Nessus
[Top] [All Lists]

Re: Thorough test of a Web server

To: Nessus@list.nessus.org
Subject: Re: Thorough test of a Web server
From: "George A. Theall" <theall@tenablesecurity.com>
Date: Fri, 19 Jan 2007 10:17:33 -0500
Cc:
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: Nessus@list.nessus.org
In-reply-to: <BF94750921492E4AA5B825026FCE6A24012A20C6@exnswn1-syd.nexus.csiro.au>
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
References: <011820071558.11585.45AF993A000E147C00002D4122007504389D0A9B0A03020E900006@comcast.net> <45AFB1CA.70105@tenablesecurity.com> <BF94750921492E4AA5B825026FCE6A24012A20C6@exnswn1-syd.nexus.csiro.au>
Sender: nessus-bounces@list.nessus.org
User-agent: Thunderbird 1.5.0.9 (X11/20061222)
On Fri, Jan 19, 2007 at 02:55:57PM +1100, Arkadi.Kosmynin@csiro.au wrote:

I am using Nessus 3.0.4 on Win XP. I can configure it scan the server,
but I don't think that it does what is expected. The web site has a few
thousand pages, but scan takes only 20-30 minutes (I disable port scans,
except port 80).

Can you point to specific things that Nessus that you feel Nessus has missed? Are these pages written using a scripting language such as PHP or ASP rather than just static pages? And if so, are they linked in from the initial page or in well-known directories?

> The
webmiror plugin is selected too, but I don't think that it does
anything.

Why? That plugin generally won't report anything; instead, it updates the KB with information found with entries such as:

  www/80/content/extensions/html

The question is, how do I enable thorough tests?

If you're using the Nessus 3 client for Windows itself, you do this by editing a new policy and selecting "Thorough tests" under the "General" settings tab.

I found a couple of books describing Nessus, but they talk about Nessus
2. The new Nessus 3 interface is intuitive, but not well documented.

Have you look at the white papers here:

  http://www.nessus.org/documentation/

Included are two user guides for Nessus 3.0.


George
--
theall@tenablesecurity.com
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>