Re: How does nessus know exactly which application is running
On Thu, Feb 19, 2004 at 03:28:59AM -0800, alan donald wrote:
> I am a bit confused. I dont seem to understand how
> nessus is knowing which application is running.
> Since
> it has to know this information in order to launch
> an
> exploit.
>
> Is it just matching a banner
> OR
> does it have a database of responses for each
> application like maybe nmap does.
> OR
> It is fingerprinting the application in some other
> way.
It recognizes the application based on the banner and/or error message
replied to the request it sent. find_services.nes has been doing that
for a couple of years now.
-- Renaud
This archive was generated by a fusion of
Pipermail 0.09 (Mailman edition) and
MHonArc 2.6.8.