On Thu, Nov 10, 2005 at 09:25:27AM -0500, Joel Elwell wrote:

> Has anyone run into the probable false positives below? 
> The only cgi folder existing on the server is in Apache2. It contains none of 
> the indicated CGI's. 
> Apache, Perl and Tomcat where not loaded at the time of the scan.
> What is keying Nessus to indicate these warnings?

Did you enable dependencies when you ran the scan? If not, I could see
this happening if you didn't and your web server doesn't respond with a
404 error code to requests for non-existent pages.

Also, are you by any chance using NessusWX that you've upgraded and with
a session from before the upgrade? If so, create a new session and
re-run your scan.

And finally, have you manually tested for the CGIs?

George
-- 
[EMAIL PROTECTED]
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to