Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Nessus: plugins

Plug-in - 25674 false positive?

 

 

Nessus plugins RSS feed   Index | Next | Previous | View Threaded


Lyal.Collins at vectra-corp

Jan 28, 2008, 5:50 PM

Post #1 of 2 (1531 views)
Permalink
Plug-in - 25674 false positive?

This plug-in responds with a false positive on server responds with
anything other than a 'not found' response.
The machine is definitely not running Asteridex and 'callback.php' does
not exist.

http services that responds with a '200' response and "not found"
message generated the false positive.
Unfortunately, I don't have actual response data from the recent test
where this came up.

Noted on http services on the following ports
can-ferret-ssl (3661/tcp)
can-ferret (1920/tcp)

Has anyone else seen this?

Reading the source, the response check may need to be enhanced.

Lyal Collins
Senior Security Consultant
Vectra Corporation Limited

320 Adelaide St
Brisbane QLD 4000
Phone: +61 7 3010 9716
Fax: +61 7 3010 9001
Mobile: 0419 836 003
www.vectra-corp.com

Leaders in Information Security & Infrastructure - Adelaide, Sydney,
Brisbane, Singapore

_______________________________________________
Plugins-writers mailing list
Plugins-writers [at] list
http://mail.nessus.org/mailman/listinfo/plugins-writers


theall at tenablesecurity

Jan 29, 2008, 3:54 AM

Post #2 of 2 (1457 views)
Permalink
Re: Plug-in - 25674 false positive? [In reply to]

On 01/28/08 20:50, Lyal Collins wrote:

> This plug-in responds with a false positive on server responds with
> anything other than a 'not found' response.

I've committed a change to look for some text generated by the actual
script, which should correct the false-positive. Look for revision 1.4
to become available in a couple of hours.

Thanks for reporting this.

George
--
theall [at] tenablesecurity
_______________________________________________
Plugins-writers mailing list
Plugins-writers [at] list
http://mail.nessus.org/mailman/listinfo/plugins-writers

Nessus plugins RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.