Download presentation
Presentation is loading. Please wait.
Published byBranden Wilkinson Modified over 8 years ago
1
Vulnerability Assessment 2012 BackTrack Workshop Upstate ISSA Chapter
2
Agenda Performing Vulnerability Assessments System VA Tools Web App Scanners
3
Performing Vulnerability Assessments Identify and catalog potential vulnerabilities Associate level of risk with each potential vulnerability Examine possible attack vectors and attack chains to determine probability Prioritize remediation efforts
4
Associating Risk Level
5
System VA Tools OpenVAS Now with Greenbone! Nessus NeXpose
6
OpenVAS Configuring OpenVAS Running an OpenVAS Scan Greenbone Security Assistant
7
Configuring OpenVAS 1. Add an OpenVAS user 2. Create the OpenVAS server certificate 3. Synchronize OpenVAS database 4. Start the OpenVAS scanner 5. Check the OpenVAS configuration openvas-check-setup
8
Configuring OpenVAS 6. Configure OpenVAS Manager openvas-mkcert-client –n om –i 7. Rebuild OpenVAS Database openvasmd –rebuild 8. Add OepnVAS Admin Openvasad –c ‘add_user’ –n openvasadmin –r Admin
9
Configuring OpenVAS 9. Start the OpenVAS Manager openvasmd –p 9390 –a 127.0.0.1 10. Start the OpenVAS Administrator openvasad –a 127.0.0.1 –p 9393 11. Start the Greenbone Security Assistant gsad –http-only –listen=127.0.0.1 –p 9392
10
Greenbone Security Assistant
13
Nessus Installing Nessus on BackTrack Default Nessus Scan Customizing Nessus Policies
14
Installing Nessus on Backtrack Download Nessus Ubuntu Source from www.nessus.org www.nessus.org Install Nessus dpkg –i Nessus-5.0.1-ubuntu910_i386.deb Verify Nessus version nessus-fetch --version Register your serial number nessus-fetch –register SERIAL-NUMBER
15
Default Nessus Scan
18
Customizing Nessus Policies
19
NeXpose Community edition for up to 32 IPs
20
Web App Scanners nikto w3af
21
nikto./nikto.pl –h 192.168.1.112
22
w3af
23
Bookmarks openvas.org tenable.com rapid7.com securitystreet.com owasp.org cyberarms.wordpress.com
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.