About

Try out OpenVAS

Information/Howtos

Books

German:

Support

Mailing Lists

Developers Corner

Download

OpenVAS 3.1

Classic Setup

Full Setup

OpenVAS 3.0

OpenVAS 2.0

Server components

Client

Documentation

More

NVT Lookup by OID

(replace 61039 by any other old-style ID)

OpenVAS Change Request #8: Introduce NVT family "Credentials"

Status: Voted +2. Implemented. Server-side changes released with openvas-plugins 1.0.2, client-side released with OpenVAS-Client 1.0.4.

Purpose

To consistently mark those NVTs that transfer user input on credentials into the knowledge base by setting the family to "Credentials".

References

Initial discussion on openvas-plugins mailing list where this request emerged from.

Rationale

OpenVAS-Client offers a configuration page on "Credentials". It summarizes those "plugin preferences" that are managing parameters for logging in somewhere. OpenVAS-Client identifies them currently by hard-coded names (which is a behavior inherited from Nessus).

Apparently names can change or new ones can appear. It is considered a broken concept to have it necessary to change this in the client application each time such a change occurs. Instead, the client should flexible react on changes happened in OpenVAS server.

Effects

Design and Implementation

History