Using Credentials with network scanners

Posted by grossmae on Server Fault See other posts from Server Fault or by grossmae
Published on 2010-09-21T23:18:05Z Indexed on 2012/07/08 21:18 UTC
Read the original article Hit count: 208

I'm testing out both Tenable's Nessus scanner as well as eEye's Retina for scanning network devices. I am trying to supply credentials to get deeper, more accurate results, however there seems to be no difference in the results whether I supply the credentials or not. I've read the documentation and it seems like I've tried all the logical settings in the Credential options. I've submit along with usernames and passwords for many different accounts and types of accounts (both SSH Credentials and Web Application Credentials) on the devices as well as their respective domain names (when applicable).

Is there possibly a good test for either (or both) scanners to tell where these credentials are being provided (if at all) and if any of them are successfully getting authentication?

© Server Fault or respective owner

Related posts about networking

Related posts about credentials