官术网_书友最值得收藏!

Vulnerability scanning

Once the open ports are identified on the discovered live hosts, we can perform vulnerability scanning. A vulnerability scan detects and identifies known issues of the software and tools installed on a host such as older version of software in use, vulnerable protocols enabled, and default passwords. It is difficult to perform this activity manually; hence this phase needs to be performed using automated tools that identify the open ports and try various exploits on the ports to identify whether the particular process/software using the port is vulnerable to the exploit based on the process. Some of the tools used to perform vulnerability scanning are Nessus, OpenVas, and Qualys.

The following screenshot shows a sample host scanned for vulnerabilities using OpenVas. You can see that the output shows the list of vulnerabilities the host is affected:

In this cookbook, we will further introduce you to various recipes on how to scan a host for vulnerabilities using Nessus, and how to customize these scans to obtain specific and fewer false-positive results.

主站蜘蛛池模板: 连平县| 台北县| 宁明县| 互助| 介休市| 通渭县| 金沙县| 杭州市| 高要市| 葫芦岛市| 大洼县| 四子王旗| 永德县| 郸城县| 太谷县| 建始县| 淮北市| 武功县| 灯塔市| 上饶县| 靖边县| 吉林市| 四子王旗| 巴东县| 盐边县| 密云县| 涿鹿县| 兴山县| 巩义市| 遂平县| 云浮市| 沐川县| 拉萨市| 比如县| 简阳市| 湖南省| 青龙| 安化县| 新丰县| 大冶市| 炎陵县|