<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Nessus | plugins</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>13 Feb  2012 03:46:34 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Nessus | plugins</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Fixes to nmap.nasl</title>
<description>Hello! Here&amp;#039;s the fixes against nmap.nasl found on this link: http://www.nessus.org/documentation/nmap.nasl Here&amp;#039;s the link to the diff (it&amp;#039;s in att</description>
<pubDate>14 Mar  2009 04:59:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33747</link>
</item><item>
<title>Re: False positive in frontpage_chunked_overflow.nasl</title>
<description>On Mar 10, 2009, at 11:12 PM, nnposter@users.sourceforge.net wrote: &amp;gt; Plugin frontpage_chunked_overflow.nasl (version 1.18) reports a false &amp;gt; positiv</description>
<pubDate>13 Mar  2009 08:25:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33746</link>
</item><item>
<title>Re: Extending the generic web application	vulnerability checks</title>
<description>Hi Piet, &amp;gt; I have the following questions: &amp;gt; 2. What is the development roadmap for these kind of checks? There is no firm roadmap for more applic</description>
<pubDate>12 Mar  2009 02:41:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33745</link>
</item><item>
<title>False positive in frontpage_chunked_overflow.nasl</title>
<description>Plugin frontpage_chunked_overflow.nasl (version 1.18) reports a false positive if the IIS web server is configured not to return 404.  The following</description>
<pubDate>10 Mar  2009 20:12:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33744</link>
</item><item>
<title>Low severity and CVSS score in ssh1_proto_enabled.nasl</title>
<description>Plugin ssh1_proto_enabled.nasl (version 1.18) rates CVE-2001-0361 as Low with CVSS 2.6, which seems rather odd, especially considering that it shoul</description>
<pubDate>10 Mar  2009 20:12:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33743</link>
</item><item>
<title>Re: Extending the generic web application vulnerability checks</title>
<description>On Mon, 9 Mar 2009 14:47:59 +0000 Piet Haanstra &amp;lt;10109@live.com&amp;gt; wrote: &amp;gt; 1. Are there more generic web application vulnerability checks that &amp;gt; I mi</description>
<pubDate>10 Mar  2009 09:50:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33742</link>
</item><item>
<title>Extending the generic web application vulnerability checks</title>
<description>Hello all, I am currently investigating the possibilities of Nessus with regards to testing web applications on generic vulnerabilities. My goal is t</description>
<pubDate>09 Mar  2009 07:47:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33741</link>
</item><item>
<title>CanSecWest 2009 Speakers and Dojo courses (Mar 14-20)</title>
<description>Final Speaker Lineup for CanSecWest 2009 (March 18-20): =============================================== The Smart-Phones Nightmare - Sergio &amp;#039;shadown&amp;#039;</description>
<pubDate>15 Feb  2009 18:52:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33716</link>
</item><item>
<title>Re: setting to disable a plugin by default</title>
<description>Perhaps you are correct that it is more of a user training issue than  anything, or I should make a new family for inverse logic plugins, so  they d</description>
<pubDate>12 Feb  2009 07:43:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33711</link>
</item><item>
<title>Windows Compliance settings</title>
<description>Don&amp;#039;t know if this is the proper way to ask this but I&amp;#039;m in the process of trying to convince MGMT to utilize nessus Windows compliance .audit file</description>
<pubDate>12 Feb  2009 06:45:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33710</link>
</item><item>
<title>Re: setting to disable a plugin by default</title>
<description>Doug Nordwall wrote: &amp;gt; is there a setting for plugins to disable them by default? the nikto.nasl &amp;gt; has a nice checkbox.. any other way? I have one wit</description>
<pubDate>12 Feb  2009 06:33:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33709</link>
</item><item>
<title>openssh 50.nasl and paranoia</title>
<description>I have just run Nessus with the paranoid option against three systems. I believe all three are instances of Firewall-1 (ports 264/tcp and 500/udp open</description>
<pubDate>11 Feb  2009 09:48:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33706</link>
</item><item>
<title>setting to disable a plugin by default</title>
<description>is there a setting for plugins to disable them by default? the nikto.nasl has a nice checkbox.. any other way? I have one with reverse logic (errors i</description>
<pubDate>11 Feb  2009 08:22:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33705</link>
</item><item>
<title>Re: writing new plugin</title>
<description>On Jan 30, 2009, at 7:47 PM, George A. Theall wrote: &amp;gt; We recommend using script IDs in the range 60000 - 62000 for plugins  &amp;gt; you might write for i</description>
<pubDate>09 Feb  2009 11:54:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33698</link>
</item><item>
<title>Re: writing new plugin</title>
<description>On Jan 31, 2009, at 3:44 AM, Peter Van Eeckhoutte (corelan) wrote: &amp;gt; I am using checkbox, radio and entry fields in my plugin preferences &amp;gt; I would l</description>
<pubDate>03 Feb  2009 18:28:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33684</link>
</item><item>
<title>Re: Tenable patch superseded co relation</title>
<description>On Feb 3, 2009, at 6:35 AM, Renil Lambert wrote: &amp;gt; Hi guys, &amp;gt; &amp;gt; PFA. This contains the consolidated list of scans performed for a  &amp;gt; single subnet</description>
<pubDate>03 Feb  2009 05:14:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33682</link>
</item><item>
<title>Tenable patch superseded co relation</title>
<description>Hi guys,   PFA. This contains the consolidated list of scans performed for a single subnet last day. The items marked in RED have patch mismatch as</description>
<pubDate>02 Feb  2009 21:35:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33681</link>
</item><item>
<title>Re: nasl question : split and arrays</title>
<description>Great, thanks ! I have published my plugin on my blog... It basically is a wrapper/output parser for ike-scan, more info can be found at http://www.</description>
<pubDate>31 Jan  2009 17:13:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33678</link>
</item><item>
<title>Re: nasl question : split and arrays</title>
<description>On Sat, 31 Jan 2009 15:29:32 +0100 &amp;quot;Peter Van Eeckhoutte (corelan)&amp;quot; &amp;lt;peter.ve@corelan.be&amp;gt; wrote: &amp;gt; array1=split(mystring,&amp;quot; &amp;quot;); The separator is a na</description>
<pubDate>31 Jan  2009 07:30:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33677</link>
</item><item>
<title>nasl question : split and arrays</title>
<description>Hello, I have a string that looks like this mystring=&amp;quot;value1=1 value2=a value3=cd value4=jj&amp;quot;; I would like to be able to put this in individual arr</description>
<pubDate>31 Jan  2009 06:29:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33676</link>
</item><item>
<title>Re: writing new plugin</title>
<description>Thanks - it works now I have another question I am using checkbox, radio and entry fields in my plugin preferences I would like to be able to allow</description>
<pubDate>31 Jan  2009 00:44:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33675</link>
</item><item>
<title>Re: writing new plugin</title>
<description>On Jan 30, 2009, at 6:01 AM, Peter Van Eeckhoutte (corelan) wrote: &amp;gt; 1. When I run the plugin with nasl (at a command line), I get &amp;gt; &amp;quot;A non-authentic</description>
<pubDate>30 Jan  2009 16:47:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33674</link>
</item><item>
<title>Re: writing new plugin</title>
<description>The nessusd.conf option did the trick Thanks   ____________________________________________________ Peter Van Eeckhoutte peter.ve@telenet.be - pet</description>
<pubDate>30 Jan  2009 09:25:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33673</link>
</item><item>
<title>Re: writing new plugin</title>
<description>You can try the option nasl_no_signature_check option in nessud.conf And indeed non-signed plugins which use authenticated function won&amp;#039;t run by defau</description>
<pubDate>30 Jan  2009 07:10:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33671</link>
</item><item>
<title>writing new plugin</title>
<description>Hi all, I have started writing a new nessus plugin in nasl. 1. When I run the plugin with nasl (at a command line), I get &amp;quot;A non-authenticated scrip</description>
<pubDate>30 Jan  2009 03:01:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33670</link>
</item><item>
<title>Nessus plugin for detecting SNMP community string leaks</title>
<description>The attached plugin detects presence of SNMP community strings in SNMP MIBs. In this sense it eclipses the functionality of snmp_vacm.nasl while pro</description>
<pubDate>25 Jan  2009 11:06:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33652</link>
</item><item>
<title>From mailing lists to web forums</title>
<description>Hello everyone, For 10 years now, the Nessus user base has been supported with the use  of mailing lists as a medium to communicate with the communi</description>
<pubDate>12 Jan  2009 09:08:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33637</link>
</item><item>
<title>Re: up-to-date nasl reference manual?</title>
<description>&amp;gt; Do you mean it&amp;#039;s possible for the appropriate service to be enabled &amp;gt; but the AV to still be disabled? Yes, the service can be running but a user (</description>
<pubDate>08 Jan  2009 10:08:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33623</link>
</item><item>
<title>Re: Stop scan when can&amp;#039;t login</title>
<description>Renaud Deraison wrote: [snip] &amp;gt; If you set it in script_exclude_keys() or script_require_keys() then  &amp;gt; you do not need to check for it in the scrip</description>
<pubDate>07 Jan  2009 13:08:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33622</link>
</item><item>
<title>Re: up-to-date nasl reference manual?</title>
<description>On Jan 5, 2009, at 6:25 PM, David ROBERT wrote: &amp;gt; I tried to improve the plugin 21725 (Symantec Anti-Virus check) so it &amp;gt; will check that the anti-vi</description>
<pubDate>06 Jan  2009 17:37:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33614</link>
</item><item>
<title>Re: Stop scan when can&amp;#039;t login</title>
<description>On Jan 6, 2009, at 4:25 PM, Simon John wrote: &amp;gt;&amp;gt; &amp;gt;&amp;gt; With the first one, your scripts will only run if a given KB item is &amp;gt;&amp;gt; set, with the second one t</description>
<pubDate>06 Jan  2009 08:00:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33611</link>
</item><item>
<title>Re: Stop scan when can&amp;#039;t login</title>
<description>Renaud Deraison wrote: &amp;gt; On Jan 6, 2009, at 12:41 AM, Simon John wrote: [snip] &amp;gt;&amp;gt; Anyway, rather than having a security note for each plugin that fai</description>
<pubDate>06 Jan  2009 07:25:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33610</link>
</item><item>
<title>Re: Stop scan when can&amp;#039;t login</title>
<description>On Jan 6, 2009, at 12:41 AM, Simon John wrote: &amp;gt; I&amp;#039;ve written a few plugins that check if they can successfully login  &amp;gt; via &amp;gt; SSH - checks return v</description>
<pubDate>06 Jan  2009 06:17:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33609</link>
</item><item>
<title>Stop scan when can&amp;#039;t login</title>
<description>I&amp;#039;ve written a few plugins that check if they can successfully login via SSH - checks return value of ssh_open_connection(), empty username/password</description>
<pubDate>05 Jan  2009 15:41:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33608</link>
</item><item>
<title>up-to-date nasl reference manual?</title>
<description>Dear All, Is there an up-to-date reference manual for nasl ? I tried to improve the plugin 21725 (Symantec Anti-Virus check) so it will check that t</description>
<pubDate>05 Jan  2009 15:25:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33607</link>
</item><item>
<title>Re: Broken cipher list retrieval in plugins 26928, 31705</title>
<description>On Dec 31, 2008, at 11:35 AM, nnposter@users.sourceforge.net wrote: &amp;gt; Plugins ssl_anon_ciphers.nasl and ssl_weak_supported_ciphers.nasl &amp;gt; obtain the</description>
<pubDate>02 Jan  2009 07:11:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33598</link>
</item><item>
<title>Broken cipher list retrieval in plugins 26928, 31705</title>
<description>Plugins ssl_anon_ciphers.nasl and ssl_weak_supported_ciphers.nasl obtain the list of supported SSL ciphers via get_kb_list(). Both of these plugins</description>
<pubDate>31 Dec  2008 08:35:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33586</link>
</item><item>
<title>Re: su/sudo issues with SSH</title>
<description>Renaud Deraison wrote: &amp;gt; On Dec 28, 2008, at 9:36 PM, Simon John wrote: [snip] &amp;gt; Actually, all the Secret/* KB items are only available to signed  &amp;gt;</description>
<pubDate>29 Dec  2008 07:25:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33577</link>
</item><item>
<title>Re: su/sudo issues with SSH</title>
<description>On Dec 28, 2008, at 9:36 PM, Simon John wrote:  &amp;gt; Firstly the knowledgebase item &amp;quot;Secret/SSH/sudo-password&amp;quot; does not  &amp;gt; seem &amp;gt; to return to the scri</description>
<pubDate>29 Dec  2008 05:18:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33574</link>
</item><item>
<title>Re: plugin 11112</title>
<description>On Dec 24, 2008, at 7:18 PM, Cheryl Ammann wrote: &amp;gt; This generic ftp traversal test uses anonymous:nessus@&amp;lt;hostname&amp;gt;. I &amp;gt; found an ftp server this mo</description>
<pubDate>29 Dec  2008 01:23:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33573</link>
</item><item>
<title>su/sudo issues with SSH</title>
<description>Hi, First post, but I&amp;#039;ve been using Nessus, nasl&amp;#039;s and .audit files for a couple of years now. I&amp;#039;ve recently been writing a few plugins that requir</description>
<pubDate>28 Dec  2008 12:36:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33572</link>
</item><item>
<title>plugin 11112</title>
<description>This generic ftp traversal test uses anonymous:nessus@&amp;lt;hostname&amp;gt;. I found an ftp server this morning with a traversal vulnerability, but it doesn&amp;#039;t</description>
<pubDate>24 Dec  2008 10:18:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33569</link>
</item><item>
<title>Re: Some questions about running compliance checks on	linux servers</title>
<description>Hello Frank, Comments inline:  Frank_Kenisky@psc.uscourts.gov wrote: &amp;gt; &amp;gt; I&amp;#039;ve used Nessus &amp;quot;free&amp;quot; tool for almost 8 years now. I just recently &amp;gt; p</description>
<pubDate>16 Dec  2008 07:16:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33544</link>
</item><item>
<title>Some questions about running compliance checks on linux servers</title>
<description>I&amp;#039;ve used Nessus &amp;quot;free&amp;quot; tool for almost 8 years now. I just recently purchased the commercial version so I can utilize the .audit files. After runn</description>
<pubDate>15 Dec  2008 08:15:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33541</link>
</item><item>
<title>Re: phpMyAdmin_remote_cmd.nasl (script id 15748)</title>
<description>On Dec 4, 2008, at 9:51 AM, Simon Ward wrote: &amp;gt; According to the CVE-2004-2630[1] and the advisory from the  &amp;gt; phpMyAdmin team[2] only phpMyAdmin ve</description>
<pubDate>08 Dec  2008 12:47:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33507</link>
</item><item>
<title>Re: Bug in os_fingerprint_http.nasl</title>
<description>On Thursday 04 December 2008 17:45:27 nnposter@users.sourceforge.net wrote: &amp;gt; The following patch against version 1.54 resolves the issue: &amp;gt; There is</description>
<pubDate>05 Dec  2008 06:54:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33498</link>
</item><item>
<title>Bug in os_fingerprint_http.nasl</title>
<description>There is a minor bug in script os_fingerprint_http.nasl. The following patch against version 1.26 resolves the issue: --- os_fingerprint_http.nasl.or</description>
<pubDate>04 Dec  2008 08:45:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33497</link>
</item><item>
<title>Bug in hastymail_attachment_exec.nasl</title>
<description>There is a typo bug in script hastymail_attachment_exec.nasl. The following patch against version 1.5 resolves the issue: --- hastymail_attachment_ex</description>
<pubDate>04 Dec  2008 08:29:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33496</link>
</item><item>
<title>Broken 404 parsing in cross_site_scripting.nasl</title>
<description>Recently script cross_site_scripting.nasl got modified to request URLs via http_send_recv3(). The script attempts to retrieve mostly non-existent UR</description>
<pubDate>04 Dec  2008 08:17:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33495</link>
</item><item>
<title>phpMyAdmin_remote_cmd.nasl (script id 15748)</title>
<description>According to the CVE-2004-2630[1] and the advisory from the phpMyAdmin team[2] only phpMyAdmin versions 2.5.0 to 2.6.0-pl1 have the command executio</description>
<pubDate>04 Dec  2008 06:51:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33494</link>
</item><item>
<title>CanSecWest 2009 CFP (March 18-20 2009, Deadline December 8 2008)</title>
<description>Call For Papers     The CanSecWest 2009 CFP is now open.     Deadline is December 8th, 2008. CanSecWest CALL FOR PAPERS     VANCOUVER, Canada -- T</description>
<pubDate>24 Nov  2008 21:21:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33442</link>
</item><item>
<title>plugin for detecting shared printers</title>
<description>anyone have (or perhaps I just can&amp;#039;t find it) a plugin that detects that a printer is locally attached and is shared? -- Doug Nordwall Unix, Network</description>
<pubDate>10 Nov  2008 08:26:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33403</link>
</item><item>
<title>Re: 12253 Mailman &amp;lt; 2.1.5 Password Retrieval - false positives</title>
<description>On Nov 4, 2008, at 12:11 PM, Andrew Paterson wrote: &amp;gt; The latest version of GNU Mailman is currently 2.1.11, which is  &amp;gt; causing &amp;gt; this plugin (1225</description>
<pubDate>04 Nov  2008 09:34:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33353</link>
</item><item>
<title>12253 Mailman &amp;lt; 2.1.5 Password Retrieval - false positives</title>
<description>The latest version of GNU Mailman is currently 2.1.11, which is causing this plugin (12253 Mailman &amp;lt; 2.1.5 Password Retrieval) to false positive. I&amp;#039;v</description>
<pubDate>04 Nov  2008 09:11:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33352</link>
</item><item>
<title>Re: 34265 ProFTPD CSRF - CVSS score inconsistency</title>
<description>On Nov 4, 2008, at 6:28 AM, Andrew Paterson wrote: &amp;gt; We just noticed that the CVSS score given for 34265 ProFTPD Cross-Site &amp;gt; Request Forgery differs</description>
<pubDate>04 Nov  2008 09:02:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33351</link>
</item><item>
<title>Re: 34265 ProFTPD CSRF - CVSS score inconsistency</title>
<description>Andrew Paterson wrote: &amp;gt; We just noticed that the CVSS score given for 34265 ProFTPD Cross-Site &amp;gt; Request Forgery differs between the NVD and the Ness</description>
<pubDate>04 Nov  2008 04:01:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33350</link>
</item><item>
<title>34265 ProFTPD CSRF - CVSS score inconsistency</title>
<description>We just noticed that the CVSS score given for 34265 ProFTPD Cross-Site Request Forgery differs between the NVD and the Nessus plugin: &amp;gt;From the NVD:</description>
<pubDate>04 Nov  2008 03:28:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33349</link>
</item><item>
<title>Re: Sanity check please? False positive with Citrix XSS plugin (#12301)</title>
<description>On Thursday 30 October 2008 22:43:25 Andy Ellsworth wrote: &amp;gt; Unfortunately, this logic triggers a false positive when the web server &amp;gt; returns somethi</description>
<pubDate>31 Oct  2008 06:23:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33341</link>
</item><item>
<title>Sanity check please? False positive with Citrix XSS plugin (#12301)</title>
<description>I wanted to do a quick sanity check here before heading over to bugzilla. I have a host that&amp;#039;s being flagged by plugin 12301, which is looking for an</description>
<pubDate>30 Oct  2008 14:43:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33338</link>
</item><item>
<title>Re: 33561 - false positive on Mac OS X</title>
<description>On Oct 3, 2008, at 12:56 PM, Cheryl Ammann wrote: &amp;gt; Plugin 33561 does a straight version check of the Retrospect Client  &amp;gt; and &amp;gt; reports &amp;lt; 7.5.116.</description>
<pubDate>07 Oct  2008 07:59:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33230</link>
</item><item>
<title>33561 - false positive on Mac OS X</title>
<description>Plugin 33561 does a straight version check of the Retrospect Client and reports &amp;lt; 7.5.116. Unfortunately, the most recent version for Mac OS X is 6.</description>
<pubDate>03 Oct  2008 09:56:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33218</link>
</item><item>
<title>Re: How/where do i submit custom nasl&amp;#039;s</title>
<description>On Sep 24, 2008, at 6:36 PM, pradeep sm wrote: &amp;gt; i have written some customer nasl&amp;#039;s. i would share them with nessus  &amp;gt; community, can anyone tell m</description>
<pubDate>25 Sep  2008 16:06:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33156</link>
</item><item>
<title>How/where do i submit custom nasl&amp;#039;s</title>
<description>Hi everyone, i have written some customer nasl&amp;#039;s. i would share them with nessus community, can anyone tell me, how/where do i submit them please.</description>
<pubDate>24 Sep  2008 15:36:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33148</link>
</item><item>
<title>Re: get_backport_banner() false negative</title>
<description>This has been fixed, thanks.  On Sep 23, 2008, at 5:23 AM, nnposter@users.sourceforge.net wrote: &amp;gt; In several cases I have seen a &amp;quot;vanilla&amp;quot; Apache H</description>
<pubDate>24 Sep  2008 02:24:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33143</link>
</item><item>
<title>get_backport_banner() false negative</title>
<description>In several cases I have seen a &amp;quot;vanilla&amp;quot; Apache HTTPD instance getting mis-classified by get_backport_banner() from backport.inc. This leads to the in</description>
<pubDate>22 Sep  2008 20:23:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33139</link>
</item><item>
<title>Re: Cisco &amp;quot;webvpn&amp;quot; being misclassified as printer</title>
<description>On Sep 17, 2008, at 7:15 PM, Jason Haar wrote: &amp;gt; I&amp;#039;ve noticed that our Cisco ASA and VPN3000 concentrators are being &amp;gt; classified as HP printers (rul</description>
<pubDate>17 Sep  2008 18:24:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33116</link>
</item><item>
<title>Cisco &amp;quot;webvpn&amp;quot; being misclassified as printer</title>
<description>Hi there I&amp;#039;ve noticed that our Cisco ASA and VPN3000 concentrators are being classified as HP printers (rule 11936) by Nessus-3.2.1-es4. They are b</description>
<pubDate>17 Sep  2008 16:15:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33115</link>
</item><item>
<title>Re: Sorting By Authentication</title>
<description>Hi Frank, In Nessus, you want to select the &amp;quot;Credentials&amp;quot; tab and then &amp;quot;SSH settings&amp;quot; from the drop down. There you can enter your credentials and ch</description>
<pubDate>17 Sep  2008 06:13:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33110</link>
</item><item>
<title>A few questions about using nessus</title>
<description>I&amp;#039;ve been using nessus (free) for a few years now. Recently, we purchased the commercial version which has a lot of the .audit files included. I&amp;#039;m</description>
<pubDate>16 Sep  2008 13:50:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33106</link>
</item><item>
<title>Fw: Plugin 20811 Windows Software Enum via SMB doesn&amp;#039;t support x64</title>
<description>Is there plans to support enumeration of registry fro 64 bit machines using plugin 20811?  I think it needs to inspect HKLM\SOFTWARE\Wow6432Node \M</description>
<pubDate>16 Sep  2008 10:17:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33104</link>
</item><item>
<title>Re: Sorting By Authentication</title>
<description>this is a test as I&amp;#039;ve never responded to this list. I have a question regarding authentication using a nessus .audit file. I&amp;#039;m testing the commeric</description>
<pubDate>16 Sep  2008 07:30:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33105</link>
</item><item>
<title>Re: Unpredictable behavior of uninitialized named arguments</title>
<description>&amp;quot;Nicolas Pouvesle&amp;quot; wrote: &amp;gt; On Sep 15, 2008, at 6:10 AM, nnposter@users.sourceforge.net wrote: &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt; IIRC, I added some code which printed a warnin</description>
<pubDate>16 Sep  2008 06:41:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33107</link>
</item><item>
<title>Re: Unpredictable behavior of uninitialized named arguments</title>
<description>On Sep 15, 2008, at 6:10 AM, nnposter@users.sourceforge.net wrote: &amp;gt; &amp;gt;&amp;gt; IIRC, I added some code which printed a warning if a variable was  &amp;gt;&amp;gt; found &amp;gt;</description>
<pubDate>15 Sep  2008 06:13:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33100</link>
</item><item>
<title>Re: Unpredictable behavior of uninitialized named arguments</title>
<description>&amp;quot;Michel Arboi&amp;quot; wrote: &amp;gt; On Sat, 13 Sep 2008 15:15:27 -0400 &amp;gt; nnposter@users.sourceforge.net wrote: &amp;gt; &amp;gt; &amp;gt; I understand that the development is focusin</description>
<pubDate>14 Sep  2008 21:10:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33099</link>
</item><item>
<title>Re: Unpredictable behavior of uninitialized named arguments</title>
<description>On Sat, 13 Sep 2008 15:15:27 -0400 nnposter@users.sourceforge.net wrote: &amp;gt; I understand that the development is focusing on 3.x but are there &amp;gt; any c</description>
<pubDate>14 Sep  2008 07:16:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33098</link>
</item><item>
<title>Re: Unpredictable behavior of uninitialized named arguments</title>
<description>&amp;quot;Michel Arboi&amp;quot; wrote: &amp;gt; On Sunday 31 August 2008 21:15:27 nnposter@users.sourceforge.net wrote: &amp;gt; &amp;gt; Named function arguments exhibit a questionable be</description>
<pubDate>13 Sep  2008 12:15:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33095</link>
</item><item>
<title>Re: Sorting By Authentication</title>
<description>On Thu, 11 Sep 2008 22:19:57 -0400 &amp;lt;Jeremy.Grainger@bcbssc.com&amp;gt; wrote: &amp;gt; An auditor usually will scan unauthenticated Odd. For me, audit = whitebox</description>
<pubDate>12 Sep  2008 15:11:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33096</link>
</item><item>
<title>Sorting By Authentication</title>
<description>In my organization we are audited several times a year and I would like to have a *non standard* view into my Nessus vulnerabilities. As opposed to ra</description>
<pubDate>11 Sep  2008 19:19:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33094</link>
</item><item>
<title>Re: SMB LogonTime Question</title>
<description>On Sep 5, 2008, at 6:27 AM, Herman Young wrote: &amp;gt; Please advise on how to convert the value of the KB Item &amp;quot;SMB/ &amp;gt; LocalUsers/1/Info/LogonTime=0x01-</description>
<pubDate>08 Sep  2008 18:43:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33072</link>
</item><item>
<title>SMB LogonTime Question</title>
<description>Good day, Please advise on how to convert the value of the KB Item &amp;quot;SMB/LocalUsers/1/Info/LogonTime=0x01-0xc1-0x3b-0xa4-0x4c-0x0d-0x17-0x6a&amp;quot; to a dat</description>
<pubDate>05 Sep  2008 03:27:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33070</link>
</item><item>
<title>Re: Unpredictable behavior of uninitialized named arguments</title>
<description>On Sunday 31 August 2008 21:15:27 nnposter@users.sourceforge.net wrote: &amp;gt; Named function arguments exhibit a questionable behavior in that when not &amp;gt;</description>
<pubDate>02 Sep  2008 04:59:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33012</link>
</item><item>
<title>Unpredictable behavior of uninitialized named arguments</title>
<description>Named function arguments exhibit a questionable behavior in that when not specified in the call they behave as if they were undeclared variables, i.e.</description>
<pubDate>31 Aug  2008 12:15:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/33011</link>
</item><item>
<title>PacSec 2008 CFP   (Deadline Sept. 1, Conference Nov. 12/13) and BA-Con 2008 Speakers (Sept. 30/  Oct. 1)</title>
<description>Spanish url: http://ba-con.com.ar/speakers.html?language=es Speaker list and Dojos for BA-Con, September 30, October 1st. (all presentations in both</description>
<pubDate>26 Aug  2008 13:02:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32987</link>
</item><item>
<title>Re: Custom Plugin</title>
<description>A new version of the original plugin has been signed and pushed to the web site. See http://www.nessus.org/documentation/nmap.nasl It is simpler (the</description>
<pubDate>18 Aug  2008 06:55:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32942</link>
</item><item>
<title>Re: Custom Plugin</title>
<description>Thanks for the changes.  I had already written my own plugin to perform an import on grepable nmap results, it works in the same way as &amp;quot;nmap.nasl&amp;quot;</description>
<pubDate>18 Aug  2008 04:37:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32941</link>
</item><item>
<title>Re: Custom Plugin</title>
<description>On Thu, 14 Aug 2008 16:41:25 +0100 Mark Woan &amp;lt;markwoan@hotmail.com&amp;gt; wrote: &amp;gt; I was trying to use the &amp;quot;nmap.nasl&amp;quot; plugin under Windows XP (using &amp;gt; ver</description>
<pubDate>15 Aug  2008 07:47:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32933</link>
</item><item>
<title>Re: Custom Plugin</title>
<description>Figured it out...Ran build.exe in the Nessus directory.   From: markwoan@hotmail.comTo: plugins-writers@list.nessus.orgDate: Thu, 14 Aug 2008 16:41</description>
<pubDate>15 Aug  2008 07:18:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32932</link>
</item><item>
<title>Custom Plugin</title>
<description>I was trying to use the &amp;quot;nmap.nasl&amp;quot; plugin under Windows XP (using version 3.2.1.1 of Nessus), but apparently it doesn&amp;#039;t work under Windows, since it</description>
<pubDate>14 Aug  2008 08:41:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32930</link>
</item><item>
<title>Plugin to detect Microsoft Siteserver XSS</title>
<description>Attached is a plugin that detects a cross-site scripting flaw in Microsoft Site Server 3.0 (CVE-2002-2073). This is quite an old vulnerability, howe</description>
<pubDate>05 Aug  2008 09:37:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32887</link>
</item><item>
<title>Plugin to detect arbitrary redirection.</title>
<description>Attached is a plugin that detects a specific case of arbitrary redirection. It should fire on web servers whom return the path requested in the &amp;#039;Loc</description>
<pubDate>05 Aug  2008 09:29:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32886</link>
</item><item>
<title>Test for dwsync.xml files.</title>
<description>Attached is a plugin to detect dwsync.xml files. These are sometimes generated by Dreamweaver and may disclose the presence of files or directories</description>
<pubDate>05 Aug  2008 09:14:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32888</link>
</item><item>
<title>Re: How to debug the plugin</title>
<description>On Aug 5, 2008, at 12:15 AM, Fred Qiu wrote: &amp;gt; I have another question. What is the state of the GPLed plugins, i.e. &amp;gt; those from nessus-plugins-GPL-</description>
<pubDate>05 Aug  2008 07:34:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32884</link>
</item><item>
<title>Test for .svn/entries</title>
<description>Here&amp;#039;s a plugin to locate websites managed by svn that leak their entries file analogous to the one for CVS/Entries files. It does a little processing</description>
<pubDate>05 Aug  2008 04:07:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32882</link>
</item><item>
<title>Re: How to debug the plugin</title>
<description>Thank you, George. Your answer is very clear. I have another question. What is the state of the GPLed plugins, i.e. those from nessus-plugins-GPL-2.2</description>
<pubDate>04 Aug  2008 21:15:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32883</link>
</item><item>
<title>Re: How to debug the plugin</title>
<description>On Aug 2, 2008, at 12:26 PM, Fred Qiu wrote: &amp;gt; Generally how do you guys debug a plugin? The &amp;#039;nasl&amp;#039; command seems not &amp;gt; always helpful if a plugin de</description>
<pubDate>04 Aug  2008 16:38:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32880</link>
</item><item>
<title>How to debug the plugin</title>
<description>Generally how do you guys debug a plugin? The &amp;#039;nasl&amp;#039; command seems not always helpful if a plugin depends on others such as find_service. P.S. What i</description>
<pubDate>02 Aug  2008 09:26:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32871</link>
</item><item>
<title>Re: this_host() returns 127.0.0.1?</title>
<description>I think the reason you got no more answers is because you were told to upgrade to a newer version of nessus. I currently run 2.2.10 and have no issues</description>
<pubDate>13 Jul  2008 09:33:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32748</link>
</item><item>
<title>Re: this_host() returns 127.0.0.1?</title>
<description>On Fri, Jul 11, 2008 at 2:35 AM, Renaud Deraison &amp;lt;deraison@nessus.org&amp;gt; wrote: &amp;gt; &amp;gt; &amp;gt; Hello Nathan, &amp;gt; &amp;gt; On Jul 9, 2008, at 9:12 PM, Nathan wrote: &amp;gt; &amp;gt;&amp;gt; I</description>
<pubDate>11 Jul  2008 09:45:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32741</link>
</item><item>
<title>Re: this_host() returns 127.0.0.1?</title>
<description>Hello Nathan, On Jul 9, 2008, at 9:12 PM, Nathan wrote: &amp;gt; I&amp;#039;ve manually compared the configuration of the 2.6.23 kernel (where &amp;gt; nessus works) and t</description>
<pubDate>11 Jul  2008 01:35:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32737</link>
</item><item>
<title>Re: this_host() returns 127.0.0.1?</title>
<description>On Tue, Jul 8, 2008 at 5:46 PM, Nathan &amp;lt;nathan.stocks@gmail.com&amp;gt; wrote: &amp;gt; I found it! Or at least I found something. I rebooted off of an &amp;gt; earlier</description>
<pubDate>09 Jul  2008 12:12:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/nessus/plugins/32728</link>
</item>
</channel>
</rss>

