This specific plugin (and perhaps others we are not aware of) seems to not be returning correct data in Nessus 3. The vulnerability is in CommuniGate Pro with a specific module, but the nasl only does a banner check. When we launch a scan against a host whose banner is within the range of the vulnerability it does not show up on Nessus 3, but it does on Nessus 2. The kb from the Nessus 3 scan shows the plugin launching and finishing, but the host is not listed as vulnerable on the report. The banner also shows in the kb from the scan and if you manually run egrep, with the pattern in the nasl, against the banner listed in the kb - it matches. Is this a possible bug in the way 3 handles plugin data or is there a configuration option that could possibly influence this (we have already set the SSL check option to all ports)?

Regards,

Kenneth Shelton
Incident Response Team
University of South Florida
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to