On Thu, Nov 10, 2005 at 09:25:27AM -0500, Joel Elwell wrote: > Has anyone run into the probable false positives below? > The only cgi folder existing on the server is in Apache2. It contains none of > the indicated CGI's. > Apache, Perl and Tomcat where not loaded at the time of the scan. > What is keying Nessus to indicate these warnings?
Did you enable dependencies when you ran the scan? If not, I could see this happening if you didn't and your web server doesn't respond with a 404 error code to requests for non-existent pages. Also, are you by any chance using NessusWX that you've upgraded and with a session from before the upgrade? If so, create a new session and re-run your scan. And finally, have you manually tested for the CGIs? George -- [EMAIL PROTECTED] _______________________________________________ Nessus mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus
