Module 05: Vulnerability Analysis
Vulnerability Analysis Using Nessus
[Link]
Username: admin / Password: password
Create a new policy
Policy Templates > Advanced Scan
Settings section, select Host Discovery from the DISCOVERY drop-down list.
Turn off Ping the remote host option (toggle the blue switch to left).
Select Port Scanning and check the Verify open TCP ports found by local port
enumerators option.
Setting section, select ADVANCED The Policy General Settings window with
Advanced Setting Type appears. Set the values of Max number of TCP sessions per
host and Max number of TCP sessions per scan as unlimited.
Create a new scan with new policy.
Schedule settings > turn off the Enabled switch, select Launch from the drop-
down list to start the scan.
CGI Scanning with Nikto
Nikto is not a stealthy tool, it scans a webserver in the shortest time but
will get logged in an IDS/IPS.
nikto -h
nikto -H
nikto -h [Link] -Tuning 1