Well, here is the 30,000 foot view.

Nessus runs on a box that is dual-homed.  For argument sake:

eth0 - (Nessus interface)
eth1 - Admin interface

eth0 is on a DMZ rail
eth1 is on an admin rail

The overall concept is this.  Eth1 is used to collect results, change
.nessusrc files, etc.  Eth0 is on a DMZ, and if bound to an IP address, is
vulnerable to attack from anyone on this segment.

If Nessus was able to send packets out with spoofed IP/MAC addresses, and
then sniff the results off the wire, it could perform the necessary scans,
but not itself be vulnerable to attack on that segment.

Does this make sense?  I know that this is WAY over my head (still
learning), but I would like to see if it is possible, or try to figure out a
way to retro-fit Nessus to do this.

Comments are appreciated!

Bob


-----Original Message-----
From: Renaud Deraison [mailto:[EMAIL PROTECTED]]
Sent: Thursday, January 24, 2002 9:31 AM
To: '[EMAIL PROTECTED]'
Subject: Re: Nessus on "blind" interface


On Thu, Jan 24, 2002 at 09:00:38AM -0500, Perciaccante, Robert wrote:
> Not sure if this has been covered, but I did not see it in the archives...
> 
> I am trying to figure out how Nessus can be used on a blind nic, so that
is
> can reside on a network rail, and not be visible.
> 
> Is there a way, or process you might recommend, to use IP\ARP spoofing and
> the NIC in promiscious mode to enable Nessus to run on such an interface?
> 

What do you want to do ? hide nessusd from the network (ie: nobody can
connect to it remotely), or prevent nessusd from revealing its IP
address at all during the tests ? (which is impossible).

If it's just the first, you can do
        nessusd -a 127.0.0.1


If it's the second, well, you mix nessusd with a sniffer...

                                -- Renaud

Reply via email to