On Thu, 20 Oct 2005, Javier Fernandez-Sanguino wrote:

> Hugo van der Kooij wrote:
>
>
> > Nessus and PacketShapers do not mix. The average survival time of a
> > PacketShaper in the path of a Nessus test was about 5 minutes.
> >
> > In fact just running nmap was quit sufficient to render it helpless.
>
> Do you mean _through_ it or _to_ it. If "through it" I  would be
> surprised as I have done Nessus scans through a PacketShaper in the
> past and did not have any issues.

That is a definit THROUGH it. Is simply chokes on the amount of sessions
it needs to handle. Mind you that this was with nmap testing 30 host at
the same time with an aggresive policy.

It might have been fixed by now. But 2 years ago it was a perfect way to
perform a DoS attack on a network behind a packetshaper.

Hugo.

-- 
        I hate duplicates. Just reply to the relevant mailinglist.
        [EMAIL PROTECTED]               http://hvdkooij.xs4all.nl/
                Don't meddle in the affairs of magicians,
                for they are subtle and quick to anger.
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to