Nessus
[Top] [All Lists]

Re: Targeting Vista

To: Nessus List <Nessus@list.nessus.org>
Subject: Re: Targeting Vista
From: Renaud Deraison <deraison@nessus.org>
Date: Wed, 24 Jan 2007 16:23:12 +0100
Cc:
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: nessus@list.nessus.org
In-reply-to: <99C044C317E0424D9E050A4C8634E63D010FB2F7@G3W0068.americas.hpqcorp.net>
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
References: <99C044C317E0424D9E050A4C8634E63D010FB2F7@G3W0068.americas.hpqcorp.net>
Sender: nessus-bounces@list.nessus.org


Hi Drew,

On Jan 18, 2007, at 11:51 AM, Flickema, Drew W. wrote:



If Nessus is sourcing from a forested Vista install, then it should be
able to communicate and perform it's authenticated assessment when
targeting other clients in the forest. If Nessus is sourcing from a non
forested client or installed on a non-windows platform, then
authenticated checks will always fail since Nessus does not talk IPSec.


Will there be any effort to develop Nessus communications so that it too will attempt to negotiate IPSec or fail back to clear channel? If this
moves forward, what is the perceived impact to scan times when
considering a global enterprise consisting of multiple Oses?

The question you're asking is not really Nessus related, although it does affect it -- it will depend on the configuration of the underlying IPSsec API (ok, in terms of packet forgery Nessus will also be affected a bit and we'll have to fix this).

We're going to test this setup and determine what can be done to help the user configure his IP stack so that IPSec is used whenever possible.


                                -- Renaud
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>
  • Targeting Vista, Flickema, Drew W.
    • Re: Targeting Vista, Renaud Deraison <=