When using a port scan I would recommend to just use both TCP connect and Nessus.
I limit the Nessus port scan just to SYN scan. Do not use RPC at all. I was able to crash Veritas and autosys services with it.
The only service that I know will still crash is Sybase replication on older versions of Sybase.
Regards
Rolando Azpurua
Kh�rt_Williams <[EMAIL PROTECTED]> wrote:
Kh�rt_Williams <[EMAIL PROTECTED]> wrote:
Just disable the RPC scanning piece in your .nessusrc file.
[EMAIL PROTECTED] wrote:
>Thanks so much! I enabled NMAP some time ago but I'll disable it again
>when running on production.
>
>Thanks,
>
>Magda Hewryk
>--------------------------------
>
>
>
>
> Khurt Williams
> <[EMAIL PROTECTED]
> zon.net> cc: [EMAIL PROTECTED]
> Sent by: Subject: Re: Nessus crashed TSM processes - Non-DOS plugins were enabled.
> [EMAIL PROTECTED]
> .nessus.org
>
>
> 04/22/04 02:15 PM
>
>
>
>
>
>
>I have similar problems with applications crashing after a nessus scan
>("safe_mode"). After some investigation I determined that NMAP rpc
>scans were at fault not nessus. You may want to test using NMAP only
>againt the same host and service.
>
>[EMAIL PROTECTED] wrote:
>
>
>
>>Hi,
>>Is it possible that Nessus can crash some processes. It looks like it
>>crashed TSM web clients on all our prod servers. I always enable Non-Dos
>>plugins when scanning production site.
>>
>>
>>4/17/2004 16:22:31 isFileNameValid: Invalid file name
>>cgi-bin/NessusTest869843619.inc - file type not allowed.
>>04/17/2004 16:22:31 isFileNameValid: Invalid file name
>>cgi-bin/NessusTest869843619.shtml - file type not allowed.
>>04/17/2004 16:22:31 isFileNameValid: Invalid file name
>>cgi-bin/NessusTest869843619.php - file type not allowed.
>>04/17/2004 16:22:31 isFileNameValid: Invalid file name
>>cgi-bin/NessusTest869843619.php3 - file type not allowed.
>>04/17/2004 16:22:31 isFileNameValid: Invalid file name
>>cgi-bin/NessusTest869843619.cfm - file type not allowed.
>>04/17/2004 16:22:31 isFileNameValid: Invalid file name CVS/Entries - file
>>type required.
>>
>>
>>Thanks,
>>
>>Magda Hewryk
>>
>>
>>
>>_______________________________________________
>>Nessus mailing list
>>[EMAIL PROTECTED]
>>http://mail.nessus.org/mailman/listinfo/nessus
>>
>>
>>
>>
>(See attached file: khurtwilliams.vcf)
>_______________________________________________
>Nessus mailing list
>[EMAIL PROTECTED]
>http://mail.nessus.org/mailman/listinfo/nessus
>
>
>
>
>
_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus
_______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
