thanks for explanation - I'm using Nessus for little bit longer time :-)
than a year, but I realize that my memory is worser :-) But at least my
confusion could help to clear a little this handy KB from edgeos :-)

kamil

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of George Theall
Sent: Wednesday, April 21, 2004 4:26 AM
To: [EMAIL PROTECTED]
Cc: [EMAIL PROTECTED]
Subject: Re: FTP bounce and also test HTTPS

On Tue, Apr 20, 2004 at 12:38:30PM +0200, Golombek Kamil    |   BDO IT
a.s. wrote:

> after I looked at edgeos Nessus KB, I noticed two options I've never 
> seen in my Nessus GUI.

You've never seen them presumably because you started using Nessus only
within the past year or so -- both options were removed from Nessus
before then.  Edgeos' knowledge base should probably be updated to
reflect that. 

> The first one was FTP bounce scan
> (http://www.edgeos.com/nessuskb/details.php?option_id=222)

The plugin ftp_bounce_scan.nes was removed from Nessus in February 2003,
purportedly because it was crash-prone and useless; ie,

 
http://cvsweb.nessus.org/cgi-bin/cvsweb.cgi/nessus-plugins/plugins/ftp_b
ounce_scan/Attic/ftp_bounce_scan.c

> The second was option of NIKTO - Also test HTTPS servers 
> (http://www.edgeos.com/nessuskb/details.php?option_id=135).

This option was removed from nikto_wrapper.nes in September 2002 after
an SSL bug was fixed in libwhisker / NIKTO; ie,

 
http://cvsweb.nessus.org/cgi-bin/cvsweb.cgi/nessus-plugins/plugins/nikto
_wrapper/nikto_wrapper.c.diff?r1=1.14&r2=1.15

[Btw, Jay, the URL for Nikto in this KB entry is wrong -
"http://www.cirt/net/"; should be "http://www.cirt.net/";.]


George
--
[EMAIL PROTECTED]

_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to