Forum Discussion
4 years ago
Tenable Research is providing the following supporting...
Tenable Research is providing the following supporting information about the 31 NASL detection plugins and two WAS plugin recently released in response to a critical vulnerability reported in Log4j (...
ccoble
4 years agoConnect Rookie
This is so frustrating!!! As of this posting the newest plugins are not finding vulnerabilities in a known device that is vulnerable. We have deployed an appliance for testing that we can confirm is vulnerable by using the tool provided by Huntress(https://log4shell.huntress.com/). We paste the JNDI payload into the Username field on the login screen of this device; use any password and submit the form and we get a callback. Why is Nessus not able to detect this?