Alan,

There are several ways Nessus can test for a vulnerability:

1) Directly exploiting it. This works very well for information leakage vulnerabilities, or ones like SQL injection and cross-site scripting. Unfortunately, testing buffer overrun or DoS vulnerabilities this way risks harming the target server and for most people this is not acceptable, so a most of the particularly serious vulns cannot be tested this way.
2) Checking for software versions in the registry. This works very well (except a few issues relating to failed installs and no reboots) but is Windows only, relies on the SMB ports being open and requires domain admin privileges. This makes it only useful on internal networks.
3) Checking the banner. This works well when the banner is present, but false-negatives when the banner is disguised and false-positives when a patch is applied but the version number not changed. This works better on Unix as many Windows services have quite generic banners. This is becoming less useful as more people disguise banners.
4) Version fingerprinting. In general fingerprints aren't sensitive enough to distinguish particular versions where the vuln is fixed. However, you can sometime probe for side changes related to the fix, e.g. the recent OpenSSL ASN vuln and the Messenger RPC overrun. I would regard this type of testing as the cutting edge.


I'm sure this analysis isn't complete.

Paul


alan donald wrote:


I have a few questions. Forgive me if I am naive but
just wanted to clear my mind about the following
questions.

1. What information does nessus need to test a
vulnerability. Only the service name, or the
application name or the complete application
version.
I presume currently nessus is detecting in some
cases
only the service, or the application name or
sometimes
the exact application version.


Why is it that the application version is not
completely made sure of before the vulnerability is
detected.


2. Once it has this information how does it decide
whether to do an exploit or go through the registry.


__________________________________ Do you Yahoo!? Yahoo! Finance: Get your refund fast by filing online. http://taxes.yahoo.com/filing.html _______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus





-- Paul Johnston Internet Security Specialist Westpoint Limited Albion Wharf, 19 Albion Street, Manchester, M1 5LN England Tel: +44 (0)161 237 1028 Fax: +44 (0)161 237 1031 email: [EMAIL PROTECTED] web: www.westpoint.ltd.uk


_______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to