On Thu, Jan 24, 2002 at 03:42:10PM -0600, Russ Foster wrote:
> The most likely problem is Nessus is being run too hot and some packets are
> getting dropped or ignored.
> 
> Lower the Max Threads value and raise the timeout values.

And if you use Nessus 1.1.x, you want to lower the number of concurrent
checks. 

Note differences between reports may be due to :

(a) Network Congestion
(b) Services disabled by the previous check
(c) Inetd's braindeadness


For (a), you want to reduce the number of hosts being scanned at the
same time (or increase your bandwidth [killall -9 ftp is a good start
:]). 

For (b), you want to use Nessus 1.1.x with the "safe checks" option
(and also make sure to disable dangerous plugins, as plugins labelled
as being dangerous are STILL dangerous with safe checks)

(c) happens when an inetd-spawn service is hit too many times in a short
lapse of time. inetd, trying to be clever (as always), says "hey, this
service <insert service name here> is f*cking popular! I'll shut it
down". As a result, not all tests are launched against this service, and
you end up with evil False Negatives. The solution is to tune Nessus
properly (as all inetd are not equal). To do this, you first want to
reduce the number of checks to be performed at the same time to a lower
value, and if that still does not help, you may want to increase the
value of the option "delay_between_tests" in nessusd.conf.


                                -- Renaud

Reply via email to