On Thu, 19 Aug 2004, Marc Haber wrote:
> On Wed, Aug 18, 2004 at 04:55:05PM -0400, George Theall wrote:
> > On Wed, Aug 18, 2004 at 03:31:27PM -0500, Perrymon, Josh L. wrote:
> > > It's really easy on my Linux box- Apt-get install nessus-plugins.
> >
> > Does this really update the plugins or simply retrieve the current
> > distribution package?
>
> It retrieves the current distribution package which can be quite
> current in case of Debian sid. In Debian stable, of course, the
> plugins are horribly outdated which is a constant source of problems.
>
> The rationale behind using the Debian packages of the plugins is that
> there are two more eyes looking over the plugins, thus enhancing the
> chance of detecting a trojan plugin which might have adverse effects
> on the scanned network. The disadvantage of course is that one is
> always a few weeks behind.
And being weeks behind on this battlefield is not a option if you want to
keep ahead of things.
Hugo.
--
All email sent to me is bound to the rules described on my homepage.
[EMAIL PROTECTED] http://hvdkooij.xs4all.nl/
Don't meddle in the affairs of sysadmins,
for they are subtle and quick to anger.
_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus