Nessus
[Top] [All Lists]

Re: NESSUS CRASHING CITRIX METAFRAME SERVERS

To: nessus@list.nessus.org
Subject: Re: NESSUS CRASHING CITRIX METAFRAME SERVERS
From: "Dan Harkless" <nessus.list07@harkless.org>
Date: Wed, 07 Mar 2007 20:05:48 -0800
Cc: JScherff_at_24hourfit.com@www.harkless.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: nessus@list.nessus.org
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
Sender: nessus-bounces@list.nessus.org
[Posted to nessus list and CC'd to John in case he's not still a
subscriber.]

In December 2006, John Scherff wrote:
> > Starting last month, Nessus began crashing our Citrix Metaframe farm 
> > (approximately 60 servers).
[...]
> But I think Renaud is going to end up being correct (as usual) about the
> cause. After some investigation, I found that 'thorough tests' was
> turned on the month before the problems started occurring.

Hi, John.  I didn't see a followup to the list confirming whether "Thorough
tests" was the culprit in your Citrix server crashes.  We're currently using
Nessus to scan some hosts at my company and I was considering turning on
"Thorough" because for several of the https servers we get:

    The remote web server is very slow - it took 90 seconds to execute the
    plugin no404.nasl (it usually only takes a few seconds).

    In order to keep the scan total time to a reasonable amount, the remote
    web server has not been tested.

    If you want to test the remote server, either fix it to have it reply to
    Nessus's requests in a reasonable amount of time, or set the global
    option 'Thorough tests' to 'yes'
    Nessus ID : 10386

but since some of them are running Citrix, I'm wary of turning on "Thorough"
if it's likely to DoS the servers.

-- 
Dan Harkless
http://harkless.org/dan/
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>