[Openvas-discuss] OpenVAS 9 Scanner 5.1.2 - lib kb_redis-CRITICAL **: fetch_max_db_index:

2018-04-10 Thread Pete @ GREENUP ENGINEERING
Hi folks I got the following error on a 2 out of 3 servers im running after leaving  scan /24's. I have to flush redis, restart services and rebuild openvas to fix it. Can someone point me in the right direction for discovering what maybe causing it?  openvas-scanner.service - LSB: remote ne

Re: [Openvas-discuss] Private or Corporate CAs

2018-04-10 Thread Christian Kuersteiner
Guys, Please watch your language. This is an open discussion list and it makes your arguments moot if you turn it into a swearing contest. If you can't add something in a meaningful tone then best keep it to yourself. This list should be a place to find insights, help, solutions, ideas etc.

Re: [Openvas-discuss] Private or Corporate CAs

2018-04-10 Thread Reindl Harald
Am 10.04.2018 um 19:39 schrieb Alex Smirnoff: > I dare to say any "external security audit" which considers that being a > problem is pefromed by morons that should be replaced ASAP. you have no idea from the real world external audits are typically ordered by customers and done by independent

Re: [Openvas-discuss] "Are you dead?" Really?

2018-04-10 Thread Andy Robinson
Better to distribute some plush comfort animals. Then recognize appeal to ridicule is a fallacy, and THEN fix “are you dead ?” Sent from my iPhone > On Apr 10, 2018, at 12:45, R0b0t1 wrote: > > Hello friends, > > This talk of hospitals has triggered me. Can we please censor the mailing > li

Re: [Openvas-discuss] Private or Corporate CAs

2018-04-10 Thread Alex Smirnoff
I dare to say any "external security audit" which considers that being a problem is pefromed by morons that should be replaced ASAP. No, I won't get fired, for sure. And I won't work for any employer where I could get fired for standing my point. On Tue, Apr 10, 2018 at 05:16:43PM +0200, Reindl H

Re: [Openvas-discuss] "Are you dead?" Really?

2018-04-10 Thread R0b0t1
Hello friends, This talk of hospitals has triggered me. Can we please censor the mailing list? On Tue, Apr 10, 2018 at 11:31 AM, Stewart Joseph wrote: > Oh, I agree. It would be concerning if I was there. But from over here we > got a good chuckle. You are correct, the wording could be a bit m

Re: [Openvas-discuss] "Are you dead?" Really?

2018-04-10 Thread Stewart Joseph
Oh, I agree. It would be concerning if I was there. But from over here we got a good chuckle. You are correct, the wording could be a bit more professional. Maybe phrases that get printed out could start with a phrase like “Network Security Scan In Progress. Diagnostic Message is:” so that p

Re: [Openvas-discuss] "Are you dead?" Really?

2018-04-10 Thread Andrew Robinson
Yes, _I_ appreciate the humor and irony. But the client didn’t find it even slightly humorous, particularly when the nurses in the hospital almost triggered the lockdown protocol because they thought they were under an active threat. An over-reaction for sure, but as I try to advance OpenVAS as

Re: [Openvas-discuss] [WORKAROUND] unknown or invalid Host header

2018-04-10 Thread Christian Fischer
Hi, On 10.04.2018 17:18, Aaron Couts wrote: > In any case I couldn't find any config settings that > addressed this. have a look at the following mailing list post for the config option and how to configure it: http://lists.wald.intevation.org/pipermail/openvas-discuss/2018-April/011929.html Re

[Openvas-discuss] [WORKAROUND] unknown or invalid Host header

2018-04-10 Thread Aaron Couts
I ran into an issue with my OpenVAS 9 installation and couldn't find anything about it online (at least in the limited googling that I did), so I wanted to post the error message and a workaround in case anyone else runs into it. I installed OpenVAS 9 on an AWS EC2 instance running Ubuntu 16.04.3

Re: [Openvas-discuss] Private or Corporate CAs

2018-04-10 Thread Reindl Harald
Am 10.04.2018 um 17:12 schrieb Alex Smirnoff: > Could you elaborate an attack scenario that depends on root certificate > signature? > > The job of security scanner is not to point at any shit, it is to point > at dangerous shit. it's job is to point out shit which would lead to not survive a e

Re: [Openvas-discuss] "Are you dead?" Really?

2018-04-10 Thread Alex Smirnoff
If it asks "Are you alive? Prove it!" then it might be more scary. Even if it is a printer, not a toaster ;-) On Mon, Apr 09, 2018 at 07:05:46PM +, Stewart Joseph wrote: > You must admit, there is more than a touch of ironic humor there. I ran a > scan of a Deli's network and when it hit the

Re: [Openvas-discuss] Private or Corporate CAs

2018-04-10 Thread Alex Smirnoff
Could you elaborate an attack scenario that depends on root certificate signature? The job of security scanner is not to point at any shit, it is to point at dangerous shit. On Mon, Apr 09, 2018 at 10:26:54AM +0200, Reindl Harald wrote: > jesus add a override and you are done > > MD5/SHA1 certif

Re: [Openvas-discuss] Scanning for vulnerabilities in Oracle Database

2018-04-10 Thread Antu Sanadi
Hello, Here nothing do with NVT.  As it looks like issue with an server configuration. Please google exact error message along with status code. You might find the solution for proper configuration. If you don't find , request you to send the exact error message with error code. Thanks, An

Re: [Openvas-discuss] Scanning for vulnerabilities in Oracle Database

2018-04-10 Thread Anantha Raghava
Hi, Any specific configuration to be done to get OpenVAS scan Oracle for vulnerabilities. I am doing authenticated scan. Yet receiving "tns listner connection refused" error. I checked the NVT, but could get any idea as to why it is failing to scan. Oracle tns is listening on port 1521, but c