Re: [Openvas-discuss] arachni, etc.

2014-10-16 Thread Jan-Oliver Wagner
Am Mittwoch, 1. Oktober 2014, 15:51:43 schrieb Geoff Galitz: FWIW, openvas as a wrapper around other established tools/projects is half the point of openvas (to me anyways). It would be great if the project somehow identifies what needs to be done to get these to work again. There's no real

Re: [Openvas-discuss] arachni, etc.

2014-10-02 Thread Jack Harvey
, 2014 10:53 AM To: Geoff Galitz Cc: Jack Harvey; openvas-discuss@wald.intevation.org Subject: Re: [Openvas-discuss] arachni, etc. I agree that utilities like dirb and nikto are useful as plugins for OpenVAS since these are generally applicable to any web server. Arachni and wapiti require

Re: [Openvas-discuss] arachni, etc.

2014-10-01 Thread Jack Harvey
@wald.intevation.org Subject: Re: [Openvas-discuss] arachni, etc. Am 30.09.2014 um 21:39 schrieb Jack Harvey: I realize this has been asked...and asked...and...but enquiring minds want to know... OpenVAS v7 install via atomic repo includes in the pre-built scan configs components arachni

Re: [Openvas-discuss] arachni, etc.

2014-10-01 Thread Brandon Perry
To: openvas-discuss@wald.intevation.org Subject: Re: [Openvas-discuss] arachni, etc. Am 30.09.2014 um 21:39 schrieb Jack Harvey: I realize this has been asked...and asked...and...but enquiring minds want to know... OpenVAS v7 install via atomic repo includes in the pre-built scan

Re: [Openvas-discuss] arachni, etc.

2014-10-01 Thread Brandon Perry
Subject: Re: [Openvas-discuss] arachni, etc. Am 30.09.2014 um 21:39 schrieb Jack Harvey: I realize this has been asked...and asked...and...but enquiring minds want to know... OpenVAS v7 install via atomic repo includes in the pre-built scan configs components arachni and wapiti

Re: [Openvas-discuss] arachni, etc.

2014-10-01 Thread Reindl Harald
Am 01.10.2014 um 16:52 schrieb Brandon Perry: I agree that utilities like dirb and nikto are useful as plugins for OpenVAS since these are generally applicable to any web server. Arachni and wapiti require such application specific configurations that I wouldn't want to give people

Re: [Openvas-discuss] arachni, etc.

2014-10-01 Thread Reindl Harald
Am 01.10.2014 um 17:21 schrieb Reindl Harald: Am 01.10.2014 um 16:52 schrieb Brandon Perry: I agree that utilities like dirb and nikto are useful as plugins for OpenVAS since these are generally applicable to any web server. Arachni and wapiti require such application specific

Re: [Openvas-discuss] arachni, etc.

2014-10-01 Thread Brandon Perry
If you want to perform possibly destructive web audit scans on production systems, that is fine. I think you are taking what I said and making an overly-general statement about any kind of security scanning. On Wed, Oct 1, 2014 at 10:21 AM, Reindl Harald h.rei...@thelounge.net wrote: Am

Re: [Openvas-discuss] arachni, etc.

2014-10-01 Thread Reindl Harald
Am 01.10.2014 um 17:40 schrieb Brandon Perry: If you want to perform possibly destructive web audit scans on production systems, that is fine. surely because better i do at a scheduled point in time and with a recent backup or some bad guy unasked for what purpose do i need a security scan

Re: [Openvas-discuss] arachni, etc.

2014-09-30 Thread Reindl Harald
Am 30.09.2014 um 21:39 schrieb Jack Harvey: I realize this has been asked…and asked…and…but enquiring minds want to know… OpenVAS v7 install via atomic repo includes in the pre-built scan configs components arachni and wapiti (and of course others) I am getting this when I run a scan

Re: [Openvas-discuss] arachni, etc.

2014-09-30 Thread Jack Harvey
:45 PM To: openvas-discuss@wald.intevation.org Subject: Re: [Openvas-discuss] arachni, etc. Am 30.09.2014 um 21:39 schrieb Jack Harvey: I realize this has been asked...and asked...and...but enquiring minds want to know... OpenVAS v7 install via atomic repo includes in the pre-built scan

Re: [Openvas-discuss] arachni, etc.

2014-09-30 Thread Jack Harvey
-4939 From: Brandon Perry [mailto:bperry.volat...@gmail.com] Sent: Tuesday, September 30, 2014 3:59 PM To: Jack Harvey Cc: Reindl Harald; openvas-discuss@wald.intevation.org Subject: Re: [Openvas-discuss] arachni, etc. Arachni and wapiti I would highly recommend running separately from OpenVAS

Re: [Openvas-discuss] arachni, etc.

2014-09-30 Thread Brandon Perry
*Subject:* Re: [Openvas-discuss] arachni, etc. Arachni and wapiti I would highly recommend running separately from OpenVAS. These tools can be highly customized to be as effective as possible for web applications, and any generic check that runs them will certainly not be the optimal settings

Re: [Openvas-discuss] arachni, etc.

2014-09-30 Thread Reindl Harald
Am 30.09.2014 um 22:06 schrieb Jack Harvey: So I just clone the desired config, edit and UN-select both wapiti and arachni. Are there any others? I ask because previously dirb and nikto gave similar “can’t be found, etc.’ messages. I believe this is not currently the case with them