Hi,

for tests I scanned a Debian 'lenny' system today. It showed 16 high and
32 medium issues. I asked the system guys and they told me, the system
seams to be up to date.

- /etc/apt/sources contains  http://security.debian.org/ lenny/updates main
- last update a few days ago

I checked a single issue (from
secpod_apache_mod_proxy_ftp_cmd_inj_vuln.nasl) and it showed that the
report was based on the server banner and the check seamed to be correct.

The system guy told me that Debian usually doe not change the version,
not even for security patches. If this is true, I wonder whether is
makes sense scanning Debian systems at all as there will be unreliable
results.

Any hints?

-- 
Schönen Gruß - Regards
Hartmut Goebel
Dipl.-Informatiker (univ.), CISSP, CSSLP

Goebel Consult
Spezialist für IT-Sicherheit in komplexen Umgebungen
http://www.goebel-consult.de

Monatliche Kolumne: http://www.cissp-gefluester.de/
Goebel Consult mit Mitglied bei http://www.7-it.de

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
Openvas-discuss mailing list
[email protected]
http://lists.wald.intevation.org/mailman/listinfo/openvas-discuss

Reply via email to