Hi, for tests I scanned a Debian 'lenny' system today. It showed 16 high and 32 medium issues. I asked the system guys and they told me, the system seams to be up to date.
- /etc/apt/sources contains http://security.debian.org/ lenny/updates main - last update a few days ago I checked a single issue (from secpod_apache_mod_proxy_ftp_cmd_inj_vuln.nasl) and it showed that the report was based on the server banner and the check seamed to be correct. The system guy told me that Debian usually doe not change the version, not even for security patches. If this is true, I wonder whether is makes sense scanning Debian systems at all as there will be unreliable results. Any hints? -- Schönen Gruß - Regards Hartmut Goebel Dipl.-Informatiker (univ.), CISSP, CSSLP Goebel Consult Spezialist für IT-Sicherheit in komplexen Umgebungen http://www.goebel-consult.de Monatliche Kolumne: http://www.cissp-gefluester.de/ Goebel Consult mit Mitglied bei http://www.7-it.de
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ Openvas-discuss mailing list [email protected] http://lists.wald.intevation.org/mailman/listinfo/openvas-discuss
