ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    OpenVAS

    IT Discussion
    9
    35
    3.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BRRABillB
      BRRABill @Veet
      last edited by

      @Veet said in OpenVAS:

      @dafyre said in OpenVAS:

      From what I remember, it was easy to set up... Just pick the Subnets (or individual servers) that you want to scan, and pick what scans you want it to do... Start the scan, and wait for it to generate a report.

      How effective/accurate is it ?

      That's one of the things I never actually got working. Couldn't figure out the scanning. I am sure it works, just didn't have the time to figure out what I needed.

      Hmmm, what would @scottalanmiller say here?

      SAM: "that's like building a car, and not knowing if it drives or not"

      1 Reply Last reply Reply Quote 0
      • DustinB3403D
        DustinB3403
        last edited by

        http://www.openvas.org/vm.html

        Demo is plainly listed, I'm guessing that is just put there to say, hey if you want to do this, you should really build from sources.

        BRRABillB V 2 Replies Last reply Reply Quote 0
        • BRRABillB
          BRRABill @DustinB3403
          last edited by

          @DustinB3403 said in OpenVAS:

          http://www.openvas.org/vm.html

          Demo is plainly listed, I'm guessing that is just put there to say, hey if you want to do this, you should really build from sources.

          Yeah, no idea what that is.

          1 Reply Last reply Reply Quote 0
          • V
            Veet @DustinB3403
            last edited by

            @DustinB3403 said in OpenVAS:

            http://www.openvas.org/vm.html

            Demo is plainly listed, I'm guessing that is just put there to say, hey if you want to do this, you should really build from sources.

            Scroll down to the bottom of the page, and you'll read the following : -

            ***Important note on these Virtual Appliances

            Please note that these virtual appliances are for demonstration/testing purposes and not recommended for regular production uses, particularly for more than a few hosts depending on local system resources. The OpenVAS scanner is resource intensive and may take a long time to start on slower systems, especially when run as a VM on laptops.***

            dafyreD DustinB3403D 2 Replies Last reply Reply Quote 1
            • dafyreD
              dafyre
              last edited by dafyre

              The DEMO build is just an OVA that you can import into VMware / VirtualBox and be ready to go in a few minutes... Sadly, their image download seems to be overloaded... A whopping 14 kbit/sec download for me...and the appliance is 3GB... So I'm building from Ubuntu and going to try the OpenVAS9 PPA.

              Edit: Clarity.

              BRRABillB 1 Reply Last reply Reply Quote 0
              • BRRABillB
                BRRABill @dafyre
                last edited by

                @dafyre said in OpenVAS:

                The DEMO build is just an OVA that you can import into VMware / VirtualBox and be ready to go in a few minutes... Sadly, their image download seems to be overloaded... A whopping 14 kbit download for me... So I'm building from Ubuntu and going to try the OpenVAS9 PPA.

                Right.

                It's not a working appliance like Graylog, or XO.

                dafyreD 1 Reply Last reply Reply Quote 0
                • dafyreD
                  dafyre @Veet
                  last edited by

                  @Veet said in OpenVAS:

                  @DustinB3403 said in OpenVAS:

                  http://www.openvas.org/vm.html

                  Demo is plainly listed, I'm guessing that is just put there to say, hey if you want to do this, you should really build from sources.

                  Scroll down to the bottom of the page, and you'll read the following : -

                  ***Important note on these Virtual Appliances

                  Please note that these virtual appliances are for demonstration/testing purposes and not recommended for regular production uses, particularly for more than a few hosts depending on local system resources. The OpenVAS scanner is resource intensive and may take a long time to start on slower systems, especially when run as a VM on laptops.***

                  Essentially saying, be sure to give it enough RAM to run.

                  1 Reply Last reply Reply Quote 0
                  • dafyreD
                    dafyre @BRRABill
                    last edited by

                    @BRRABill said in OpenVAS:

                    @dafyre said in OpenVAS:

                    The DEMO build is just an OVA that you can import into VMware / VirtualBox and be ready to go in a few minutes... Sadly, their image download seems to be overloaded... A whopping 14 kbit download for me... So I'm building from Ubuntu and going to try the OpenVAS9 PPA.

                    Right.

                    It's not a working appliance like Graylog, or XO.

                    No, it is a fully working appliance... but I don't feel like waiting 3 days for it to download, lol.

                    BRRABillB 1 Reply Last reply Reply Quote 0
                    • BRRABillB
                      BRRABill @dafyre
                      last edited by

                      @dafyre said

                      No, it is a fully working appliance... but I don't feel like waiting 3 days for it to download, lol.

                      I meant working in the sense of "production usable" ... it's more a proof of concept than a working appliance like XO or Graylog offerings.

                      dafyreD 1 Reply Last reply Reply Quote 0
                      • DustinB3403D
                        DustinB3403 @Veet
                        last edited by

                        @Veet I did, and I read it as well. Just curious if there was some kind of "paid" or source difference from what they have in the OVA.

                        1 Reply Last reply Reply Quote 0
                        • dafyreD
                          dafyre @BRRABill
                          last edited by

                          @BRRABill said in OpenVAS:

                          @dafyre said

                          No, it is a fully working appliance... but I don't feel like waiting 3 days for it to download, lol.

                          I meant working in the sense of "production usable" ... it's more a proof of concept than a working appliance like XO or Graylog offerings.

                          It's quite usable for production -- that's what I ran when I used it in the past. You just can't gimp on the RAM. For production, I'd suggest 8GB or 16GB of RAM or more... Especially for anything more than a few hosts.

                          BRRABillB 1 Reply Last reply Reply Quote 0
                          • BRRABillB
                            BRRABill @dafyre
                            last edited by

                            @dafyre said in OpenVAS:

                            @BRRABill said in OpenVAS:

                            @dafyre said

                            No, it is a fully working appliance... but I don't feel like waiting 3 days for it to download, lol.

                            I meant working in the sense of "production usable" ... it's more a proof of concept than a working appliance like XO or Graylog offerings.

                            It's quite usable for production -- that's what I ran when I used it in the past. You just can't gimp on the RAM. For production, I'd suggest 8GB or 16GB of RAM or more... Especially for anything more than a few hosts.

                            Oh, that's good to know.

                            I admittedly struggled a bit with getting it installed from source. But that's probably just me.

                            And by probably I mean definitely.

                            dafyreD 1 Reply Last reply Reply Quote 0
                            • dafyreD
                              dafyre @BRRABill
                              last edited by

                              @BRRABill said in OpenVAS:

                              @dafyre said in OpenVAS:

                              @BRRABill said in OpenVAS:

                              @dafyre said

                              No, it is a fully working appliance... but I don't feel like waiting 3 days for it to download, lol.

                              I meant working in the sense of "production usable" ... it's more a proof of concept than a working appliance like XO or Graylog offerings.

                              It's quite usable for production -- that's what I ran when I used it in the past. You just can't gimp on the RAM. For production, I'd suggest 8GB or 16GB of RAM or more... Especially for anything more than a few hosts.

                              Oh, that's good to know.

                              I admittedly struggled a bit with getting it installed from source. But that's probably just me.

                              And by probably I mean definitely.

                              If you like Ubuntu, they have pre-compiled binaries and such from the PPA. Easy to set up.

                              https://launchpad.net/~mrazavi/+archive/ubuntu/openvas

                              I've got a scan going... I am trying the openvas9 beta.

                              1 Reply Last reply Reply Quote 0
                              • BRRABillB
                                BRRABill
                                last edited by

                                Not that anyone cares, but I looked at my OpenVAS VM.........

                                "Imported from OVA"

                                I'm. A. Dope.

                                dafyreD 1 Reply Last reply Reply Quote 0
                                • dafyreD
                                  dafyre @BRRABill
                                  last edited by

                                  @BRRABill said in OpenVAS:

                                  Not that anyone cares, but I looked at my OpenVAS VM.........

                                  "Imported from OVA"

                                  I'm. A. Dope.

                                  No Problem with that either. 🙂

                                  BRRABillB 1 Reply Last reply Reply Quote 0
                                  • BRRABillB
                                    BRRABill @dafyre
                                    last edited by

                                    @dafyre said in OpenVAS:

                                    @BRRABill said in OpenVAS:

                                    Not that anyone cares, but I looked at my OpenVAS VM.........

                                    "Imported from OVA"

                                    I'm. A. Dope.

                                    No Problem with that either. 🙂

                                    I just mean that I thought I didn't use it. Duh.

                                    It WAS a few months ago!

                                    dafyreD 1 Reply Last reply Reply Quote 0
                                    • dafyreD
                                      dafyre @BRRABill
                                      last edited by

                                      @BRRABill said in OpenVAS:

                                      @dafyre said in OpenVAS:

                                      @BRRABill said in OpenVAS:

                                      Not that anyone cares, but I looked at my OpenVAS VM.........

                                      "Imported from OVA"

                                      I'm. A. Dope.

                                      No Problem with that either. 🙂

                                      I just mean that I thought I didn't use it. Duh.

                                      It WAS a few months ago!

                                      You've slept a few times since then. 🙂

                                      BRRABillB 1 Reply Last reply Reply Quote 0
                                      • StrongBadS
                                        StrongBad
                                        last edited by

                                        It got mentioned a year ago... but that's about it.

                                        https://mangolassi.it/topic/5507/it-infrastructure-health-checkup/23

                                        I've never used it.

                                        1 Reply Last reply Reply Quote 1
                                        • BRRABillB
                                          BRRABill @dafyre
                                          last edited by

                                          @dafyre said in OpenVAS:

                                          @BRRABill said in OpenVAS:

                                          @dafyre said in OpenVAS:

                                          @BRRABill said in OpenVAS:

                                          Not that anyone cares, but I looked at my OpenVAS VM.........

                                          "Imported from OVA"

                                          I'm. A. Dope.

                                          No Problem with that either. 🙂

                                          I just mean that I thought I didn't use it. Duh.

                                          It WAS a few months ago!

                                          You've slept a few times since then. 🙂

                                          I think alcohol is killing my brain cell

                                          1 Reply Last reply Reply Quote 0
                                          • T
                                            tiagom
                                            last edited by

                                            I've worked with it in the past for a particular issue in a product. Worked for what we needed it for.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2 / 2
                                            • First post
                                              Last post