Re: Virtual Domain Scanning Bug



On Jun 6, 2005, at 8:07 PM, davenessus_at_davewking.com wrote:

I think I may have figured this out. As far as I can tell with my limited testing, instead of ip[domain] it should be domain[ip], for example try www.foo.com[10.0.0.2]. It looks like this is backwards in several places including the Nessus Knowledge base and several emails on the mailing list. I actually found this answer in this email http://mail.nessus.org/pipermail/nessus/2002-October/ msg00227.html. Let the list know if this works.

Thanks for the reply, Dave. I'm afraid that doesn't work either. Assuming www.foo.com resolves to 10.0.0.1, then nessus will scan that IP and not 10.0.0.2. We found an old list msg that seems to suggest this is how it was designed to work:


http://mail.nessus.org/mailman/htdig/nessus-devel/2004-September/ msg00028.html

I don't understand why it was designed this way, though.

Best regards,
Erik




This archive was generated by a fusion of Pipermail 0.09 (Mailman edition) and MHonArc 2.6.8.