Home > Security Channel All-in-One Guides > Open Source Security Software > Nessus > Nessus can spot some monster security problems
All-in-One Guides: Open Source Security Software:
EMAIL THIS
 START   VAR CONSIDERATIONS   SNORT   NESSUS   NMAP   OTHER TOOLS   
Nessus

<< PREVIOUS | NEXT >>
 TIPS & NEWSLETTERS TOPICS 

SCOTT SIDEL'S DOWNLOADS

Nessus can spot some monster security problems


Scott Sidel
10.20.2006
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


More security tools

Visit our resource center for news, tips and expert advice on the latest open source tools.

Check out our Information Security IT Downloads section and review other freeware tools.
Each month, the editor of our downloads section recommends the security freeware that he finds most valuable. This week, Scott Sidel reviews the benefits of Nessus.
If I were stranded on a desert island and I could bring along only one security tool, I would take Nessus. Why? Well, with Nessus, I could keep my network gear -- made of coconuts, of course -- safe and secure. Nessus is perhaps the most comprehensive vulnerability scanner available.

Nessus' features
Nessus checks local and remote hosts for flaws, probes other machines' ports and services, and analyzes the responses for insecure configurations, missing patches and a host of other security issues that can lead to a really bad day for a security manager.

It is available in both free and fee-based iterations; it's free for those who don't mind seven-day-old vulnerability signatures. Otherwise, it costs $1,200 annually for fresh, daily signatures.

I like to use Nessus for black box and white box testing. For a black box test, seeing what a hacker sees when scoping out your perimeter, you can use Nessus outside on your network or from a subnet with no special trusts. When I use Nessus to white box test, I provide SSH credentials to log into the remote systems and determine which patches need to be applied. Nessus will log into the remote host, extract the list of installed software and tell you which packages require updates.

Nessus can also be used to audit how remote systems (including Windows) are configured, and report which systems are compliant (or not) with a user-definable security policy. Even without a defined security policy, you can see how well the configuration management team is performing. For instance, if hosts of an identical type (webhost01 and webhost02) show that one host has a vulnerability but its twin is vulnerability-free, it's an indication that the hosts are not being configured or maintained identically.

About the Author:
Scott Sidel is an ISSO with Lockheed Martin.

Read Sidel's previous edition: Logwatch: Taking the pain out of log analysis.

Can't wait for next month's installment? Check out SearchSecurity.com's Information Security IT Downloads section, and learn what other valuable security freeware solutions are available.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Application and Platform Security,   Open Source Security Tools and Applications,   Scott Sidel's Downloads,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>
VIEW ALL IN THIS CATEGORY


RELATED CONTENT
Open Source Security Tools and Applications
Screencast: Find rogue wireless acess points with Vistumbler
Screencasts: On-screen demonstrations of security tools
H.D. Moore on future of Metasploit attack platform
H.D. Moore speaks about Metasploit Project deal, Release 3.3
Screencast: How to launch an OpenVAS scan
Could Metasploit popularity erode?
Metasploit Project acquired by vulnerability management firm Rapid7
SSH key compromise shuts down Apache website
Screencast: Smoothwall offers firewall defense in lean times
Screencast: Samurai offers pen-testing nirvana

Scott Sidel's Downloads
Use BotHunter for botnet detection
Review system event logs with Splunk
FISMA compliance made easier with OpenFISMA
Ophcrack: Password cracking made easy
Enigmail: Wrapping email in a digital security blanket
Secure file copying with WinSCP
FreeRADIUS: Acing a secure connection
Spiceworks: Free network monitoring and management with a little zest
VirusTotal: On-demand antivirus service scans malicious files
Shining a spotlight on rootkits

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Blowfish  (SearchSecurity.com)
Kermit  (SearchSecurity.com)
Open Source Hardening Project  (SearchSecurity.com)
SnortSnarf  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts