官术网_书友最值得收藏!

Vulnerability scanning

Once the open ports are identified on the discovered live hosts, we can perform vulnerability scanning. A vulnerability scan detects and identifies known issues of the software and tools installed on a host such as older version of software in use, vulnerable protocols enabled, and default passwords. It is difficult to perform this activity manually; hence this phase needs to be performed using automated tools that identify the open ports and try various exploits on the ports to identify whether the particular process/software using the port is vulnerable to the exploit based on the process. Some of the tools used to perform vulnerability scanning are Nessus, OpenVas, and Qualys.

The following screenshot shows a sample host scanned for vulnerabilities using OpenVas. You can see that the output shows the list of vulnerabilities the host is affected:

In this cookbook, we will further introduce you to various recipes on how to scan a host for vulnerabilities using Nessus, and how to customize these scans to obtain specific and fewer false-positive results.

主站蜘蛛池模板: 宁安市| 屯留县| 鹤庆县| 临江市| 亚东县| 黑龙江省| 江安县| 榕江县| 四川省| 新密市| 洪江市| 高青县| 章丘市| 安义县| 富阳市| 阿瓦提县| 财经| 和龙市| 云林县| 海城市| 班玛县| 察雅县| 重庆市| 青州市| 阿克苏市| 富民县| 阿巴嘎旗| 尼木县| 宝应县| 堆龙德庆县| 察哈| 筠连县| 明星| 丽水市| 泸溪县| 固安县| 泰宁县| 株洲市| 兴文县| 江安县| 聂荣县|