From bchandra at secpod.com Mon Dec 1 11:46:24 2008 From: bchandra at secpod.com (Chandrashekhar B) Date: Mon, 1 Dec 2008 16:16:24 +0530 Subject: [Openvas-plugins] CR #22: script_tag command - Call For Votes In-Reply-To: <20081128152316.GF4017@intevation.de> References: <20081128152316.GF4017@intevation.de> Message-ID: <66444E821F9247CD8D07165BF30AD41B@bchandra> Vote +1 Chandra. -----Original Message----- From: openvas-plugins-bounces at wald.intevation.org [mailto:openvas-plugins-bounces at wald.intevation.org] On Behalf Of Michael Wiegand Sent: Friday, November 28, 2008 8:53 PM To: OpenVAS Development List; OpenVAS Plugins List Subject: [Openvas-plugins] CR #22: script_tag command - Call For Votes Hello, I've just uploaded another change request. This one proposes adding a script_tag command to NASL which would help NVT writers to manage the properties of their scripts in a more flexible way. The change request is available at: http://www.openvas.org/openvas-cr-22.html I'd like to ask all of you to take a look at it (especially the NASL developers) and to cast your vote. Let me know if you have any suggestions or questions. Thank you and have a great weekend! Regards, Michael -- Michael Wiegand | OpenPGP key: D7D049EC | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabr?ck | AG Osnabr?ck, HR B 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner _______________________________________________ Openvas-plugins mailing list Openvas-plugins at wald.intevation.org http://lists.wald.intevation.org/mailman/listinfo/openvas-plugins From michael.wiegand at intevation.de Mon Dec 1 12:47:05 2008 From: michael.wiegand at intevation.de (Michael Wiegand) Date: Mon, 1 Dec 2008 12:47:05 +0100 Subject: [Openvas-plugins] Planning openvas-plugins 1.0.5 release Message-ID: <20081201114705.GA20725@intevation.de> Hello, there has been quite an amount of changes to openvas-plugins since the release of 1.0.4 in October, including improvements in the build environment, 64-bit cleanliness, a large number of new NVTs and updated packaging for Debian. Because of this and to synchronize this package with the SVN ahead of the upcoming 2.0 release of OpenVAS, I'd like to release openvas-plugins 1.0.5 on Wednesday, December 3rd. Please contact me if you have any issues with this plan; if you are planning on packaging openvas-plugins for a distribution, please let me know if there is anything that should be done before the release to make the inclusion of OpenVAS into the distribution of your choice easier. Thank you! Regards, Michael -- Michael Wiegand | OpenPGP key: D7D049EC | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabr?ck | AG Osnabr?ck, HR B 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner From jan-oliver.wagner at intevation.de Wed Dec 3 11:00:02 2008 From: jan-oliver.wagner at intevation.de (Jan-Oliver Wagner) Date: Wed, 3 Dec 2008 11:00:02 +0100 Subject: [Openvas-plugins] [Openvas-devel] CR #22: script_tag command - Call For Votes In-Reply-To: <20081128152316.GF4017@intevation.de> References: <20081128152316.GF4017@intevation.de> Message-ID: <200812031100.05251.jan-oliver.wagner@intevation.de> On Freitag, 28. November 2008, Michael Wiegand wrote: > I've just uploaded another change request. This one proposes adding a > script_tag command to NASL which would help NVT writers to manage the > properties of their scripts in a more flexible way. > > The change request is available at: > http://www.openvas.org/openvas-cr-22.html > > I'd like to ask all of you to take a look at it (especially the NASL > developers) and to cast your vote. > > Let me know if you have any suggestions or questions. Thank you and have > a great weekend! +1 -- Dr. Jan-Oliver Wagner | ++49-541-335 08 30 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabr?ck | AG Osnabr?ck, HR B 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner From timb at nth-dimension.org.uk Thu Dec 4 15:50:09 2008 From: timb at nth-dimension.org.uk (Tim Brown) Date: Thu, 4 Dec 2008 14:50:09 +0000 Subject: [Openvas-plugins] Some ideas for plugins... Message-ID: <200812041450.09632.timb@nth-dimension.org.uk> All, As some of you may have notice I've been a bit quiet lately, due to a rather large piece of testing that I've been involved with at $job. However it's give me some time to have a think about some things that it would be nice to have. I'm mainly sending this email as a way to remind myself of them later, but if anyone wants to have a crack at them feel free: * Microsoft RPC DCOM check results in false positives; * The Microsoft local checks result in much noise when OpenVAS can't connect; * smbcl_func.inc should maybe be deprecated in favour of SecPod's routines?; * ssh_func.inc is broken, making Solaris plugins in my branch useless at this time; * We have mutiple LDAP checks, implemented in varying ways, these checks should be aggregated; * A check for http://www.portcullis-security.com/294.php which allows username enumeration against a fully patched Windows 2003 system running LDAP would be nice (there's a Python POC here: http://downloads.securityfocus.com/vulnerabilities/exploits/ldapuserenum-32305.py); * A new class of checks that look for broadcast traffic such as MS NLB, CDP, VRRP and HSRP etc would be awesome. Cheers, Tim -- Tim Brown From michael.wiegand at intevation.de Tue Dec 9 11:10:49 2008 From: michael.wiegand at intevation.de (Michael Wiegand) Date: Tue, 9 Dec 2008 11:10:49 +0100 Subject: [Openvas-plugins] Some ideas for plugins... In-Reply-To: <200812041450.09632.timb@nth-dimension.org.uk> References: <200812041450.09632.timb@nth-dimension.org.uk> Message-ID: <20081209101049.GF18801@intevation.de> * Tim Brown [ 4. Dec 2008]: > * ssh_func.inc is broken, making Solaris plugins in my branch useless at this > time; This is one issue I would like to fix sooner rather than later; I haven't yet been able to pinpoint the exact problem, so I'd appreciate additional bug reports and thoughts on this as this might break other LSCs as well. If you observe similar behavior, please submit anything you consider useful to the bug tracker and attach it to bug #788 (http://bugs.openvas.org/788). Regards, Michael -- Michael Wiegand | OpenPGP key: D7D049EC | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabr?ck | AG Osnabr?ck, HR B 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner From michael.wiegand at intevation.de Wed Dec 10 15:53:55 2008 From: michael.wiegand at intevation.de (Michael Wiegand) Date: Wed, 10 Dec 2008 15:53:55 +0100 Subject: [Openvas-plugins] Planning OpenVAS 2.0.0 Message-ID: <20081210145355.GH22004@intevation.de> Hello, I would like to schedule the release of the "real" 2.0.0 for Wednesday, December 17th. The feedback we have received for the 2.0-rc1 release was (mostly) positive and I think OpenVAS is now ready for prime time, just in time for the holidays. :) This release affects openvas-libraries, openvas-libnasl, openvas-server and openvas-client. Not affected are openvas-plugins and openvas-compendium. Please report any bugs which you think need to be fixed before 2.0.0 to the OpenVAS bug tracker at http://bugs.openvas.org/ and let me know if you have problems with the proposed schedule. Translators, Distro Packagers: Please make sure you contributions are in the SVN repository at least one day before the release so we can include the in 2.0.0. Many thanks once again to everybody who has contributed on the way to 2.0. Feel free to contact me if you have any questions or suggestions. Regards, Michael -- Michael Wiegand | OpenPGP key: D7D049EC | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabr?ck | AG Osnabr?ck, HR B 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner From bchandra at secpod.com Mon Dec 29 09:15:06 2008 From: bchandra at secpod.com (Chandrashekhar B) Date: Mon, 29 Dec 2008 13:45:06 +0530 Subject: [Openvas-plugins] OpenSuse 11.1 update Message-ID: I have made the following changes to gather-package-list.nasl, - Added openSUSE11.1 into the KB item - Changed openSUSE11 to openSUSE11.0 - Added openSUSE10.2 into the KB item. Please let me know if any one is affected by this change. Thanks, Chandra. From lists at securityspace.com Mon Dec 29 18:04:05 2008 From: lists at securityspace.com (Thomas Reinke) Date: Mon, 29 Dec 2008 12:04:05 -0500 Subject: [Openvas-plugins] OpenSuse 11.1 update In-Reply-To: References: Message-ID: <49590305.4000208@securityspace.com> Chandrashekhar B wrote: > - Changed openSUSE11 to openSUSE11.0 This one broke some of our scripts, but on review, the change is consistent with the numbering scheme that should have been used in the first place, so we changed those affected scripts to pull the changed KB name. Thomas