Chuyển đến nội dung chính

Bài Tập Thực Hành - NESSUS: Lesson 0 Register and Download Nessus Security Scanner

{ Register and Download Nessus Security Scanner }

Section 0: Background Information
  1. What is NESSUS?
    • Tenable Network Security provides enterprise-class solutions for continuous monitoring and visibility of vulnerabilities, configurations, user activity and system events that impact security and compliance.

    • Nessus features high-speed discovery, configuration auditing, asset profiling, sensitive data discovery and vulnerability analysis of your security posture.
  2. Reference Link: 
  3. Lab Notes
    • In this lab we will do the following:
      1. Download Nessus
      2. Retrieve Registration Code
      3. Install Nessus

  4. Legal Disclaimer
      Www.AnToanThongTin.Edu.Vn
       

Section 1: Login to PENTEST-WXP
  1. Start Up VMWare Player
    • Instructions:
      1. Click the Start Button
      2. Type Vmplayer in the search box
      3. Click on Vmplayer
  2. Edit Virtual Machine Settings
    • Instructions:
      1. Click on PENTEST-WXP
      2. Edit Virtual Machine Settings
    • Note:
      • This VM is running Windows XP.
  3. Set Network Adapter
    • Instructions:
      1. Click on Network Adapter
      2. Click on the radio button "Bridged: Connected directly to the physical network".
  4. Start Up PENTEST-WXP
    • Instructions:
      1. Click Play virtual machine
     
  5. Send Ctrl+Alt+Del
    • Instructions:
      1. Click Player
      2. Click Send Ctrl+Alt+Del
  6. Logging into PENTEST-WXP
    • Instructions:
      1. Username: administrator
      2. Password: Supply your password
  7. Open a Command Prompt
    • Instructions:
      1. Start --> All Programs --> Accessories --> Command Prompt
  8. Determine IP Address
    • Instructions:
      1. ipconfig
    • Note(FYI):
      • My IP Address is 192.168.1.111.  Your IP Address will probably be different.
Section 2: Download Firefox
  1. Start Internet Explorer
    • Note(FYI):
      • If you already have Firefox installed, then skip Section 2 and continue to Section 3.
    • Instructions:
      1. Start --> All Programs --> Internet Explorer
  2. Navigate to Firefox
    • Instructions:
      1. Place http://www.mozilla.org/en-US/firefox/new/ into the Address Bar
      2. Click on Firefox Free Download
  3. Possible Blocked Download Message
    • Instructions:
      1. Click on the banner "To help protect your security".
      2. Click on Download File...
  4. Start Installation
    • Instructions:
      1. Click Run
  5. Run this software
    • Instructions:
      1. Click Run
  6. Mozilla Firefox Setup
    • Instructions:
      1. Click Next
  7. Mozilla Firefox Setup Type
    • Instructions:
      1. Select Standard
      2. Click the Next Button
  8. Mozilla Firefox Setup Summary
    • Instructions:
      1. Select Firefox as default web browser
      2. Click the Install Button
  9. Launch Firefox now
    • Instructions:
      1. Check the "Launch Firefox now" checkbox
      2. Click the Finish Button
  10. Import Settings and Data
    • Instructions:
      1. Select the "Microsoft Internet Explorer" radio button
      2. Click the Next Button
  11. Home Page Selection
    • Instructions:
      1. Select the "Import your home page from Internet Explorer" radio button
      2. Click the Next Button
Section 3: Obtain Nessus Activation Code
  1. Start Up Firefox
    • Instructions:
      1. Start --> All Programs --> Firefox
  2. Open a Command Prompt
    • Instructions:
      1. Place the following URL into Firefox
        • http://www.tenable.com/products/nessus/nessus-homefeed
      2. Supply First Name
      3. Supply Last Name
      4. Supply Email
      5. Click on the "I Agree" Checkbox
      6. Click the Register Button
  3. Thank Your for Registering!
    • Note:
      • Check Your Email Inbox for your registration code.
      • You will need the registration code to complete the Nessus Scanner Installation.

Section 4: Download Nessus
  1. Navigate to Download Agreement
    • Instructions:
      1. Place the below URL in the address bar.
        • http://www.tenable.com/products/nessus/nessus-download-agreement
      2. Click on the Agree Button
  2. Select Download File
    • Instructions:
      1. Click on the Microsoft Windows Twistie
      2. Click on either the 32 bit or 64 bit version of the Nessus Scanner
      3. Click the Save File Button
  3. Open the Nessus msi file
    • Instructions:
      1. Right Click on the Nessus msi file
      2. Click on Open
  4. Open Executable File?
    • Instructions:
      1. Click the OK button.
  5. Open Fire - Security Warning
    • Instructions:
      1. Click the Run Button
  6. Tenable Nessus - InstallShield Wizard
    • Instructions:
      1. Click the Next Button
  7. Tenable Nessus Software License Agreement
    • Instructions:
      1. Click the radio button "I accept the terms in the license agreement"
      2. Click the Next Button.
  8. Install Tenable Nessus to:
    • Instructions:
      1. Click the Next Button
  9. Please select a setup type
    • Instructions:
      1. Click the radio button "Complete"
      2. Click the Next Button
  10. Ready to Install the Program
    • Instructions:
      1. Click the Install Button
  11. InstallShield Wizard Completed
    • Instructions:
      1. Click the Finish Button
  12. Welcome to Nessus!
    • Instructions:
      1. Click the here link (See Below)
  13. Untrusted Connection Message
    • Instructions:
      1. Click on "I Understand the Risks"
      2. Click on the Add Exception Button
  14. Add Security Exception
    • Instructions:
      1. Check the "Permanently store this exception" checkbox.
      2. Click on the Confirm Security Exception Button
  15. Getting Started
    • Instructions:
      1. Click on the Get Started Button
  16. Initial Account Setup
    • Instructions:
      1. Login: admin
      2. Password: Input a Password.
      3. Confirm Password: Input the same Password
      4. Click the Next Button
  17. Registration
    • Instructions:
      1. Provide the Activation Code
      2. Click the Next Button
  18. Download Plugsin
    • Instructions:
      1. Click on the Download Plugins Button
    • Instructions:
      1. The pluggin download takes between 10 and 15 minutes.
      2. Initialization takes between 15 and 25 minutes.
  19. Test Login Credentials
    • Instructions:
      1. Username: admin
      2. Password: Supply your password
      3. Click the Sign In To Continue Button
  20. Sign Out
    • Instructions:
      1. Click the Sign Out Button
Section 5:  Create Nessus Desktop Icon
  1. Create Nessus Decktop Icon
    • Instructions:
      1. All Programs --> Tenable Network Security --> Nessus --> Nessus Web Click (Right Click)
      2. Send To --> Desktop (create shortcut)
  2. Nessus Web Client
    • Note(FYI):
      • On your desktop you should see an icon called "Nessus Web Client" (See Below)

Section 6:  Proof of Lab
  1. Start the Nessus Web Client
    • Instructions:
      1. Click on the Nessus Web Client located on the desktop
  1. Open a Command Prompt
    • Instructions:
      1. Start --> All Programs --> Accessories --> Command Prompt
  2. Proof of Lab Instructions
    • Instructions:
      1. netstat -nao | findstr 8834
      2. date /t
      3. echo "Your Name"
        • Replace the string "Your Name" with your actual name.
        • e.g., echo "John Gray"
      4. Do a PrtScn
      5. Paste into a word document
      6. Upload to website Www.AnToanThongTin.Edu.Vn

Bài đăng phổ biến từ blog này

Pentest lab - Metasploitable 2

Today I will walk through different ways of exploiting Metasploitable 2, the newer release of Rapid7’s popular vulnerable machine. First, what is Metasploitable? Metasploitable is an intentionally vulnerable Linux virtual machine. This VM can be used to conduct security training, test security tools, and practice common penetration testing techniques. In my lab environment, the IP of the attacker machine is 192.168.127.159, and the victim machine is 192.168.127.154. Since this is a test lab, I won’t be concerned about stealth. Instead, I will try to get the most information out of the scans. Let’s start by port scanning the target with nmap. I did a full port, aggresive scan against the target. Here are the results. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 ...

Metasploitable 2 vulnerability assessment

A vulnerability assessment is a crucial part in every penetration test and is the process of identifying and assessing vulnerabilities on a target system. In this part of the tutorial we will be assessing the vulnerabilities available on the network side of the Metasploitable 2 virtual machine. We will be assessing the web applications on the Metasploitable 2 machine in a later tutorial. In the previous Metasploit enumeration and fingerprinting tutorial we’ve learned that the Metasploitable 2 machine contains a lot of vulnerabilities. We have collected valuable information about the target system which we will be using to find known vulnerabilities both on- and offline. Exploitation of these vulnerabilities will be demonstrated in the next exploitation tutorial. In this tutorial we will be looking at a few different ways to perform vulnerability analysis. We will be manually searching for exploits, use scanning tools like Nmap with scripts and we will be...

CEH v9 (CEHVIETNAM.COM) - Hacking Metasploitable Lab

CEH v9 : Hacking Metasploitable VM In this guide, I will demonstrate how to root a Metasploitable 2 virtual machine. Metasploitable is an intentionally vulnerable Ubuntu machine. I’ll explore just a few of the many ways Metasploitable can be attacked, from vulnerabilities in common services to little known exploits and web vulnerabilities. I’ve set up Kali Linux and Metasploitable VMs in VirtualBox on the same network (bridged mode). Kali – 192.168.56.101 Metasploitable – 192.168.56.102 - Hãy thay IP của bạn cho thích hợp Contents   1 Footprinting 1.1 Ping 1.2 Traceroute 2 Scanning 2.1 Port Scanning 2.2 OS Fingerprinting 2.2.1 nmap 2.2.2 xprobe2 3 Enumeration 3.1 FTP (TCP 21) Enumeration 3.2 Telnet (TCP 53) Enumeration 3.3 SMTP (TCP 25) Enumeration 3.4 VNC (TCP 5900) Enumeration 3.5 X11 (TCP 6000) Enumeration 3.6 RLogin (TCP 513) Enumeration 3.7 IRC (TCP 6667) Enumeration 4 Exploitation 4.1 FTP Exploit 4.2 VNC Password Cracking 4.3 IRC E...