EH-Net
May 23, 2013, 11:21:42 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Vulnerability Assesment
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Vulnerability Assesment (Read 2677 times)
0 Members and 1 Guest are viewing this topic.
impelse
Hero Member
Offline
Posts: 565
Vulnerability Assesment
«
on:
March 23, 2012, 11:49:33 PM »
This question is for you guys that do vulnerability assessment.
What vulnerability tool do you normally use? OpenVass, Saint, Nessus or Rapid7? Do you scan only servers/switches/firewall/routers, etc or the whole networking including workstations?
I am talking a general vulnerability assessment, not compliant.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Vulnerability Assesment
«
Reply #1 on:
March 24, 2012, 11:16:02 AM »
I use a mix
(Of Nessus and Metasploit) Sometimes I scan everything (small subnets), sometimes I break things up and scan smaller segments at a time in +100 device networks. (I've often been under an extremely tight time-limit, meaning 1-3 hours max.)
Logged
I'm an InterN0T'er
impelse
Hero Member
Offline
Posts: 565
Re: Vulnerability Assesment
«
Reply #2 on:
March 24, 2012, 12:30:08 PM »
Last night and today I use OpenVas in a real environment, my supervisor begin to ask the vulnerability assessment for one of our client.
I am glad he asked something like that so I can experiment more, I am taking PWB training but I was worry come on: I will need to get more real experience!!!!. I know vulnerability assessment is not a pentest but I will get it someday very soon.
Tonight I will try Nessus and see what fit better for the company.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
BillV
Hero Member
Offline
Posts: 1892
Re: Vulnerability Assesment
«
Reply #3 on:
March 24, 2012, 02:17:50 PM »
A mix... Nessus, Qualys, Nexpose. Scans are conducted on whatever is in scope.
Logged
cd1zz
Hero Member
Offline
Posts: 561
Re: Vulnerability Assesment
«
Reply #4 on:
March 25, 2012, 09:37:33 PM »
Nexpose. It's not perfect, but none of them are. There are many times that the scanner reports nothing "critical" but full compromise happens shortly there after. I hate VA's... I wish compliance programs realized that.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
sil
Hero Member
Offline
Posts: 549
Re: Vulnerability Assesment
«
Reply #5 on:
March 26, 2012, 08:42:10 AM »
I suggest you read a paper I wrote which expounds on these topics
http://infosecisland.com/documentview/12932-Defending-the-Castle-by-Actively-Abusing-It.html
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...