Hartmut Goebel wrote:
> Am 28.04.2010 18:38, schrieb Vlatko Kosturjak:
>
>> Few of them:
>>
>> - Use local security checks if possible.
>
> Unfortunately not practicable in our case :-(. (Esp. since the
> requirements for local checks are not well documented.)

Requirements are that the scanner has permissions to a shell
account on the platform being audited, and that this account
has access to the commands

   uname
   cat
   dpkg

>
>> - Turn off "Safe checks". Did not check the particular NASL(s) you
>> mention. but if there's correct implementation, safe check would check
>> for vulnerability harder. With safe checks, usually it checks
>> banners/versions.
>
> Uff, this will become hard, since I assume these are not grouped into a
> family.

I believe this is a single configuration setting that in most cases
will apply to all tests that have a choice of making a "banner" check,
vs a more thorough vulnerability check. It would apply to all scripts
across all families that operate in this dual mode.

Thomas
_______________________________________________
Openvas-discuss mailing list
[email protected]
http://lists.wald.intevation.org/mailman/listinfo/openvas-discuss

Reply via email to