On Monday 26 August 2002 16:47, Renaud Deraison wrote:
> Question: if Nessus detects that a web server does not respect the HTTP
> protocol, and therefore does not reply properly to the requests, should
> it disable all the CGI checks altogether and issue a big fat warning
> explaining why the web server was not tested instead ?

No, there are some fairly simple ways to detect these servers and avoid 
false positives using the current no404 system. A small change to the 
nessus library code and a new no404.nasl solved all of the false positive 
issues we have run into.

-HD
-
[EMAIL PROTECTED]: general discussions about Nessus.
* To unsubscribe, send a mail to [EMAIL PROTECTED] with
"unsubscribe nessus" in the body.

Reply via email to