On Fri, Aug 30, 2002 at 01:15:37PM -0700, Tony Torri wrote:
> Hi,
>
> Our NAV scanning software recently found the Virus "EICAR Test String was
> found". This was found on a server that I recently ran a Nessus scan
> against. There is some concern among our admins that the virus was
> "planted" on the server during a Nessus scan. Is that possible?...
No it's not. However Nessus sends an email containing this string
(which is *not* a virus, it just triggers anti-virii) to the remote
host. If the remote MTA starts to keep a local copy of all the mails it
receives, then it might appear as being "planted".
I'm interested by everyone's feedback about this though - I'm not really
sure testing an SMTP server for an anti-virus should be a Nessus test,
what's you take on this check ?
-- Renaud
-
[EMAIL PROTECTED]: general discussions about Nessus.
* To unsubscribe, send a mail to [EMAIL PROTECTED] with
"unsubscribe nessus" in the body.