On Wed, Feb 22, 2006 at 01:10:16PM -0500, Youngstrom.Timothy wrote:

> I need to verify the number of login attempts that a fresh unmodified
> install of Nessus makes.

There's no single answer; it depends on the plugins available on your
server, which specific plugins you enable, how you configure your scan,
which ports are determined to be open on the targets, etc.

> If all Hydra brute force settings are
> configured to 'No' will there be ANY user ids and password combinations
> submitted to a machine including a blank password for login to the
> machine, ftp, mail etc?

Sure. There are plenty of plugins that will try to authenticate in some
fashion using known or common credentials; eg, account_*.nasl and
mssql_brute_force.nasl (despite its name, it tries only 10 user/password
combinations).

George
-- 
[EMAIL PROTECTED]
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to