For everyone's benefit, I'll post details of the solution to this problem here:
Short answer: I rolled back to 3.0.6 and it works just fine. Long answer: Nessus 3.2 on FreeBSD 6.3 is broken. Just to make sure I wasn't hallucinating the entire episode, I re-downloaded it (to make sure I was picking up the proper binaries--avoiding the whole "is it plugged in sir?" line of questioning) and re-installed it on the server in question, and on another server running the same OS and version, as well as a laptop. I tested all three and was able to reproduce the results listed below perfectly. Just to add to the mix, I tested with both local and remote clients (even third party linux stuff under binary emulation), and the results were the same---spike in CPU, perhaps a few results here and there depending on how the policy was set up (I tested ten of them each)...I've found nothing wonky in system logs, and the nessus logs themselves (including debug) just trail off without error. All ten policies work perfectly--as long as I'm running 3.0.6 on Freebsd 6.3. I have no problems at all running the 3.2 server on OS X 10.5.2 or Solaris 10. On Mar 22, 2008, at 3:41 PM, James Birk wrote: > Has anyone seen this? > > I'm running the Nessus 3.2 server on Freebsd 6.3 (upgraded from 3.0.6 > and 6.2 freshly), and the 3.2 client on OS X 10.5.2. > > I can connect to the remote server with the client fine, and it shows > up in both a netstat and a ps -aux on the server without issue. The > problem happens when I begin a scan--nessusd churns heavily for about > 5 seconds and then drops to 0% CPU usage, and the client either > receives no results at all, or just a few things greyed out. I'm > running the same set of policies that I was under 3.0.6, and made a > few new ones, turning off pingers, trying different portscanners, etc, > to see if I could nail down the problem, but to no avail. > > One interesting point, I did try nessuscmd on the server with the same > results---it throws up a few open ports and the number of a hit module > or two, but it never exits. > > Any ideas? > > Thanks, > > > > > James > _______________________________________________ > Nessus mailing list > [email protected] > http://mail.nessus.org/mailman/listinfo/nessus _______________________________________________ Nessus mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus
