Re: [Openvas-discuss] OpenVAS 8: scans not finishing

2015-04-15 Thread Michael Meyer
> > I have tcpdumps of both scans, but it doesn't tell much beyond the > above. I'll see if I can find a simple way to reproduce this. Does it help to change: buf = recv( socket:soc, min:4, length:4 ); to buf = recv( socket:soc, length:4 ); if( strlen( buf ) < 4 ) exit( 0 );

Re: [Openvas-discuss] OpenVAS 8: scans not finishing

2015-04-16 Thread Michael Meyer
*** Kent Fritz wrote: > Yes, that makes the problem go away, but my bigger concern is that hung > scripts are not terminated on OpenVAS 8 Yes, absolutly. I've opened an (internal GB-) ticket for this problem. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A

Re: [Openvas-discuss] MS CVE not checked ?

2015-04-22 Thread Michael Meyer
*** Knoblauch, Simon wrote: > Windows log is successfull all the time, but still no information > about missing updates... got InternetExplorer Information and > Servicepack http://www.greenbone.net/learningcenter/auth_scans.html Micha -- Michael Meyer Op

Re: [Openvas-discuss] HTTP.sys CVE-2015-1635 : Setting up a single scan

2015-04-28 Thread Michael Meyer
eport. I've told OpenVAS to assume the > target is alive. Enable: Port Scanners -> nmap (NASL Wrapper) ping host Web application abuses -> MS15-034 HTTP.sys Remote Code Execution ... That should wor

Re: [Openvas-discuss] Broken WMI dep for OpenVAS from Atomic repo?

2015-05-05 Thread Michael Meyer
penVAS IRC channel. (http://openvas.org/online-chat.html). Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunwald, Dr. Jan-Oliver

Re: [Openvas-discuss] Install from Binary Packages on CentOS

2015-05-13 Thread Michael Meyer
*** Eero Volotinen wrote: > Please stop trolling and just disable it. The only reason that OpenVAS suggest to disable selinux is, that no one ever take care about what's the problem. So at the end Brandon is right. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EF

Re: [Openvas-discuss] https sites fail

2015-05-26 Thread Michael Meyer
ut or something like that? Something else interesting in /var/log/openvas/openvassd.{messages,dump}? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer

Re: [Openvas-discuss] Syn cert data without using rsync?

2015-05-30 Thread Michael Meyer
e:port pair pointing to your web proxy. Note that your web proxys configuration must support proxy connections to port 873." Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG

Re: [Openvas-discuss] false positives

2015-06-01 Thread Michael Meyer
5.1.68, 5.2.15, 5.3.13, 5.5.30 or later, For > updates refer to https://mariadb.org > > uhm, there is running 10.0.19 on *Linux* Which version was detected by '1.3.6.1.4.1.25623.1.0.100152'? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http:

Re: [Openvas-discuss] false positives

2015-06-02 Thread Michael Meyer
*** Reindl Harald wrote: > you just need to handle the version in the greeting correct, the > 5.5- versioning is for clients with no idea about mariadb at all Thanks...We'll take care... Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.gr

Re: [Openvas-discuss] false positives

2015-06-05 Thread Michael Meyer
*** Reindl Harald wrote: > you just need to handle the version in the greeting correct, the > 5.5- versioning is for clients with no idea about mariadb at all Should be fixed in r1314. Thanks for reporting. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6

Re: [Openvas-discuss] latest version of openvas br0ken?

2015-06-09 Thread Michael Meyer
vn.wald.intevation.org/svn/openvas/trunk/openvas-scanner/doc/ Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunw

Re: [Openvas-discuss] "Client not present" error in OpenVAS 8

2015-06-13 Thread Michael Meyer
n/openvas/trunk/openvas-scanner/doc/redis_config.txt) SELinux is disabled? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, H

Re: [Openvas-discuss] "Client not present" error in OpenVAS 8

2015-06-15 Thread Michael Meyer
*** Brian Thompson wrote: >Any other ideas? Maybe the scanner was not able to detect the target as up (grep -i dead /var/log/messages). If so try another "Alive Test" when creating a target. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.

Re: [Openvas-discuss] "Client not present" error in OpenVAS 8

2015-06-15 Thread Michael Meyer
*** Brian Thompson wrote: >The only thing I see in /var/log/messages is: > ># grep -i dead /var/log/messages Sorry ... "/var/log/openvas/openvassd.messages" :) Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Gree

Re: [Openvas-discuss] "Client not present" error in OpenVAS 8

2015-06-16 Thread Michael Meyer
*** Brian Thompson wrote: >But still no reports generated. Set all "level" to 128 in "/etc/openvas/openvasmd_log.conf" and start manager with "-v". Watch "/var/log/openvas/openvasmd.log" when accessing a report. Maybe you'll see

Re: [Openvas-discuss] OpenVAS 8 virtual appliance

2015-06-22 Thread Michael Meyer
*** Brandon Perry wrote: > The error on screen after trying to auth via GSA is Cookie missing > or bad. Please login again. Time is in sync on VM and Client? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH,

Re: [Openvas-discuss] Missing CVEs

2015-06-22 Thread Michael Meyer
*** Public Account wrote: > More info: > I updated the feeds with: > $ openvas-scapdata-sync > $ openvas-nvt-sync > $ openvas-certdata-sync Did you restart the scanner and did you run "openvasmd --rebuild" after that? Micha -- Michael Meyer OpenPG

Re: [Openvas-discuss] local account used for scans

2015-07-01 Thread Michael Meyer
nstalled packages via SSH login (1.3.6.1.4.1.25623.1.0.50282)". What did they report? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Luka

Re: [Openvas-discuss] local account used for scans

2015-07-01 Thread Michael Meyer
CentOS v6.4.) If you add the user to the sudoers file of the target, the *login* is successful? A login with the same user had failed because the user was not in the sudoers file? I don't think that this is related to OpenVAS. Micha -- Michael Meyer OpenPGP Key: 0xAF069

Re: [Openvas-discuss] Problems to migrate V7 to V8 OpenVAS

2015-07-06 Thread Michael Meyer
*** LABOURIAUX Pierrick wrote: > < FIX: You should start the redis-server or configure it to listen on socket: > /tmp/redis.sock > https://svn.wald.intevation.org/svn/openvas/trunk/openvas-scanner/doc/redis_config.txt -- Michael Meyer OpenPGP Key: 0xAF069E9152

Re: [Openvas-discuss] nasl script development

2015-08-13 Thread Michael Meyer
gnature and not running > the script? add "-X" to openvas-nasl (see also --help). Maybe join our IRC on further questions, then i can help you directly. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Gra

Re: [Openvas-discuss] Severity in error, access denied when scanning any remote hosts

2015-08-14 Thread Michael Meyer
*** Jeremy MJ wrote: > [Fri Aug 14 14:49:39 2015][4026] Host testhost.com access denied. Sounds like "GSA -> Administration -> Users -> Edit -> Host Access" Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Green

Re: [Openvas-discuss] Good list to send Unknown services banners?

2015-08-17 Thread Michael Meyer
/listinfo/openvas-plugins :) Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunwald, Dr.

Re: [Openvas-discuss] amazon local security checks for openvas8

2015-09-04 Thread Michael Meyer
*** Jan-Oliver Wagner wrote: > I assume there is also a basic detection NVT for Amazon? a patch from Eero to detect Amazon Linux was already applied to gather-package-list.nasl Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenb

Re: [Openvas-discuss] my first beta release of amazon linux security checks

2015-09-06 Thread Michael Meyer
nse do you publish them? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunwald, Dr.

Re: [Openvas-discuss] my first beta release of amazon linux security checks

2015-09-06 Thread Michael Meyer
g/linux-notes/determine-and-change-file-character-encoding/ Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunwald

Re: [Openvas-discuss] Errors with authenticated scans in CentOS 7

2015-09-07 Thread Michael Meyer
*** Kenny Aondona wrote: > md main:WARNING:2015-09-07 16h12.22 UTC:7322: sql_prepare_internal: > sqlite3_prepare failed: no such table: current_credentials http://lists.wald.intevation.org/pipermail/openvas-discuss/2015-August/008317.html Micha -- Michael Meyer OpenP

Re: [Openvas-discuss] Running gb_openssl_ccs_67899.nasl

2015-09-12 Thread Michael Meyer
*** Howard Sheen wrote: > I tried to run gb_openssl_ccs_67899.nasl individually to check > "CVE-2014-0224" but my command does not seem to work. Replace port = get_kb_item("Transport/SSL"); with port = 443; if you want to run the NVT against po

Re: [Openvas-discuss] Running gb_openssl_ccs_67899.nasl

2015-09-15 Thread Michael Meyer
*** Howard Sheen wrote: > Is there anything I can try in addition the fix you suggested? run openvas-nasl with "-T -". Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück |

Re: [Openvas-discuss] Setting up SSH connection to WHM (CPanel) Centos Box

2015-09-18 Thread Michael Meyer
n the target? Anything special in sshd_config of the target? What is the libssh version on the scanner host? Maybe updating libssh to >= 0.7.0 will help. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074

Re: [Openvas-discuss] Setting up SSH connection to WHM (CPanel) Centos Box

2015-09-18 Thread Michael Meyer
t; Sep 15 17:16:01 bh01 sshd[10036]: Proto­col major versions differ for > 75.*.*.*: SSH-2.0-OpenSSH_6.6.1 vs. SSH-1.5-­OpenVASSSH_1.0 This is from ssh_proto_version.naslwhich try to detect supported SSH protocol versions. This has nothing to do with the login. Micha -- Michael Meyer

Re: [Openvas-discuss] Samba log on suddenly failing for authenticated scans

2015-09-18 Thread Michael Meyer
gin directory with this one. If you have "nasl_no_signature_check = no" in your openvassd.conf set it to "yes". Restart the scanner and scan again. Is the scanner now able to login? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.

Re: [Openvas-discuss] Dovecot Sieve Plugin Multiple Buffer Overflow Vulnerabilities

2015-09-19 Thread Michael Meyer
t location /usr/libexec/dovecotstdin Ok...problem is in the detection NVT. Thanks for reporting. @Antu: Please have a look. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrü

Re: [Openvas-discuss] Running gb_openssl_ccs_67899.nasl

2015-09-19 Thread Michael Meyer
penvas/plugins/2014/gb_openssl_ccs_67899.nasl -i /usr/local/var/lib/openvas/plugins/ -T - Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Luka

Re: [Openvas-discuss] Samba log on suddenly failing for authenticated scans

2015-09-19 Thread Michael Meyer
ll contact you fore some details about your configuration. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunwald, Dr. Jan

Re: [Openvas-discuss] Pango Integer Buffer Overflow Vulnerability - False Positive?

2015-09-20 Thread Michael Meyer
de to pango version 1.24.0 or later > http://ftp.acc.umu.se/pub/GNOME/sources/pango/ > Affected Software/OSPango version prior to 1.24.0 @Antu: Please have a look. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Netwo

Re: [Openvas-discuss] greetings + empty vuln

2015-10-06 Thread Michael Meyer
*** cory cardio wrote: > Noticed an empty vuln in a report today, and I was hoping to report it... > Is this the proper place to do so? Which version of OpenVAS? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH,

Re: [Openvas-discuss] GSAD: rendering of webinterface

2015-10-11 Thread Michael Meyer
*** Reindl Harald wrote: > i wonder why even in the newest version things are one above the > other and no developer is annoyed by that (see screenshot) I wonder why it's not possible to give relevant information like browser, browser version, gsa version, os, ... :) Micha -- Mi

Re: [Openvas-discuss] Samba log on suddenly failing for authenticated scans

2015-10-12 Thread Michael Meyer
h the old smb_login.nasl a login to the target is possible, because the script set the Domain ever. With the new script, the Domain will only be set if the User sets the Value in the login credentials and therefore no login is possible! HTH Micha -- Michael

Re: [Openvas-discuss] about 1.3.6.1.4.1.25623.1.0.15640 Numbered pluging

2015-10-21 Thread Michael Meyer
OpenVAS Enable also "Port Scanners" -> "Nmap (NASL wrapper)" and try again. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Gesc

Re: [Openvas-discuss] Errors compiling openvas-scanner under CentOS7

2015-10-27 Thread Michael Meyer
dis.service > >systemctl restart redis.service > > the bug is more that openvas expects a socket in /tmp mime@kira[4]:~/ (0)$ openvassd -s | grep redis kb_location = /var/run/redis/redis.sock mime@kira[4]:~/ (0)$ openvassd --version OpenVAS Scanner 5.1+beta3 SVN revision 23678 Micha

Re: [Openvas-discuss] Asterisk False-Positives

2015-11-03 Thread Michael Meyer
ereference Overflow (OID: > 1.3.6.1.4.1.25623.1.0.991) > > Upgrade to Asterisk PBX release 1.4.1 or 1.2.16. > > Details: Asterisk PBX SDP Header Overflow Vulnerability (OID: > 1.3.6.1.4.1.25623.1.0.992) > > Upgrade to Asterisk release 1.4.2/1.2.17 or newer. Than

Re: [Openvas-discuss] scap data behind proxy

2015-11-05 Thread Michael Meyer
t your web proxy's configuration must | support proxy connections to port 873. `---| Or use a different host for the rsync and just scp the files to the scanner host. Or setup an internal rsync mirror and point to this mirror in openvas-scapdata-sync... HTH Micha -- Mi

Re: [Openvas-discuss] Service temporarily down

2015-11-06 Thread Michael Meyer
Start Task > Status code:503 > Status message: Service temporarily down https://svn.wald.intevation.org/svn/openvas/trunk/openvas-manager/INSTALL -> "Updating Scanner Certificates". HTH Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A

Re: [Openvas-discuss] Not getting the same test result for the further time

2015-11-24 Thread Michael Meyer
. If it was successfull at the first scan, it make sense that later scans not showing this if the TFTPd was not restarted... Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Os

Re: [Openvas-discuss] openvas-nvt-feed

2015-11-27 Thread Michael Meyer
ed_info.inc". Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunwald, Dr. Jan-Oliver Wagner __

Re: [Openvas-discuss] Scanner doesn't start

2016-01-04 Thread Michael Meyer
r missing > signature. Will not execute this script Read http://openvas.org/trusted-nvts.html or set "nasl_no_signature_check = yes" in /etc/openvas/openvassd.conf Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Network

Re: [Openvas-discuss] All scans result in no results

2016-01-18 Thread Michael Meyer
*** Ralf Hildebrandt wrote: > I'm running openvas9 installed from the PPA > https://launchpad.net/~mrazavi/+archive/ubuntu/openvas [...] > Checking for SELinux ... As the result is missing in your log, selinux is disabled? Micha -- Michael Meyer

Re: [Openvas-discuss] Questions about Compilation

2016-02-03 Thread Michael Meyer
compile this amazing open > source software; If there is, where is switch(sorry, I am not very familiar > with CMake) cmake -DCMAKE_BUILD_TYPE=Release Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49

Re: [Openvas-discuss] Autogenerate credential

2016-02-10 Thread Michael Meyer
pm * fakeroot * alien Prerequisites for generating credentials .exe packages: * makensis (usually distributed as part of nsis)" Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück |

Re: [Openvas-discuss] Are the Greenbone reports supported in OpenVAS?

2016-02-29 Thread Michael Meyer
*** Juan Moreno wrote: > Is there any resource that we can follow in order to learn how to generate > reports for OpenVAS? https://svn.wald.intevation.org/svn/openvas/trunk/openvas-manager/doc/report-format-HOWTO Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6

Re: [Openvas-discuss] openvas 8 log output

2016-03-19 Thread Michael Meyer
ion is; I have ???Negative index !??? after every plugin. Is it really *every* NVT or "only" the web based ones? What is running on this target? Especially which web services? Which scan config did you use? Which (web) services where detected by the scanner? Micha -- Michael M

Re: [Openvas-discuss] openvas 8 log output

2016-03-22 Thread Michael Meyer
;s from get_array_elem() (openvas-libraries/nasl/nasl_var.c). Seems there is something "strange" in an array. Hard to say what exactly is going on... Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 4907

Re: [Openvas-discuss] Import 0 byte PDF report

2016-03-23 Thread Michael Meyer
The PDF report format will not work. > SUGGEST: Install required LaTeX packages. > > I had run "zipper install latex*" , but it still exists , what shoud I do? zypper in texlive-latex texlive-comment If that is not enough, look in the log openvas-check-setup is gen

Re: [Openvas-discuss] Import 0 byte PDF report

2016-03-24 Thread Michael Meyer
*** Liyaping (Security Tools) wrote: > It didn't worked, see " more /tmp/openvas-check-setup.log " > There are two errors: > Package ifvtex Info: VTeX not detected. > ! LaTeX Error: File `utf8x.def' not found. zypper in texlive-ucs Micha -- Michael Me

Re: [Openvas-discuss] Scan fails with "503 Service temporarily down"

2016-04-11 Thread Michael Meyer
*** Ralf Hildebrandt wrote: >WARNING: OpenVAS Scanner is NOT running! >SUGGEST: Start OpenVAS Scanner (openvassd). Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrüc

Re: [Openvas-discuss] Scan fails with "503 Service temporarily down"

2016-04-11 Thread Michael Meyer
;openvasmd --rebuild -v" and look if you see anything interesting in /var/log/openvasmd.log. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osna

Re: [Openvas-discuss] Scan fails with "503 Service temporarily down"

2016-04-11 Thread Michael Meyer
*** Ralf Hildebrandt wrote: > root 32756 44.6 0.0 163740 32256 ?Ss 13:23 1:15 openvassd: > Reloaded all the NVTs. Still missing the "openvassd: Waiting for incoming connections" state. Hmm..please check also /var/log/openvas/openvassd.messages. Micha -

Re: [Openvas-discuss] Scan fails with "503 Service temporarily down"

2016-04-11 Thread Michael Meyer
as/trunk/openvas-scanner/doc/redis_config.txt Maybe try to set 'save ""' in /etc/redis/default.conf, restart redis and try again. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnab

Re: [Openvas-discuss] Scan fails with "503 Service temporarily down"

2016-04-11 Thread Michael Meyer
*** Ralf Hildebrandt wrote: > * Michael Meyer : > > *** Ralf Hildebrandt wrote: > > > > > # strace -p 4949 > > > strace: Process 4949 attached > > > restart_syscall(<... resuming interrupted nanosleep ...>) = 0 > > > write(6, "*4\r\

Re: [Openvas-discuss] Scan fails with "503 Service temporarily down"

2016-04-11 Thread Michael Meyer
d to > attach client session to socket 10 > lib serv:WARNING:2016-04-11 13h54.58 utc:21258:Failed to gnutls_bye: > GnuTLS internal error. Could it be that this was a scan against localhost? Then it is ok... Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA

Re: [Openvas-discuss] Compare Reports

2016-04-13 Thread Michael Meyer
as (hopefully) already solved with r24577 and r24578. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunwald, Dr. Jan-Oliver Wagner ___

Re: [Openvas-discuss] Making Web Credentials available to normal users

2016-04-27 Thread Michael Meyer
*** TN TN wrote: > Is it possible to allow a user to enter website credentials to a password > protected site. Out of curiosity, why exactly will you do that? > If this doesnt currently exist is it on the roadmap? Yes, it is. Micha -- Michael Meyer Op

Re: [Openvas-discuss] Reg Pre-Windows 2000 Compatibility Vulnerability

2016-04-28 Thread Michael Meyer
*** Sai Ravi wrote: > Can we consider this vulnerability as false positive as we do not > see any users under "pre-Windows 2000 compatibility"? This NVT reports what it has gathered. On this output you should decide if it is a false positive or not. Micha -

Re: [Openvas-discuss] Reg Apache Vulnerability

2016-05-25 Thread Michael Meyer
*** Reindl Harald wrote: > i find it just somehow laughable to scan in 2016/05 a 2.4.7 httpd man backports Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202

Re: [Openvas-discuss] Reg Apache Vulnerability

2016-05-25 Thread Michael Meyer
*** Reindl Harald wrote: > Am 25.05.2016 um 10:54 schrieb Michael Meyer: > >*** Reindl Harald wrote: > > > >>i find it just somehow laughable to scan in 2016/05 a 2.4.7 httpd > > > >man backports > > you missed that he talks about windows as OS an

Re: [Openvas-discuss] openvasmd regular tasks.db corruption issue

2016-05-25 Thread Michael Meyer
as (https://svn.wald.intevation.org/svn/openvas/trunk/openvas-scanner/doc/)? Especially do you have all lines beginning with "save" commented out? If it's not a redis issue. Could you please run "sqlite3 tasks.db "PRAGMA integrity_check;" next time it happens? Micha -- Mic

Re: [Openvas-discuss] Reg Apache Vulnerability

2016-05-25 Thread Michael Meyer
*** Sai Ravi wrote: > It shows "windows" as the affected OS.But our scan was on > "Enterprise Linux".We are unsure on how to proceed further with this > vulnerability. Which OS has been detected in this scan? Micha -- Michael Meyer OpenPGP

Re: [Openvas-discuss] openvasmd regular tasks.db corruption issue

2016-05-25 Thread Michael Meyer
hem out and delete the dump.rdb. Start redis. Restart the scanner. Does it help? root@kali-gis-eur:/var/lib/openvas/mgr# sqlite3 tasks.db "PRAGMA > integrity_check;" > ok Ok...so probably not an tasks.db corruption issue... Micha -- Michael Meyer OpenPGP Ke

Re: [Openvas-discuss] Running a script: how to specify a parameter

2016-05-25 Thread Michael Meyer
s-nasl -X --kb "Services/www=80" ... With older versions of openvas-nasl you have to change the port directly in the NVT... Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Os

Re: [Openvas-discuss] Running a script: how to specify a parameter

2016-05-26 Thread Michael Meyer
*** Sebastien Aucouturier wrote: > That's a very new nice feature for openvas-nasl, it will definitively save > time when debugging pluging. > is it available in openvas9 official release? or from trunk ? Since libraries 8.1+beta3, IIRC. Micha -- Michael Meyer

Re: [Openvas-discuss] the certificate has expired

2016-05-31 Thread Michael Meyer
er Certificates"... Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunwald, Dr. Jan-Oliver Wagner

Re: [Openvas-discuss] Is YaBB a false positive

2016-06-04 Thread Michael Meyer
*** daniel_feenb...@yahoo.com wrote: > We are just beginning to use Openvas and are seeing High (10.0) > severity scores at port 80 of our web server for the YaBB program. It's probably a false positive. I'll update the NVT. Micha -- Michael Meyer

Re: [Openvas-discuss] Default Brute Force SSH Logins

2016-06-14 Thread Michael Meyer
l of > the users that were in this file. Edit your scanconfig, go into family "Default Accounts" and disable "SSH Brute Force Logins with default Credentials (103239)" Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/

Re: [Openvas-discuss] Help!!! Internal Error

2016-06-17 Thread Michael Meyer
*** Discover Bug wrote: > md main:WARNING:2016-06-15 21h27.47 CEST:17512: sql_prepare_internal: > sqlite3_prepare failed: no such table: current_credentials http://lists.wald.intevation.org/pipermail/openvas-discuss/2015-August/008317.html Micha -- Michael Meyer O

Re: [Openvas-discuss] OpenVAS 8 virtual appliance - unable to start task

2016-06-22 Thread Michael Meyer
*** Arthur Warnier wrote: > I've recently deployed the demo image of OpenVAS 8 (from > http://www.openvas.org/vm.html) http://plugins.openvas.org/ova_503.txt Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks

Re: [Openvas-discuss] openvassd scanner failing while loading NVTs. SEGV signal. Segmentation fault

2016-07-20 Thread Michael Meyer
e check if there are 2 gb_tls_version.nasl in your plugin directory. If yes, delete one of them. It's an issue with the feed... > [Tue Jul 19 17:15:42 2016][8183] received the SEGV signal Which scanner version is this? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http:

Re: [Openvas-discuss] 1. openvassd scanner failing while loading NVTs. SEGV signal.

2016-07-20 Thread Michael Meyer
*** Kaon Thana wrote: > I am running scanner version 4.0.2. Manager version 5.0.3. Ubuntu 14.04.4 > LTS > > I don't see 2 copies of that NVT: > > /var/lib/openvas/plugins# ls -ltr gb_tls* find /var/lib/openvas/plugins -name gb_tls_version.nasl Mi

Re: [Openvas-discuss] 1. openvassd scanner failing while loading NVTs. SEGV signal.

2016-07-20 Thread Michael Meyer
and > I have to delete it everytime? This will be fixed in the feed tomorrow Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas

Re: [Openvas-discuss] 1. openvassd scanner failing while loading NVTs. SEGV signal.

2016-07-20 Thread Michael Meyer
db_versions: > database version of database: 123 > md main:MESSAGE:2016-07-18 18h57.37 utc:16229: check_db_versions: > database version supported by manager: 146 > md main:CRITICAL:2016-07-18 18h57.37 utc:16229: main: database is wrong > version Run "openvasmd --migrate" and

Re: [Openvas-discuss] Reinstall Issues

2016-07-25 Thread Michael Meyer
*** Turner,Jonas wrote: > can't get to my admin homepage. Means what? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grun

Re: [Openvas-discuss] Reinstall Issues

2016-07-25 Thread Michael Meyer
*** Turner,Jonas wrote: > tcp0 0 127.0.0.1:9392 0.0.0.0:* LISTEN > 2534/gsad https://localhost:9392 If you want to have the gsa listen on the external interface, see /etc/sysconfig/gsad or "gsad --help". Micha -

Re: [Openvas-discuss] Openvas 7 to Openvas 8 : openvasmd rebuild failed to shake hands with peer

2016-07-27 Thread Michael Meyer
anager/INSTALL -> "Updating Scanner Certificates" Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grun

Re: [Openvas-discuss] weak ciphers on port 25

2016-08-02 Thread Michael Meyer
*** Reindl Harald wrote: > sorry, but that is pure nonsense no, it's some kind of bug in the NVT. I'll have a look... Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG

Re: [Openvas-discuss] weak ciphers on port 25

2016-08-02 Thread Michael Meyer
reenshot. Ich habe auch noch ein secpod_ssl_ciphers_setting.nasl an diese Mail angehängt. Darin habe ich nur einige Variablen umbenannt. Wenn du damit auch nochmal testen könntest... Ja, gut, sind dann schon 2 Gefallen...:) Viele Grüße Micha -- Michael Meyer OpenPGP

Re: [Openvas-discuss] Scanning Hostnames/URLs

2016-08-08 Thread Michael Meyer
s. I agree that this is a bit confusing, but this does not mean that the scanner is not using the hostname. In openvassd.messages look for "Starts a new scan. Target(s) : myhostname.com, with max_hosts = 30 and max_checks = 10" This name will then be used in the http host heade

Re: [Openvas-discuss] OpenVAS - Unstable

2016-09-06 Thread Michael Meyer
*** Turner,Jonas wrote: > status="503"> Try http://plugins.openvas.org/ova_503.txt Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschä

Re: [Openvas-discuss] OpenVAS - Unstable

2016-09-06 Thread Michael Meyer
ot;--rebuild" works now? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunwald, Dr. Jan-Oliver Wagner ___

Re: [Openvas-discuss] OpenVAS - Unstable

2016-09-07 Thread Michael Meyer
Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunwald, Dr. Jan-Oliver Wagner ___ Openvas-d

Re: [Openvas-discuss] False positives by pfile Multiple Cross Site Scripting and SQL Injection Vulnerabilities

2016-09-20 Thread Michael Meyer
*** Corti Matteo (ID BD) wrote: > I get a warning for "pfile Multiple Cross Site Scripting and SQL > Injection Vulnerabilities??? > (http://plugins.openvas.org/nasl.php?oid=103435) Thanks for reporting. I'l take care... Micha -- Michael Meyer OpenPGP Key:

Re: [Openvas-discuss] Change GSA listening port

2016-09-28 Thread Michael Meyer
ave tried the command : > > gsa --listen 192.168.89.60:55560 gsad --help Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grun

Re: [Openvas-discuss] Plugins RSS Feed?

2016-10-18 Thread Michael Meyer
an make > that happen with a simple setting? No, but i'll habe a look. It's just a question of time... If you didn't see a RSS feed at the end of the year, please send me a reminder. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone

Re: [Openvas-discuss] Error in exporting result "preload" Missing in HSTS Header to CSV Results

2016-11-15 Thread Michael Meyer
*** Ebert, Christian wrote: > 2)Substitute the " with ' in the NVT name Done in r4523 using ` as workaround for the moment. Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 O

Re: [Openvas-discuss] scans take forever - sometimes...

2016-11-30 Thread Michael Meyer
NASL wrapper)". Change the "TCP scanning technique :" to "SYN scan". Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück |

Re: [Openvas-discuss] scans take forever - sometimes...

2016-11-30 Thread Michael Meyer
one, change the TCP Scanning Technique" to SYN > then use that clone in my scans. Ohh...sorry, completly overlooked. Ignore my last mail. The above should work. I'll have a look if there is a problem in the NVT or something else. Micha -- Michael Meyer OpenPGP K

Re: [Openvas-discuss] scans take forever - sometimes...

2016-12-01 Thread Michael Meyer
*** Michael Meyer wrote: > *** fschnit...@execulink.com wrote: > > > Ok, so as it appears _all_ of the OpenVAS default scanner configs use > > a default scan mode of TCP Connect (connect()). I see that what I need > > to do for my fast scans that are firewalled, is t

Re: [Openvas-discuss] Empty Reports and gpgme WARNINGS

2016-12-07 Thread Michael Meyer
ermissions are set to > 750). It's "/var/lib/openvas/gnupg". Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäfts

Re: [Openvas-discuss] Reg Apache Vulnerabilties

2016-12-16 Thread Michael Meyer
.1.4.1.25623.1.0.105937)" for this scan? Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 202460 Geschäftsführer: Lukas Grunwald, Dr. Jan-Oliver Wagner ___

Re: [Openvas-discuss] Weak Signature Algorithm Vulnerability

2016-12-16 Thread Michael Meyer
ill remains the same. https://social.technet.microsoft.com/Forums/exchange/en-US/bcd5e976-ab99-463a-8665-76f88dec2471/security-scan-fail-remote-desktop-sha-1-issue?forum=winserver8gen Micha -- Michael Meyer OpenPGP Key: 0xAF069E9152A6EFA6 http://www.greenbone.net/ Greenbone Networks GmbH, Neuer Gra

  1   2   3   4   5   >