So you want to build a Security Program? Part 1 - Vulnerability Scanning
-
I remember trying to get OpenVAS set up once.
(Shudders...)
-
@BRRABill So the setup its self so far hasn't seemed to difficult.
The GUI sucks though, and isn't intuitive. Adding targets is awkward, but once you've seen it, its easy enough.
-
@DustinB3403 said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
@BRRABill So the setup its self so far hasn't seemed to difficult.
The GUI sucks though, and isn't intuitive. Adding targets is awkward, but once you've seen it, its easy enough.
Yeah, I guess installing wasn't a big deal. I ended up just using one of their preconfigured ones. (This was back in my pre-Linux days.)
I think getting it work was more my thing. I'm sure if I stayed on it I would have figured it out. The GUI is definitely terrible.
-
Probably the worse GUI I've seen. It's so bad I had to download the vm again just to help @DustinB3403 because it's not intuitive at all.
-
So besides the bad interface, and oddity of having to download the NVTs separately the solution its self doesn't seem so bad.
A bit slow (vbox on my system), once you start to use it its actually kinda simply, and provides a nice insight to where things are vulnerable.
-
@DustinB3403 said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
So besides the bad interface, and oddity of having to download the NVTs separately the solution its self doesn't seem so bad.
A bit slow (vbox on my system), once you start to use it its actually kinda simply, and provides a nice insight to where things are vulnerable.
NVTs are downloaded on a schedule (weekly). You only have to do it once manually and it should update after that. You can always verify in the GUI by looking at the date of the latest NVTs.
The other option, which I've done for small companies who are low on resources is to just have the update command run at startup. There isn't a real reason to have this server up 24/7 so you can boot it up weekly or whatever if you want.
-
@DustinB3403 said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
Key note, once installed and you're able to access the web console, you need to enable the root account get to a shell command and run
openvasmd --update && openvasmd --rebuild
to download the NVTs and other SecInfo.This has taken about 5 minutes so far, but could take longer still.
Another thing to note, is that the free version is only allowed to run this command once a week. I've read that they can cut you off completely for you try to do it daily or whatever.
-
How to start your first scan
Ok so step one is to go to Configuration > Targets
Click the Star (top left) to Add A new Target
Let's just use one target for now. Name it whatever you want and just type in IP in manually
Otherwise I would use a text file
Then go to Configuration > Credentials
Add a credential and save it
Now go back to Configuration > Targets and edit the one you already made and go to SMB and select the credential you just made
Next go to Scan Management > Tasks
Then click the star to create a new task
Name it whatever you want and select the scan target you just created
Once you are finished with the task click the green play button to start the scan
Note: Added to the OP as well.
-
@IRJ said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
@DustinB3403 said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
Is OpenVAS intuitive to use and pickup? Does it have built in scans and reporting that are easily assessed (read).
The GUI and reporting are not good. In fact the GUI is one of the ugliest GUIs I have ever seen, but you will get the same data as you would with paid solutions.
You don't like the lady?
-
@stacksofplates said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
@IRJ said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
@DustinB3403 said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
Is OpenVAS intuitive to use and pickup? Does it have built in scans and reporting that are easily assessed (read).
The GUI and reporting are not good. In fact the GUI is one of the ugliest GUIs I have ever seen, but you will get the same data as you would with paid solutions.
You don't like the lady?
Maybe if I had a 4k monitor I could appreciate her more!
-
Is this more for finding Vulnerability's internally not say through your external ip(s)?
-
@hobbit666 Internal assessments only, you shouldn't be scanning the open internet. . .
-
It can work for either. There are plenty of people who have VPS setup with OpenVAS to do their external scans.
This is a full hosted external security solution, but you can build all the included tools in your own VPS
https://hackertarget.com -
@DustinB3403 said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
you shouldn't be scanning the open internet. . .
You most certainly should be. What do you think hackers are doing every minute on large networks?
-
@IRJ As in, you shouldn't be scanning everything on the open internet.
The FBI, NSA and other 3 letter government agency's will come knocking down your door.
-
@DustinB3403 said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
@IRJ As in, you shouldn't be scanning everything on the open internet.
The FBI, NSA and other 3 letter government agency's will come knocking down your door.
No they wont. It's like walking or driving up to a house and looking and casing it out for a robbery. You aren't doing anything illegal until you breach the house.
-
@IRJ Sure they can, it's called premeditation.
Planning to break in is as illegal as breaking in so long as you are committed to it.
-
@DustinB3403 said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
@IRJ Sure they can, it's called premeditation.
Planning to break in is as illegal as breaking in so long as you are committed to it.
But there is no way to know if someone is premeditating breaking it or doing a school report on safety concerns in the neighborhood.
-
@DustinB3403 said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
@IRJ As in, you shouldn't be scanning everything on the open internet.
The FBI, NSA and other 3 letter government agency's will come knocking down your door.
They have neither the resources nor the inclination to go after everyone that runs a simple scan. They don't in fact have the resources to go after all the people who have committed significantly damaging illegal acts let alone anything else.
-
@NDC said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
@DustinB3403 said in So you want to build a Security Program? Part 1 - Vulnerability Scanning:
@IRJ As in, you shouldn't be scanning everything on the open internet.
The FBI, NSA and other 3 letter government agency's will come knocking down your door.
They have neither the resources nor the inclination to go after everyone that runs a simple scan. They don't in fact have the resources to go after all the people who have committed significantly damaging illegal acts let alone anything else.
I see about 10 scans a minute from all over the world on our external servers on a slow day!