官术网_书友最值得收藏!

Vulnerability scanning

Once the open ports are identified on the discovered live hosts, we can perform vulnerability scanning. A vulnerability scan detects and identifies known issues of the software and tools installed on a host such as older version of software in use, vulnerable protocols enabled, and default passwords. It is difficult to perform this activity manually; hence this phase needs to be performed using automated tools that identify the open ports and try various exploits on the ports to identify whether the particular process/software using the port is vulnerable to the exploit based on the process. Some of the tools used to perform vulnerability scanning are Nessus, OpenVas, and Qualys.

The following screenshot shows a sample host scanned for vulnerabilities using OpenVas. You can see that the output shows the list of vulnerabilities the host is affected:

In this cookbook, we will further introduce you to various recipes on how to scan a host for vulnerabilities using Nessus, and how to customize these scans to obtain specific and fewer false-positive results.

主站蜘蛛池模板: 共和县| 永安市| 万州区| 大荔县| 南充市| 吴旗县| 图片| 荥阳市| 武安市| 和龙市| 繁昌县| 通许县| 六安市| 那曲县| 远安县| 乐山市| 安乡县| 静海县| 谷城县| 泰和县| 孟连| 图木舒克市| 辰溪县| 新野县| 衡水市| 榆社县| 栾城县| 肇庆市| 桦南县| 高雄县| 北京市| 文水县| 平顶山市| 游戏| 孟津县| 思茅市| 栖霞市| 普陀区| 麻城市| 静宁县| 黄浦区|