Re: [Openvas-discuss] Any news on OpenVAS debian packages?

2009-04-15 Thread Jan-Oliver Wagner
On Mittwoch, 15. April 2009, Dominique Karg wrote: just wanted to bump this again since I'd really would love to replace Nessus with OpenVAS in the upcoming OSSIM release. what is the timeline? Lenny, I guess? Any news? Here at Intevation we prepared the OpenVAS-Client 2.0.2 for Etch and

[Openvas-discuss] False positive security holes ?

2009-04-15 Thread Marco Schaerfke
Dear all, I have a problem to understand openvas messages. I would like to give an example. After a scan I found the following security hole on my PC: Overview: This host is running WinAsm Studio and is prone to Heap Overflow Vulnerability. CVSS Score: CVSS Base Score : 9.0

Re: [Openvas-discuss] False positive security holes ?

2009-04-15 Thread Jan-Oliver Wagner
On Mittwoch, 15. April 2009, Marco Schaerfke wrote: if(version_is_less_equal(version:version, test_version:5.1.5.0)){ security_hole(0); } I look with help of the explorer also for that file, but I am unable to find it. Could it be that the code above is wrong ? perhaps version

Re: [Openvas-discuss] False positive security holes ?

2009-04-15 Thread Chandrashekhar B
Hello Marco, Thanks for reporting. There was a bug in the code which is fixed now. Please get the latest code from svn. Thanks, Chandra. -Original Message- From: openvas-discuss-boun...@wald.intevation.org [mailto:openvas-discuss-boun...@wald.intevation.org] On Behalf Of Marco

[Openvas-discuss] Problem with remote host not using the good versions of the Nessus prorocol

2009-04-15 Thread Copenhaver, Walter A
Hello, I installed openvas-server and openvas-plugins on an Linux server (Archlinux). I can start, stop, and restart the daemon without any errors. I also installed the server certificate using the openvas-mkcert tool, and I added a user using the openvas-adduser tool. Everything seems to