From c_edjenguele at yahoo.it Wed Oct 1 12:59:32 2008 From: c_edjenguele at yahoo.it (Christian Eric EDJENGUELE) Date: Wed, 1 Oct 2008 10:59:32 +0000 (GMT) Subject: [Openvas-discuss] openvas appliance Message-ID: <505166.75549.qm@web26005.mail.ukl.yahoo.com> Hi Patrick, can you?make a Qemu version of this appliance ? the scope is to provide a portable version of openvas, running directly on windows without any system modifications,? I tried this: $ cd /openvas_1.0/openvas $ for i in `ls *[0-9].vmdk`; do qemu-img convert -f vmdk $i -O raw?$i.raw ; done $ cat *.raw >> openvas.img To run it, $ qemu -m 256 -hda openvas.img but it doesn't work anymore, I have a blank screen. thanks.?--- Christian Eric Edjenguele IT Security Software Developer & Researcher tel. +39 3408580513 Scopri il blog di Yahoo! Mail: Trucchi, novit? e la tua opinione. http://www.ymailblogit.com/blog From michael.wiegand at intevation.de Wed Oct 8 12:53:18 2008 From: michael.wiegand at intevation.de (Michael Wiegand) Date: Wed, 8 Oct 2008 12:53:18 +0200 Subject: [Openvas-discuss] Voting on Change Request #16 Message-ID: <200810081253.18754.michael.wiegand@intevation.de> Hello, I have prepared a change request which should solve the issue with new NVTs becoming automatically enabled in OpenVAS-Client in cases where this type of behavior is not desirable. Please take a look at http://www.openvas.org/openvas-cr-16.html and let me know what you think and whether you agree with this request or not. The change will only happen in the client and should be pretty straightforward. Regards, Michael -- Michael Wiegand | OpenPGP key: D7D049EC | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabr?ck | AG Osnabr?ck, HR B 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner From timb at nth-dimension.org.uk Mon Oct 13 19:49:04 2008 From: timb at nth-dimension.org.uk (Tim Brown) Date: Mon, 13 Oct 2008 18:49:04 +0100 Subject: [Openvas-discuss] Fwd: Re: OpenVas plugin development (was Up to date statement of Account) Message-ID: <200810131849.04760.timb@nth-dimension.org.uk> ---------- Forwarded Message ---------- Subject: Re: OpenVas plugin development (was Up to date statement of Account) Date: Monday 13 October 2008 From: Michael Schultheiss To: spi-general at lists.spi-inc.org Tim Brown wrote: > On Friday 26 September 2008 19:39:46 Michael Schultheiss wrote: > > Michael Schultheiss wrote: > > > I apologize for the lack of official communication. I was unable to > > > find my initial request to the legal and financial advisors in my sent > > > mail so I redrafted the request and added a request for an ETA of a > > > response if they must do further research. I'll get back to you as soon > > > as I hear back from the advisors. > > > > The CPA said he would look into this and get back to me on Monday, > > September 29, 2008. > > Michael, > > Any update on this? I finally heard back from the CPA. He said there should be no problem for SPI to hold the funds for this competition. -- ---------------------------- Michael Schultheiss E-mail: schultmc at spi-inc.org ------------------------------------------------------- -- Tim Brown From jan-oliver.wagner at intevation.de Tue Oct 14 09:03:40 2008 From: jan-oliver.wagner at intevation.de (Jan-Oliver Wagner) Date: Tue, 14 Oct 2008 09:03:40 +0200 Subject: [Openvas-discuss] Fwd: Re: OpenVas plugin development (was Up to date statement of Account) In-Reply-To: <200810131849.04760.timb@nth-dimension.org.uk> References: <200810131849.04760.timb@nth-dimension.org.uk> Message-ID: <200810140903.42785.jan-oliver.wagner@intevation.de> Tim, thanks for clearifying this. Now we only need bank details for international transfer. Best Jan On Montag, 13. Oktober 2008, Tim Brown wrote: > > ---------- Forwarded Message ---------- > > Subject: Re: OpenVas plugin development (was Up to date statement of Account) > Date: Monday 13 October 2008 > From: Michael Schultheiss > To: spi-general at lists.spi-inc.org > > Tim Brown wrote: > > On Friday 26 September 2008 19:39:46 Michael Schultheiss wrote: > > > Michael Schultheiss wrote: > > > > I apologize for the lack of official communication. I was unable to > > > > find my initial request to the legal and financial advisors in my sent > > > > mail so I redrafted the request and added a request for an ETA of a > > > > response if they must do further research. I'll get back to you as soon > > > > as I hear back from the advisors. > > > > > > The CPA said he would look into this and get back to me on Monday, > > > September 29, 2008. > > > > Michael, > > > > Any update on this? > > I finally heard back from the CPA. He said there should be no problem > for SPI to hold the funds for this competition. > > -- > ---------------------------- > Michael Schultheiss > E-mail: schultmc at spi-inc.org > > ------------------------------------------------------- > -- Dr. Jan-Oliver Wagner Intevation GmbH, Osnabr?ck Amtsgericht Osnabr?ck, HR B 18998 http://www.intevation.de/ Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner From jcf at ubiqube.com Fri Oct 17 10:25:19 2008 From: jcf at ubiqube.com (Jean-Christophe FORTON) Date: Fri, 17 Oct 2008 10:25:19 +0200 Subject: [Openvas-discuss] XML problems in OpenVAS-Server 2.0.0 version Message-ID: <8D6BC20888573C4D8163394E3E149FD46BDED4@TUVALU.ubiqube.com> Hello all, I'm in charge of the deployment of OpenVAS and I wanted to use the XML format to insert, via parsers, in an SQL database. This leads to my two questions: 1. The XML reports in version 2.0 of the OpenVAS server is apparently bugged : [root at localhost ~]#OpenVAS-Client -T xml -x -q 127.0.0.1 1241 jcf ubiqube /opt/target /var/www/html/scan/localhost.xml 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type 'severity' - bad query type This error leads to a quite empty report... ; -( 2. If I start making parser with version 1.0.2 of OpenVAS server, will the XML generated will be the same or will I have to modify my parsers? Best regards and thanks for the good work! Jean-Christophe Forton UBIqube Solutions Smart Security Services 18-20 rue Henri Barbusse B.P.2501 38035 Grenoble, Cedex 2, France ph: +33 438498370 www.ubiqube.com -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.wald.intevation.org/pipermail/openvas-discuss/attachments/20081017/ebb6db9c/attachment.htm From michael.wiegand at intevation.de Fri Oct 17 11:29:49 2008 From: michael.wiegand at intevation.de (Michael Wiegand) Date: Fri, 17 Oct 2008 11:29:49 +0200 Subject: [Openvas-discuss] XML problems in OpenVAS-Server 2.0.0 version In-Reply-To: <8D6BC20888573C4D8163394E3E149FD46BDED4@TUVALU.ubiqube.com> References: <8D6BC20888573C4D8163394E3E149FD46BDED4@TUVALU.ubiqube.com> Message-ID: <200810171129.49925.michael.wiegand@intevation.de> [Friday 17 October 2008 - 10:25:19] "Jean-Christophe FORTON" : > 1. The XML reports in version 2.0 of the OpenVAS server is > apparently bugged : > > > [root at localhost ~]#OpenVAS-Client -T xml -x -q 127.0.0.1 1241 jcf > ubiqube /opt/target /var/www/html/scan/localhost.xml > 'severity' - bad query type > 'severity' - bad query type > > This error leads to a quite empty report... ; -( Thank you for your feedback und for helping us testing the beta release. I have a pretty good idea as to what might cause this, I'll look into it. > 2. If I start making parser with version 1.0.2 of OpenVAS server, > will the XML generated will be the same or will I have to modify my > parsers? There are a few changes in 2.0, most notable the switch to the OID-based scheme for the NVT-IDs and the availability of NVT signature IDs in the client. The XML will stay roughly the same, but you will have to make sure your parser can handle OIDs and you might want to update parser if you want to use the signature IDs. Regards, Michael -- Michael Wiegand | OpenPGP key: D7D049EC | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabr?ck | AG Osnabr?ck, HR B 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner From michael.wiegand at intevation.de Fri Oct 17 14:37:21 2008 From: michael.wiegand at intevation.de (Michael Wiegand) Date: Fri, 17 Oct 2008 14:37:21 +0200 Subject: [Openvas-discuss] XML problems in OpenVAS-Server 2.0.0 version In-Reply-To: <8D6BC20888573C4D8163394E3E149FD46BDED4@TUVALU.ubiqube.com> References: <8D6BC20888573C4D8163394E3E149FD46BDED4@TUVALU.ubiqube.com> Message-ID: <200810171437.21878.michael.wiegand@intevation.de> [Friday 17 October 2008 - 10:25:19] "Jean-Christophe FORTON" : > 1. The XML reports in version 2.0 of the OpenVAS server is > apparently bugged : > > (..) > > This error leads to a quite empty report... ; -( The error has now been fixed in the SVN repository, the bugfix will be included in the upcoming -beta2 relase of OpenVAS-Client. Thank you again for submitting this bug! Regards, Michael -- Michael Wiegand | OpenPGP key: D7D049EC | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabr?ck | AG Osnabr?ck, HR B 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner From alimoreno at linktechnologies.com.ve Wed Oct 15 05:41:43 2008 From: alimoreno at linktechnologies.com.ve (Ali Moreno) Date: Tue, 14 Oct 2008 23:11:43 -0430 Subject: [Openvas-discuss] Problem in Debian Message-ID: <1224042103.4443.16.camel@localhost> Hi everybody, first excuse my bad english. I have a Debian 4.0 (etch) installled in my laptop and add this line to my /etc/apt/sources.list deb http://apt.intevation.de/ etch openvas then i install OpenVAS like in http://www.openvas.org/openvas-server.html # apt-get update # apt-get install libopenvas1 # apt-get install libopenvas1-dev the client # apt-get install openvas-client but i cant find the openvas-adduser command, the only openvas-commands that are in my systems are openvas-client and openvasclient-mkcert. Then i cant connect my client to my server :S Any help? -- Ali R. Moreno Ter?n Director de Proyectos Link Technologies - http://www.linktechnologies.com.ve M?vil: +58-414-144-24-44 Email: alimoreno at linktechnologies.com.ve Messenger: ali.mt at cantv.net Skype: ali.moreno From jonas at andradas.es Wed Oct 22 10:50:56 2008 From: jonas at andradas.es (Jonas Andradas) Date: Wed, 22 Oct 2008 10:50:56 +0200 Subject: [Openvas-discuss] Problem in Debian In-Reply-To: <1224042103.4443.16.camel@localhost> References: <1224042103.4443.16.camel@localhost> Message-ID: Hello Ali, On Wed, Oct 15, 2008 at 5:41 AM, Ali Moreno < alimoreno at linktechnologies.com.ve> wrote: > Hi everybody, first excuse my bad english. > [snip] > > the client > > # apt-get install openvas-client > > but i cant find the openvas-adduser command, the only openvas-commands > that are in my systems are openvas-client and openvasclient-mkcert. > > Then i cant connect my client to my server :S > > Any help? > -- > Ali R. Moreno Ter?n > Director de Proyectos > Link Technologies - http://www.linktechnologies.com.ve > > M?vil: +58-414-144-24-44 > Email: alimoreno at linktechnologies.com.ve > Messenger: ali.mt at cantv.net > Skype: ali.moreno > > You have installed the Client, but seem to be missing the server. The openvas-adduser command is found on the server package, which currently is not available as a Debian package, and thus it must be compiled by you. If you already have a server somewhere else, you have to run the openvas-adduser command on that computer. Best Regards, Jon?s Andradas. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.wald.intevation.org/pipermail/openvas-discuss/attachments/20081022/056e2ca8/attachment.htm From jcf at ubiqube.com Thu Oct 30 12:12:15 2008 From: jcf at ubiqube.com (Jean-Christophe FORTON) Date: Thu, 30 Oct 2008 12:12:15 +0100 Subject: [Openvas-discuss] XML definition file Message-ID: <8D6BC20888573C4D8163394E3E149FD46BE36B@TUVALU.ubiqube.com> Hello all, I continue my integration of OpenVAS with the following version of: * openvas-libraries-1.0.1 * openvas-libnasl-1.0.0 * openvas-server-1.0.0 * openvas-plugins-1.0.4 * openvas-client-1.0.2 And I was wondering: where is the definition file that suits the xml report? (for html display for exemple). PS : I looked in the tarball, but without any success. Thanks all. Jean-Christophe Forton UBIqube Solutions Smart Security Services 18-20 rue Henri Barbusse B.P.2501 38035 Grenoble, Cedex 2, France ph: +33 438498370 www.ubiqube.com -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.wald.intevation.org/pipermail/openvas-discuss/attachments/20081030/fe33fc48/attachment.html From jan-oliver.wagner at intevation.de Fri Oct 31 09:08:00 2008 From: jan-oliver.wagner at intevation.de (Jan-Oliver Wagner) Date: Fri, 31 Oct 2008 09:08:00 +0100 Subject: [Openvas-discuss] XML definition file In-Reply-To: <8D6BC20888573C4D8163394E3E149FD46BE36B@TUVALU.ubiqube.com> References: <8D6BC20888573C4D8163394E3E149FD46BE36B@TUVALU.ubiqube.com> Message-ID: <200810310908.02536.jan-oliver.wagner@intevation.de> On Donnerstag, 30. Oktober 2008, Jean-Christophe FORTON wrote: > I continue my integration of OpenVAS with the following version of: > > * openvas-libraries-1.0.1 > * openvas-libnasl-1.0.0 > * openvas-server-1.0.0 > * openvas-plugins-1.0.4 > * openvas-client-1.0.2 > > And I was wondering: where is the definition file that suits the xml > report? (for html display for exemple). > > PS : I looked in the tarball, but without any success. you mean something like openvas-client/doc/nessus.xsd ? However, as you can see already from the filename, this area has not been worked on by OpenVAS project yet. What is there is as inherited from Nessus. Best Jan -- Dr. Jan-Oliver Wagner Intevation GmbH, Osnabr?ck Amtsgericht Osnabr?ck, HR B 18998 http://www.intevation.de/ Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner From greencm at gmail.com Fri Oct 31 22:39:33 2008 From: greencm at gmail.com (Chris Green) Date: Fri, 31 Oct 2008 16:39:33 -0500 Subject: [Openvas-discuss] 64-bit clean? Message-ID: Good day, I'm trying to compile (working on SVN but also tried 1.0.3) on x86_64 RHEL 4 with gnutls-1.0.20-4.el4_6. I'm guessing OpenVAS isn't 64-bit clean right now but it's also possible I'm missing some implicit dependency. Has anyone seen this kind of errors? gcc -pipe -I../ -DHAVE_CONFIG_H -I. -I/home/cmgreen/src/openvas-svn/openvas-libraries/include -I/usr/local/openvas/include -g -Wall -c plugutils.c -fPIC -DPIC -o .libs/plugutils.lo plugutils.c: In function `plug_set_id': plugutils.c:233: warning: cast to pointer from integer of different size plugutils.c: In function `_plug_get_id': plugutils.c:256: warning: cast from pointer to integer of different size plugutils.c: In function `plug_set_oid': plugutils.c:269: warning: cast from pointer to integer of different size plugutils.c: In function `plug_set_timeout': plugutils.c:622: warning: cast to pointer from integer of different size gcc -pipe -I../ -DHAVE_CONFIG_H -I. -I/home/cmgreen/src/openvas-svn/openvas-libraries/include -I/usr/local/openvas/include -g -Wall -c network.c -fPIC -DPIC -o .libs/network.lo network.c:72: error: syntax error before "gnutls_session_t" network.c:72: warning: no semicolon at end of struct or union [Snip] -- Chris Green From timb at nth-dimension.org.uk Fri Oct 31 22:52:05 2008 From: timb at nth-dimension.org.uk (Tim Brown) Date: Fri, 31 Oct 2008 21:52:05 +0000 Subject: [Openvas-discuss] 64-bit clean? In-Reply-To: References: Message-ID: <200810312152.05668.timb@nth-dimension.org.uk> Hi Chris, It's a known issue and largely follows from the Nessus code base from which OpenVAS forked. There has been a lot fo discussion and some patches have been proposed. You may wish to have a read of the following thread: http://lists.wald.intevation.org/pipermail/openvas-devel/2008-October/000987.html Cheers, Tim -- Tim Brown