Well, here is the 30,000 foot view. Nessus runs on a box that is dual-homed. For argument sake:
eth0 - (Nessus interface) eth1 - Admin interface eth0 is on a DMZ rail eth1 is on an admin rail The overall concept is this. Eth1 is used to collect results, change .nessusrc files, etc. Eth0 is on a DMZ, and if bound to an IP address, is vulnerable to attack from anyone on this segment. If Nessus was able to send packets out with spoofed IP/MAC addresses, and then sniff the results off the wire, it could perform the necessary scans, but not itself be vulnerable to attack on that segment. Does this make sense? I know that this is WAY over my head (still learning), but I would like to see if it is possible, or try to figure out a way to retro-fit Nessus to do this. Comments are appreciated! Bob -----Original Message----- From: Renaud Deraison [mailto:[EMAIL PROTECTED]] Sent: Thursday, January 24, 2002 9:31 AM To: '[EMAIL PROTECTED]' Subject: Re: Nessus on "blind" interface On Thu, Jan 24, 2002 at 09:00:38AM -0500, Perciaccante, Robert wrote: > Not sure if this has been covered, but I did not see it in the archives... > > I am trying to figure out how Nessus can be used on a blind nic, so that is > can reside on a network rail, and not be visible. > > Is there a way, or process you might recommend, to use IP\ARP spoofing and > the NIC in promiscious mode to enable Nessus to run on such an interface? > What do you want to do ? hide nessusd from the network (ie: nobody can connect to it remotely), or prevent nessusd from revealing its IP address at all during the tests ? (which is impossible). If it's just the first, you can do nessusd -a 127.0.0.1 If it's the second, well, you mix nessusd with a sniffer... -- Renaud
