I've recently compiled the newest "stable" release of Nessus and have run
several tests against some web servers.  The results from the scan show a
huge number, at least 40 each, of false positives on port 80.  Most of the
false positives involve cgi-bin.  None of the servers have a cgi-bin
directory, real or virtual. 

Nessus also incorrectly identifies the operating system of each of the
servers.  They are all running NT.  Nessus, or rather Queso seems to think
that they're Reliant Unix.  I have tried changing the checks_read_timeout
value anywhere from 5 to 25 but still get similar results.

As a sanity check I have compared the scans with a recent cybercop scan run
against the same machines. Cybercop reports 21 infos and/or holes. Nessus is
reporting 68 infos and/or holes.  Any ideas on this?  The nessus server
portion is running on Solaris 8.

I am also having issues with nessus processes going to sleep on the server.
This problem occurs when a scan is run against a larger number of hosts.
The number varies from 20 to 60, depending on the checks_read_timeout
setting.  I have looked through the list archives and found a suggestion to
compile without the cipher layer.  I have tried this and still get the same
results, so I am using the cipher layer again.

Thanks in advance for any feedback

=======================
Joe Zurba
Security Engineer
NaviSite, Inc.
400 Minuteman Rd.
Andover, MA. 01810
(978) 946-5869
mailto:[EMAIL PROTECTED]
http://www.navisite.com
=======================

Reply via email to