Google Answers Logo
View Question
 
Q: Nessus -- Network based vulnerability scanner tool ( No Answer,   3 Comments )
Question  
Subject: Nessus -- Network based vulnerability scanner tool
Category: Computers > Security
Asked by: sisp-ga
List Price: $20.00
Posted: 17 May 2004 19:41 PDT
Expires: 03 Jun 2004 17:52 PDT
Question ID: 347973
I have already answered it, but need some help to "proof-read" the answer

Question 3:  NESSUS
Nessus, a network-based vulnerability scanner tool which allows you to
perform vulnerability scanning on hosts which you?ve identified.
Detail the steps you would take to automatically update the nessus
tool, listing all the commands which one would need to automatically
update the signatures within Nessus.  (Approximately 1 page answer)
3.1.	Summary: Funtions of NESSUS
http://www.nessus.org/documentation.html
·	Free and powerful remote security scanner. Audit a given network and
test the security vulnerability.
·	It will test any services running on any ports. It is able to test
unlimited hosts and multiple services at the same time
·	The client/server architecture allows flexibility to deploy the
scanner (server) and the GUI (client) in multiple configurations
·	The Unix client can export Nessus reports as ASCII text, LaTeX,
HTML, "spiffy" HTML (with pies and graphs) and an easy-to-parse file
format.
3.2.	Installing and Upgrading NESUS in Linux
The server portion will run on most any flavor of Unix. It even runs
on MAC OS X and IBM/AIX. Clients are available for both Windows and
Unix. The Nessus server performs the actual testing while the client
provides configuration and reporting functionality.

1)	Prior installation of several external programs is recommended:
NMAP is the industry standard for port scanners, Hydra is a weak
password tester and Nikto is a cgi/.script checker.

2)	Download and install nessus. Simplest way to install nessus is to
download the script nessus-installer.sh. There are a lot of mirror
sites to download this script, eg
(http://ftp.nessus.org/nessus/nessus-2.0.10a/nessus-installer/). To
install, type:  sh nessus-installer.sh. The above command should also
be used periodically to upgrade Nessus as new versions are regularly
released

3)	Create a user and supply these details:
a)	userid
b)	Authentication method (password/certification)
c)	Password
d)	Enter a set of rules (optional), eg
deny 10.163.153.1
accept 10.163.156.0/24
e)	System will prompt ?Is that okay (Y/N)?. Check your selections and
answer ?Y? to accept the values
f)	Generate a certification which will be used to encrypt the traffic
between the client and server using command: nessus-mkcert
g)	 Configure the daemon using file /usr/local/etc/nessus/nessud.conf.
nessus will create the nessusd.conf file if one is not available
3.3.	nessus signatures
·	Before a scan is done, the plug-ins should be updated. Each plug-in
is written to test for a specific vulnerability. Plug-ins can be
written in almost any language but usually are written in the Nessus
Attack Scripting Language (NASL).
3.3.1.	Steps to update the nessus signatures
a)	Login as root into the Linux machine
b)	Updating plug-ins from the maintained list with command: 
nessus-update-plugins

Request for Question Clarification by sublime1-ga on 17 May 2004 22:25 PDT
sisp...

Are you asking to have the language, format and spelling
proofread with no changes to the content?

sublime1-ga

Clarification of Question by sisp-ga on 17 May 2004 23:11 PDT
NO, i will deal with the language, spelling & format. 
1) Go thru the answer and correct any wrong commands, wrong steps,
missing steps, missing commands
2) Comment on whether there shld include some more explanation (if
everything is correct)

You may also want to include your own answer and explanation of where i go wrong
The Q had 2 parts a) Updating Nessus b) Updating the Nessus
signatures. It asked for a list of commands/steps to automate the
above. (it doesnt asked for steps to install), so i really dont know
whether how much of installation i should include
Answer  
There is no answer at this time.

Comments  
Subject: Re: Nessus -- Network based vulnerability scanner tool
From: sublime1-ga on 17 May 2004 23:16 PDT
 
sisp...

Thanks for clarifying. Perhaps another researcher will
be up to this task, however, it's not for me.

sublime1-ga
Subject: Re: Nessus -- Network based vulnerability scanner tool
From: dmrmv-ga on 18 May 2004 13:43 PDT
 
I suggest you add the suggestion that whoever posted the original make
sure that they have permission from the network administrator to
install and run Nessus (assuming they aren't the administrator). There
is no way to distinguish between legitimate use of tools like Nessus
and someone trying to break into the system.
Subject: Re: Nessus -- Network based vulnerability scanner tool
From: sisp-ga on 18 May 2004 17:04 PDT
 
Attn: dmrmv-ga

This is purely for a school assignment. I am trying to install linux
into my laptop, but failed 3x cos i'm kinda of fish out-of water. I
did the nessus tool in class as well, but it is only installing +
scanning of network which instructor had already setup (that is, the
network we connect to is a fake network, defined and created by the
instructor to show us how this tool works). Not to mention that there
was no instructions on how to install linux, just how to use this tool

As u noticed, the question asked specifically abt upgrading nessus and
upgrading nessus signatures. i think i got the signatures update
correct

Hope wonko is able to assist. he was great help w my other 2 assignments

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy