Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 21 guests online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow Tenable Updates Plugin Subscription Model for Nessus
Ethical Hacker Community Forums
November 21, 2008, 07:37:43 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Tenable Updates Plugin Subscription Model for Nessus  (Read 3984 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2347


Editor-In-Chief


View Profile WWW
« on: May 23, 2008, 11:38:33 PM »

Huh? I had to read this a few times, and I'm still not sure I get it all based solely on this press release. Bottom line is that it is no longer free for companies. Free options still there for homes and non-profits. How many of you out there will suddenly have complex home networks, so you can get your plugin updates at "no charge and with no delay?"

Either way, this is how their site spins it:

Quote
Tenable Network Security Inc. today announced an update to its subscription model that will benefit home user and qualifying charities around the world.

Please read the letter to the Nessus community here.

What do you think of this new $1200 per year model?

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Kev
Sr. Member
****
Offline Offline

Posts: 347


View Profile
« Reply #1 on: May 24, 2008, 12:25:48 PM »

I knew it was just a matter of time. Hmmm, yes my network at home just got a little bigger. As far as the $1200 a year, I would rather go with GFIlanguard if I am going to have to pay. I feel its  more complete and way more options for tweaking your scans.
Logged
Dengar13
Full Member
***
Offline Offline

Posts: 224



View Profile
« Reply #2 on: May 24, 2008, 08:02:17 PM »

I think the companies that depend/use Nessus mostly will have to suck it up (resulting in higher fees to their clients possibly) or look for a new product as previously mentioned. 
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1037


View Profile WWW
« Reply #3 on: May 24, 2008, 09:38:35 PM »

i'll be looking into openVAS
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
sgt_mjc
Full Member
***
Offline Offline

Posts: 156


View Profile
« Reply #4 on: July 10, 2008, 11:24:59 AM »

We are dealing with this issue. Nessus along with a few other tools have been part of our kit for a while. Now there is a work around form what here that does not involve a more complex home network. there is supposedly a company that will be publishing plug ins for nessus for free becasue they are upset with Tennable.

Kev,

I just got done playing with LANguard and I felt that it left things unfound and had a few too many false possitives for us. Namely, it was telling me in our lab that on one of the machines that ports 21, 25, and 110 weree open. After checking both the machine itself and using nmap, the ports were all closed. It also missed bo2k. With that said, I would be careful with whatever tool you decide to use.

Mike
Logged

Mike Conway
CompTia Security +
C|EH
Ketchup
Newbie
*
Offline Offline

Posts: 41


View Profile
« Reply #5 on: July 10, 2008, 04:59:27 PM »

I am sticking with Nessus for a while.   I don't think GFI LanGuard is a legit product replacement for Nessus.   I will also be watching OpenVAS, like Chris.   Nessus is still free for "home" users for now.   It's accuracy has picked up in the last couple of releases and it seems dependable.   

At the same time, I see no reason to switch, even if there is a $1200 fee.   If you look at SAINT, Retina, Qualsys, etc, they are about the same on the accuracy scale.   I don't think that they have anything on Nessus.  I may just spend the $1200 a year if OpenVAS doesn't pan out.   

Anyone think that CANVAS is worth the investment?   Or is Metasploit plenty?

Ketchup
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1037


View Profile WWW
« Reply #6 on: July 10, 2008, 05:34:43 PM »

not to totally hijack the thread but what do you need canvas for?  its hard to answer your question otherwise. 

its a decent tool, but any time you have to pay you really need to take a look at why. 
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Ketchup
Newbie
*
Offline Offline

Posts: 41


View Profile
« Reply #7 on: July 10, 2008, 09:58:44 PM »

I was just looking at CANVAS as an additional exploit engine.   They seem to have some of the exploits that Metasploit doesn't.   At $1400 or so, it's not a bad investment to compliment Metasploit, maybe?
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1037


View Profile WWW
« Reply #8 on: July 10, 2008, 10:38:35 PM »

yes its a good supplement, the mosdef stuff is pretty nice from a post exploitation perspective, newer exploits, etc.

documentation is lacking so be for-warned on that one.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Kev
Sr. Member
****
Offline Offline

Posts: 347


View Profile
« Reply #9 on: July 11, 2008, 09:53:48 PM »

The real key to making metasploit a contender is understanding how to add your own exploits to the database. My feeling is you should first learn metasploit inside and out and then learn how to add new exploits to it, see how far this gets you.  Even if you have someone else paying for an expensive tool, its good to be familiar with well known tools that are often used in the wild.
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1037


View Profile WWW
« Reply #10 on: July 12, 2008, 09:41:06 AM »

yeah but if people dont have the ability to write their own exploits then canvas is the  next cheapest option.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.057 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.