On Fri, 3 Oct 2003, Renaud Deraison wrote:

> On Fri, Oct 03, 2003 at 11:50:15AM -0500, Omernik, John wrote:
> > Does that mean if you use the built in SYS scan instead that it won't be
> > able to guess what is running? Is NMAP required?
> 
> No, any kind of port scanner will work well.

Or to be more specific:

stage 1 does a port scan using nmap or part of the nmap code inside nessus 
and will find tcp/600 open.

stage 2 is when the find_service tool comes in and tries to figure out who 
lives there.

stage 3 is where all relevant tests (with webserver this means dozens and 
dozens of tests) are performed for the specific service.

(Correct me if I am wrong.)

Hugo.

-- 
 All email sent to me is bound to the rules described on my homepage.
    [EMAIL PROTECTED]           http://hvdkooij.xs4all.nl/
            Don't meddle in the affairs of sysadmins,
            for they are subtle and quick to anger.

Reply via email to