I have remote registry reads setup correctly on the client machine. I tested the permissions on the nessus box using rpcclient from samba-tng and was able to read the HKEY_LOCAL_MACHINE key on the client machine. When I run nessus against the client machine with the same user and password in the .nessusrc file as with rpcclient I
receive the following message in the nessus report:
It was not possible to connect to PIPE\winreg on the remote host. If you intend to use Nessus to perform registry-based checks, the registry checks will not work because the 'Remote Registry Access' service (winreg) has been disabled on the remote host or can not be connected to with the supplied credentials. Nessus ID : 10400
As I said I am using the same credentials in .nessusrc and rpcclient. I am using nessus 2.2.3-3 and nessusd 2.2.3-3 from debian. Any ideas on why nessus can not read from the registry?
Note: the samba password includes alphanumeric characters, the at sign (@), and the pound sign (#). I can not imagine that this would cause a problem in nessus though.
-- - Josh _______________________________________________ Nessus mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus
