thanks for explanation - I'm using Nessus for little bit longer time :-) than a year, but I realize that my memory is worser :-) But at least my confusion could help to clear a little this handy KB from edgeos :-)
kamil -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of George Theall Sent: Wednesday, April 21, 2004 4:26 AM To: [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: Re: FTP bounce and also test HTTPS On Tue, Apr 20, 2004 at 12:38:30PM +0200, Golombek Kamil | BDO IT a.s. wrote: > after I looked at edgeos Nessus KB, I noticed two options I've never > seen in my Nessus GUI. You've never seen them presumably because you started using Nessus only within the past year or so -- both options were removed from Nessus before then. Edgeos' knowledge base should probably be updated to reflect that. > The first one was FTP bounce scan > (http://www.edgeos.com/nessuskb/details.php?option_id=222) The plugin ftp_bounce_scan.nes was removed from Nessus in February 2003, purportedly because it was crash-prone and useless; ie, http://cvsweb.nessus.org/cgi-bin/cvsweb.cgi/nessus-plugins/plugins/ftp_b ounce_scan/Attic/ftp_bounce_scan.c > The second was option of NIKTO - Also test HTTPS servers > (http://www.edgeos.com/nessuskb/details.php?option_id=135). This option was removed from nikto_wrapper.nes in September 2002 after an SSL bug was fixed in libwhisker / NIKTO; ie, http://cvsweb.nessus.org/cgi-bin/cvsweb.cgi/nessus-plugins/plugins/nikto _wrapper/nikto_wrapper.c.diff?r1=1.14&r2=1.15 [Btw, Jay, the URL for Nikto in this KB entry is wrong - "http://www.cirt/net/" should be "http://www.cirt.net/".] George -- [EMAIL PROTECTED] _______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
