This specific plugin (and perhaps others we are not aware of) seems to
not be returning correct data in Nessus 3. The vulnerability is in
CommuniGate Pro with a specific module, but the nasl only does a banner
check. When we launch a scan against a host whose banner is within the
range of the vulnerability it does not show up on Nessus 3, but it does
on Nessus 2. The kb from the Nessus 3 scan shows the plugin launching
and finishing, but the host is not listed as vulnerable on the report.
The banner also shows in the kb from the scan and if you manually run
egrep, with the pattern in the nasl, against the banner listed in the kb
- it matches.
Is this a possible bug in the way 3 handles plugin data or is there a
configuration option that could possibly influence this (we have already
set the SSL check option to all ports)?
Regards,
Kenneth Shelton
Incident Response Team
University of South Florida
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus