Re: [Openvas-discuss] Oracle Linux vulnerabilities past 2016

2018-06-11 Thread Eero Volotinen
Well. Try nexpose from rapid 7, it might be a bit different scanner.. Eero On Mon, Jun 11, 2018 at 1:05 PM Ewae Rpok wrote: > Thanks both. > > So I think one of the options we'll consider is managing the authenticated > local scans of Oracle Linux separately, using results of 'yum check-update

Re: [Openvas-discuss] Oracle Linux vulnerabilities past 2016

2018-06-11 Thread Ewae Rpok
Thanks both. So I think one of the options we'll consider is managing the authenticated local scans of Oracle Linux separately, using results of 'yum check-update' in place of openvas. Can still use openvas for non-authenticated remote scans. For completeness, will plan to look up details of the

Re: [Openvas-discuss] Oracle Linux vulnerabilities past 2016

2018-06-11 Thread Eero Volotinen
Hi, There are two kinds of check. remote checks and local checks. Anyway, both scanners works same way. Nessus contains a bit more remote check(s) and updated oracle linux checks. -- Eero On Mon, Jun 11, 2018 at 11:30 AM Ewae Rpok wrote: > Thanks again for the advice. > > Do all the communit

Re: [Openvas-discuss] Oracle Linux vulnerabilities past 2016

2018-06-11 Thread Christian Kuersteiner
Ewae, On 06/11/2018 03:30 PM, Ewae Rpok wrote: > Do all the community feeds work by checking only version numbers?  If > so, I think this would help me make a stronger case to get funding for > Nessus. As far as I can see are these all version checks. But just to clarify: this is actually the no

Re: [Openvas-discuss] Oracle Linux vulnerabilities past 2016

2018-06-11 Thread Ewae Rpok
Thanks again for the advice. Do all the community feeds work by checking only version numbers? If so, I think this would help me make a stronger case to get funding for Nessus. Cheers, Ewae. On Saturday, 9 June 2018, Eero Volotinen wrote: > Well. I think that checking only version numbers are

Re: [Openvas-discuss] Oracle Linux vulnerabilities past 2016

2018-06-08 Thread Eero Volotinen
Well. I think that checking only version numbers are not reliable way to evaluate security of server.. If you really want to do it, then just pick commercial nessus.. Eero la 9. kesäk. 2018 klo 1.01 Ewae Rpok kirjoitti: > Thanks for confirming, Eero. > > Any advice for alternative approaches t

Re: [Openvas-discuss] Oracle Linux vulnerabilities past 2016

2018-06-08 Thread Ewae Rpok
Thanks for confirming, Eero. Any advice for alternative approaches to managing vulnerability assessment on Oracle Linux? Cheers, Ewae. On Friday, 8 June 2018, Eero Volotinen wrote: > Hi, > > I "was" developer of that feed :) > > I haven't updated it for while, due to lack of time and/or sponso

Re: [Openvas-discuss] Oracle Linux vulnerabilities past 2016

2018-06-08 Thread Eero Volotinen
Hi, I "was" developer of that feed :) I haven't updated it for while, due to lack of time and/or sponsor ;) Eero pe 8. kesäk. 2018 klo 17.59 Ewae Rpok kirjoitti: > Hello all. > > Can anyone advise on scanning Oracle Linux vulnerabilities? > The Community feed seems to omit checks for errata p

[Openvas-discuss] Oracle Linux vulnerabilities past 2016

2018-06-08 Thread Ewae Rpok
Hello all. Can anyone advise on scanning Oracle Linux vulnerabilities? The Community feed seems to omit checks for errata published post 2016. e.g. https://linux.oracle.com/errata/ELSA-2018-0395.html was not reported despite kernel-uek 4.1.12-61.1.18 being run and kernel-3.10.0-514 being installe