Penetration Testing mailing list archives

Re: opinions on Vigliante's SecureScanNX for attack/pen work?


From: "John Lampe" <j_lampe () bellsouth net>
Date: Thu, 29 Nov 2001 20:25:16 -0000

- I don't know how much it costs
- you can only scan public ip addresses
- it's not the fastest on earth (manually supervised,
  but it will change in the future)

Really?  IMO, securescanx scanned a little too fast.  I ran a scan against a
/24 range of addresses off of a T-1 connection with both Nessus and
vigilante whilst running a packet sniffer off of the spanned default gw
port....The vigilante was so aggressive that it missed many of the ports
which Nessus (Nmap, in this instance) found.  Vigilante was sending SYN
packets about 4 times faster than the nessusd server.....


BTW, it uses all the tools we commonly have (nmap, icmpush...)
plus some smartware by VigilantE.

incidentally, securescan utilizes nessus technology as well...
http://www.vigilante.com/press/releases/?pi=19

John Lampe
https://f00dikator.hn.org/


----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/


Current thread: