On Fri, 3 Oct 2003, Renaud Deraison wrote:
> On Fri, Oct 03, 2003 at 11:50:15AM -0500, Omernik, John wrote:
> > Does that mean if you use the built in SYS scan instead that it won't be
> > able to guess what is running? Is NMAP required?
>
> No, any kind of port scanner will work well.
Or to be more specific:
stage 1 does a port scan using nmap or part of the nmap code inside nessus
and will find tcp/600 open.
stage 2 is when the find_service tool comes in and tries to figure out who
lives there.
stage 3 is where all relevant tests (with webserver this means dozens and
dozens of tests) are performed for the specific service.
(Correct me if I am wrong.)
Hugo.
--
All email sent to me is bound to the rules described on my homepage.
[EMAIL PROTECTED] http://hvdkooij.xs4all.nl/
Don't meddle in the affairs of sysadmins,
for they are subtle and quick to anger.