277]
[Tue Apr 13 11:49:02 2004][24272] smb_login.nasl (process 24277) finished its job in 0.091 seconds
[Tue Apr 13 11:49:02 2004][24272] user root : launching smb_registry_access.nasl against 00.10.7a.68.e8.2d [24278]
[Tue Apr 13 11:49:02 2004][24272] smb_registry_access.nasl (process 24278) finished its job in 0.027 seconds
[Tue Apr 13 11:49:02 2004][24272] user root : launching smb_enum_services.nasl against 00.10.7a.68.e8.2d [24279]
[Tue Apr 13 11:49:02 2004][24272] smb_enum_services.nasl (process 24279) finished its job in 0.026 seconds
[Tue Apr 13 11:49:02 2004][24272] user root : launching smb_registry_full_access.nasl against 00.10.7a.68.e8.2d [24280]
[Tue Apr 13 11:49:02 2004][24272] smb_registry_full_access.nasl (process 24280) finished its job in 0.028 seconds
[Tue Apr 13 11:49:02 2004][24272] user root : launching mcafee_installed.nasl against 00.10.7a.68.e8.2d [24281]
[Tue Apr 13 11:49:02 2004][24272] mcafee_installed.nasl (process 24281) finished its job in 0.016 seconds
[Tue Apr 13 11:49:02 2004][24272] Finished testing 00.10.7a.68.e8.2d. Time : 0.30 secs
[Tue Apr 13 11:49:02 2004][23401] user root : test complete
[Tue Apr 13 11:49:02 2004][23401] user root : Kept alive connection
[Tue Apr 13 11:58:30 2004][21556] connection from 192.168.10.70
[Tue Apr 13 11:58:30 2004][24297] Client requested protocol version 12.
[Tue Apr 13 11:58:30 2004][24297] successful login of root from 192.168.10.70
[Tue Apr 13 11:58:36 2004][24297] Redirecting debugging output to /bsc/nessus/var/nessus/logs/nessusd.dump




_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to