Re: [Openvas-discuss] Openvas Manager V 7

2017-03-15 Thread Sameer Anja
The mrazavi ppa does not work for ubuntu 16.10 Yakkety. So no updates 
are coming through for Yakkety versions.



Sameer Anja, CISSP
Co-founder & COO - Arrka Consulting
Mumbai
M: +91-98237-35313 | www.arrka.com |
sameer.a...@arrka.com|@sameeranja | @arrkacyberninja


INFOSEC | DATA PRIVACY | USER AWARENESS

Are your CyberNinjas lined up?

Disclaimer: This email may contain confidential and
privileged information for the sole use of the
intended recipient.
Any review or distribution by others is strictly prohibited.
If you are not the intended recipient, please reply to
the sender about the error and delete all copies of
this email message.
Thank you.

On 3/15/2017 11:33 PM, Christian Fischer wrote:

On 08.03.2017 21:06, Christian Fischer wrote:

On 08.03.2017 20:10, H. Stoellinger wrote:

There does not seem to be a package available yet that would allow me to
install
OpenVAS Manager 7.0. Is this package available somewhere?
Thanks for your help.
Regards from Salzburg, Austria
H. Stoellinger


OpenVAS 9 (to which the manager v7.0 belongs to) was officially released
today:

http://www.openvas.org/news.html#openvas9

so you probably need to give the packager of the Ubuntu packages a few
more days / weeks time to provide the final OpenVAS 9 packages.


seems the Ubuntu PPA at
https://launchpad.net/~mrazavi/+archive/ubuntu/openvas got updated with
the current OpenVAS 9 versions two days ago.

Regards,

--

Christian Fischer | PGP Key: 0x54F3CE5B76C597AD
Greenbone Networks GmbH | http://greenbone.net
Neumarkt 12, 49074 Osnabrück, Germany | AG Osnabrück, HR B 202460
Geschäftsführer: Lukas Grunwald, Dr. Jan-Oliver Wagner
___
Openvas-discuss mailing list
Openvas-discuss@wald.intevation.org
https://lists.wald.intevation.org/cgi-bin/mailman/listinfo/openvas-discuss


___
Openvas-discuss mailing list
Openvas-discuss@wald.intevation.org
https://lists.wald.intevation.org/cgi-bin/mailman/listinfo/openvas-discuss


Re: [Openvas-discuss] Openvas Manager V 7

2017-03-15 Thread Christian Fischer
On 08.03.2017 21:06, Christian Fischer wrote:
> On 08.03.2017 20:10, H. Stoellinger wrote:
>> There does not seem to be a package available yet that would allow me to
>> install
>> OpenVAS Manager 7.0. Is this package available somewhere?
>> Thanks for your help.
>> Regards from Salzburg, Austria
>> H. Stoellinger
> 
> OpenVAS 9 (to which the manager v7.0 belongs to) was officially released
> today:
> 
> http://www.openvas.org/news.html#openvas9
> 
> so you probably need to give the packager of the Ubuntu packages a few
> more days / weeks time to provide the final OpenVAS 9 packages.

seems the Ubuntu PPA at
https://launchpad.net/~mrazavi/+archive/ubuntu/openvas got updated with
the current OpenVAS 9 versions two days ago.

Regards,

--

Christian Fischer | PGP Key: 0x54F3CE5B76C597AD
Greenbone Networks GmbH | http://greenbone.net
Neumarkt 12, 49074 Osnabrück, Germany | AG Osnabrück, HR B 202460
Geschäftsführer: Lukas Grunwald, Dr. Jan-Oliver Wagner
___
Openvas-discuss mailing list
Openvas-discuss@wald.intevation.org
https://lists.wald.intevation.org/cgi-bin/mailman/listinfo/openvas-discuss


[Openvas-discuss] CVE-2017-5638

2017-03-15 Thread Ebert, Christian
Hi everyone,

is there any possibility to use OpenVAS to check against the Apache Struts2 
vulnerability CVE-2017-5638?

There is an NMAP NSE:  
https://nmap.org/nsedoc/scripts/http-vuln-cve2017-5638.html

Does anybody have experience with this NSE? Is it reliable?

Best regards

Christian Ebert
___
Openvas-discuss mailing list
Openvas-discuss@wald.intevation.org
https://lists.wald.intevation.org/cgi-bin/mailman/listinfo/openvas-discuss

[Openvas-discuss] how/why plugin are set to 'False positif' by manager

2017-03-15 Thread Sebastien Aucouturier
Hi community,

as you may have seen in a previous discussion,
i got some plugins declared as 'False positive'  by manager ,

even if i set the levels to get thoses plugins in the reports,
their cvss are not correct and set to value : -1, is there a tip to get the
correct cvss  using omp cli ?

if no, how the FP is  evaluate ? how can i avoid that ?

Help greatly appreciate.



Sebastien Aucouturier , VP Engineer and Senior Technologist,
___
Openvas-discuss mailing list
Openvas-discuss@wald.intevation.org
https://lists.wald.intevation.org/cgi-bin/mailman/listinfo/openvas-discuss

Re: [Openvas-discuss] how to Get vulnerabilties tagged false positif in report get from omp cli ?

2017-03-15 Thread Sebastien Aucouturier
Hi,
after having lunch, idea come clear, and i find the way :

to get the full list of vulnerabilities including  the one tagged as false
positif by manager,
you have to add the parameter : levels='hmlgf'to the get_reports
commands

where h fstands or high, m for medium, l for low, g for log and f for false
positif ..

hope this can help some of you.


Sebastien Aucouturier , VP Engineer and Senior Technologist,
___
Openvas-discuss mailing list
Openvas-discuss@wald.intevation.org
https://lists.wald.intevation.org/cgi-bin/mailman/listinfo/openvas-discuss

[Openvas-discuss] how to Get vulnerabilties tagged false positif in report get from omp cli ?

2017-03-15 Thread Sebastien Aucouturier
Hi community,

i need you help, i try differents way to get a report with vulnerability
tags as false positive by the manager :

i clearly saw them through GSAD, but when i try to get  with omp  CLI :

using   get_reports   min_qod='0' autofp='2' details='1'

they are not report ? which parameters i am missing ?

using openvas
openvas-cli1.4.3
openvas-libraries   8.0.7
openvas-manager  6.0.7
openvas-scanner5.0.5

Thanks for help

Sebastien Aucouturier , VP Engineer and Senior Technologist,
___
Openvas-discuss mailing list
Openvas-discuss@wald.intevation.org
https://lists.wald.intevation.org/cgi-bin/mailman/listinfo/openvas-discuss

[Openvas-discuss] NVT Current Feed

2017-03-15 Thread Matt Koivisto
I've noticed that the current feed archive 
(http://www.openvas.org/openvas-nvt-feed-current.tar.bz2) hasn't received any 
of the commits made from 
http://lists.wald.intevation.org/pipermail/openvas-nvts-commits/ since about 
mid-February. Does anyone have information as to when these commits will be 
incorporated into the current feed?
This e-mail may contain information that is privileged or confidential. If you 
are not the intended recipient, please delete the e-mail and any attachments 
and notify us immediately.
___
Openvas-discuss mailing list
Openvas-discuss@wald.intevation.org
https://lists.wald.intevation.org/cgi-bin/mailman/listinfo/openvas-discuss