ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    OpenVAS

    IT Discussion
    9
    35
    3.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      Veet
      last edited by

      Hi,

      I recently stumbled upon OpenVAS ... has anyone used it ?

      1 Reply Last reply Reply Quote 2
      • momurdaM
        momurda
        last edited by

        I have not. I might dl it and throw it on an Ubuntu server when i have some time at work, see what happens.

        1 Reply Last reply Reply Quote 0
        • dafyreD
          dafyre
          last edited by

          I've used it a few times. It has been a while though. It seems to work well if you give it enough RAM, etc.

          1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403
            last edited by

            I haven't used it but it seems like a very useful tool from what I've read so far.

            1 Reply Last reply Reply Quote 0
            • DustinB3403D
              DustinB3403
              last edited by

              Of your guys experience how difficult is this to setup for the targets?

              It does seem to be useful, just curious how far into the system I'd have to get before I saw some usable returns.

              1 Reply Last reply Reply Quote 0
              • dafyreD
                dafyre
                last edited by

                From what I remember, it was easy to set up... Just pick the Subnets (or individual servers) that you want to scan, and pick what scans you want it to do... Start the scan, and wait for it to generate a report.

                dafyreD V 2 Replies Last reply Reply Quote 0
                • dafyreD
                  dafyre @dafyre
                  last edited by

                  @dafyre said in OpenVAS:

                  From what I remember, it was easy to set up... Just pick the Subnets (or individual servers) that you want to scan, and pick what scans you want it to do... Start the scan, and wait for it to generate a report.

                  I'll spin it up and give it a go again to make sure it's still what I remember.

                  1 Reply Last reply Reply Quote 0
                  • BRRABillB
                    BRRABill
                    last edited by

                    I set it up a few months back. (Still have it on my XS in fact.)

                    I had a few issues getting it set up, but eventually got it to work.

                    1 Reply Last reply Reply Quote 0
                    • V
                      Veet @dafyre
                      last edited by

                      @dafyre said in OpenVAS:

                      From what I remember, it was easy to set up... Just pick the Subnets (or individual servers) that you want to scan, and pick what scans you want it to do... Start the scan, and wait for it to generate a report.

                      How effective/accurate is it ?

                      BRRABillB 1 Reply Last reply Reply Quote 0
                      • DustinB3403D
                        DustinB3403
                        last edited by

                        I'm just taking a blind guess that the "demo" version is marked as so, but not limited in anyway?

                        BRRABillB 1 Reply Last reply Reply Quote 0
                        • BRRABillB
                          BRRABill @DustinB3403
                          last edited by

                          @DustinB3403 said in OpenVAS:

                          I'm just taking a blind guess that the "demo" version is marked as so, but not limited in anyway?

                          It's all free and open source. I don't think there is a demo.

                          1 Reply Last reply Reply Quote 0
                          • BRRABillB
                            BRRABill @Veet
                            last edited by

                            @Veet said in OpenVAS:

                            @dafyre said in OpenVAS:

                            From what I remember, it was easy to set up... Just pick the Subnets (or individual servers) that you want to scan, and pick what scans you want it to do... Start the scan, and wait for it to generate a report.

                            How effective/accurate is it ?

                            That's one of the things I never actually got working. Couldn't figure out the scanning. I am sure it works, just didn't have the time to figure out what I needed.

                            Hmmm, what would @scottalanmiller say here?

                            SAM: "that's like building a car, and not knowing if it drives or not"

                            1 Reply Last reply Reply Quote 0
                            • DustinB3403D
                              DustinB3403
                              last edited by

                              http://www.openvas.org/vm.html

                              Demo is plainly listed, I'm guessing that is just put there to say, hey if you want to do this, you should really build from sources.

                              BRRABillB V 2 Replies Last reply Reply Quote 0
                              • BRRABillB
                                BRRABill @DustinB3403
                                last edited by

                                @DustinB3403 said in OpenVAS:

                                http://www.openvas.org/vm.html

                                Demo is plainly listed, I'm guessing that is just put there to say, hey if you want to do this, you should really build from sources.

                                Yeah, no idea what that is.

                                1 Reply Last reply Reply Quote 0
                                • V
                                  Veet @DustinB3403
                                  last edited by

                                  @DustinB3403 said in OpenVAS:

                                  http://www.openvas.org/vm.html

                                  Demo is plainly listed, I'm guessing that is just put there to say, hey if you want to do this, you should really build from sources.

                                  Scroll down to the bottom of the page, and you'll read the following : -

                                  ***Important note on these Virtual Appliances

                                  Please note that these virtual appliances are for demonstration/testing purposes and not recommended for regular production uses, particularly for more than a few hosts depending on local system resources. The OpenVAS scanner is resource intensive and may take a long time to start on slower systems, especially when run as a VM on laptops.***

                                  dafyreD DustinB3403D 2 Replies Last reply Reply Quote 1
                                  • dafyreD
                                    dafyre
                                    last edited by dafyre

                                    The DEMO build is just an OVA that you can import into VMware / VirtualBox and be ready to go in a few minutes... Sadly, their image download seems to be overloaded... A whopping 14 kbit/sec download for me...and the appliance is 3GB... So I'm building from Ubuntu and going to try the OpenVAS9 PPA.

                                    Edit: Clarity.

                                    BRRABillB 1 Reply Last reply Reply Quote 0
                                    • BRRABillB
                                      BRRABill @dafyre
                                      last edited by

                                      @dafyre said in OpenVAS:

                                      The DEMO build is just an OVA that you can import into VMware / VirtualBox and be ready to go in a few minutes... Sadly, their image download seems to be overloaded... A whopping 14 kbit download for me... So I'm building from Ubuntu and going to try the OpenVAS9 PPA.

                                      Right.

                                      It's not a working appliance like Graylog, or XO.

                                      dafyreD 1 Reply Last reply Reply Quote 0
                                      • dafyreD
                                        dafyre @Veet
                                        last edited by

                                        @Veet said in OpenVAS:

                                        @DustinB3403 said in OpenVAS:

                                        http://www.openvas.org/vm.html

                                        Demo is plainly listed, I'm guessing that is just put there to say, hey if you want to do this, you should really build from sources.

                                        Scroll down to the bottom of the page, and you'll read the following : -

                                        ***Important note on these Virtual Appliances

                                        Please note that these virtual appliances are for demonstration/testing purposes and not recommended for regular production uses, particularly for more than a few hosts depending on local system resources. The OpenVAS scanner is resource intensive and may take a long time to start on slower systems, especially when run as a VM on laptops.***

                                        Essentially saying, be sure to give it enough RAM to run.

                                        1 Reply Last reply Reply Quote 0
                                        • dafyreD
                                          dafyre @BRRABill
                                          last edited by

                                          @BRRABill said in OpenVAS:

                                          @dafyre said in OpenVAS:

                                          The DEMO build is just an OVA that you can import into VMware / VirtualBox and be ready to go in a few minutes... Sadly, their image download seems to be overloaded... A whopping 14 kbit download for me... So I'm building from Ubuntu and going to try the OpenVAS9 PPA.

                                          Right.

                                          It's not a working appliance like Graylog, or XO.

                                          No, it is a fully working appliance... but I don't feel like waiting 3 days for it to download, lol.

                                          BRRABillB 1 Reply Last reply Reply Quote 0
                                          • BRRABillB
                                            BRRABill @dafyre
                                            last edited by

                                            @dafyre said

                                            No, it is a fully working appliance... but I don't feel like waiting 3 days for it to download, lol.

                                            I meant working in the sense of "production usable" ... it's more a proof of concept than a working appliance like XO or Graylog offerings.

                                            dafyreD 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post