Factbites
 Where results make sense
About us   |   Why use us?   |   Reviews   |   PR   |   Contact us  

Topic: Nessus


Related Topics

In the News (Thu 10 Dec 09)

  
  Planet Waves | Nessus Notes by Eric Francis
Nessus is about power dynamics and the dynamics of abuse, very important themes today in the western world, as we discover we were all abused as kids (and I mean it).
Nessus can be used to investigate the lives of our parents and their relationships to others in the family.
Nessus is like Chiron, only you can add a lot of psychological dynamics, abuse dynamics, and what Melanie Reinhart describes as "the bottom line." Nessus is reminding us of what an abusive world we live in, and now we have something we can do about it.
www.planetwaves.net /contents/nessus_notes.html   (3230 words)

  
 Tenable discusses the Nessus 3 release
Nessus 3 will be free of charge for end users or service providers or consultants to do whatever they want with it, except put it into a product or re-brand it as their own software.
Nessus has it's own language for vulnerability checks named NASL and this is something easily picked up by the average use, even non-coders.
Unfortunately, aside from a few public Nessus 2 forks, most of the forks we are tracking or are aware of are by commercial groups who want to start with Nessus 2 to develop commercial scanner, a network monitoring tool or some other function.
www.securityfocus.com /print/columnists/371   (2771 words)

  
 SecurityDocs: Comment on Introduction to Nessus Tutorial
Nessus is released under the GPL and is designed to automate the testing and discovery of known security problems.
Nessus 2.1 is the only security scanner that has the ability to detect the remote flaws of the hosts on your network, but their local flaws and missing patches as well - whether they are running Windows, Mac OS X or a Unix-like system.
Nessus is the first scanner on the market to have implemented this feature for all the security checks (and has been copied by many since then).
www.securitydocs.com /library/2730   (1832 words)

  
 NESSUS - Graphical User Interface
NESSUS 8.2.0 is supported by a graphical user interface that assists the user in defining probabilistic problems.
NESSUS includes a graphical fault tree definition screen to support modeling multiple failure modes or multiple components in a system.
NESSUS also supports parameter variation analysis to graphically evaluate how the response varies with changes in the random variable values.
www.nessus.com /gui.shtml   (321 words)

  
 NewsForge | Nessus assesses system vulnerabilities
Nessus is available for both Windows and Unix systems, so you can run vulnerability tests on and from distinct platforms.
The work of Nessus clients comes down to fetching information from this database and performing the actual tests, either on the same host on which the client is installed or other networked devices, and later generating detailed reports on the encountered security holes and possible corrections for them.
Nessus plug-ins are distributed in three feeds that address the requirements for various organizations depending on their needs and budgets.
software.newsforge.com /software/05/02/02/1412203.shtml   (1008 words)

  
 Vulnerability Scanners Nessus
From a personal standpoint I much rather prefer Nessus 2.7 or prior versions as the client and server programs are installed and configured from one install (.sh) script and it seems a whole lot easier to use and customise.
I believe that Nessus is becoming more enterprise, (commercially), orientated and as such is tailoring its product to a centralised server, (nessusd), product with multiple windows and *nix clients able to communicate with it and carry out disparate VA scans within the enterprise.
I will agree that Nessus will not run as fast in VMWare as on a separate host, but if you are running windows and linux tools from the same box at the same time, the time trade-off in my mind is definitely worth it.
www.vulnerabilityassessment.co.uk /NESSUS.htm   (864 words)

  
 NESSUS - What's New
NESSUS 8.3 was finalized in December 2005 and released in early 2006.
NESSUS 8.2 was released to US government organizations in December 2004 and a general release was made in March 2005.
NESSUS 8.1 was released June 2004.This version includes enhanced random variable mapping capabilities including a replace mapping type.
www.nessus.com /new.shtml   (413 words)

  
 Introduction to Nessus
Nessus is a great tool designed to automate the testing and discovery of known security problems.
Nessus is designed to help identify and solve these known problems, before a hacker takes advantage of them.
Typically after a new vulnerability is released to the public, someone in the Nessus community writes a NASL plug-in, releases it to the public and submits it to www.nessus.org.
www.securityfocus.com /infocus/1741   (2729 words)

  
 Checking Your Work with Scanners, Part II: Nessus | Linux Journal
Nessus has two major parts: a server, which runs all scans, and a client, with which you control scans and view reports.
Nessus' client component, nessus, can be configured to log in either transparently (i.e., with no password associated with your private key) or with a password that protects your private key, thereby preventing unauthorized users from connecting to the Nessus server from your workstation.
Nessus' prerequisites are: Nmap, the port scanner we discussed last month; gtk, the GIMP toolkit, including the packages gtk+, gtk+-devel, glib-devel and XFree86-devel; and the scripting environment m4, or libgmp (whose package is simply called gmp).
www.linuxjournal.com /article/4685   (3466 words)

  
 Nessus PC Magazine - Find Articles   (Site not responding. Last check: 2007-10-13)
We installed Nessus on a workstation running Red Hat Linux 9 and were pleasantly surprised at the ease with which the installation script completed its job—something not too common in the open-source world.
We were then able to launch the Nessus executable file and log on to the X11 user interface without a problem.
Nessus will appeal most to administrators who want not only a comprehensive scanning tool but also an in-depth long-term education in network security vulnerabilities.
findarticles.com /p/articles/mi_zdpcm/is_200312/ai_ziff113551   (561 words)

  
 Introduction to Nessus, a Vulnerability Scanner - The Community's Center for Security
Nessus is a vulnerability scanner which performs scanning a target network to seek for vulnerabilities in the network, such as, software bugs, backdoors, and etc. The program is developed by Renaud Deraison.
In logging in to use Nessus, it is necessary to supply a passphrase which is another, not the one-time password.
Before logging in to use Nessus with an account (joey in the figure), the user needs to supply the IP address where nessusd is running, nessusd's port, and encryption method used in communicating between a client and the server.
www.linuxsecurity.com /content/view/117647   (1825 words)

  
 Nessus   (Site not responding. Last check: 2007-10-13)
These additions to Nessus are currently made available as patches with no extra assistance provided to guide their installation or use.
They are being developed under the current stable release of Nessus: 1.3.0 and have only been tested for generating the reports (use in differential reporting and partial scans is in no way guaranteed).
They are alpha releases to provide the Nessus community with more advanced reporting options as well as a way for me to obtain feedback for further enhancements.
www.rit.edu /~wjh3710/nessus.html   (518 words)

  
 Tenable Network Security   (Site not responding. Last check: 2007-10-13)
The Nessus vulnerability scanner, is the world-leader in active scanners, featuring high speed discovery, asset profiling, and vulnerability analysis of your security posture.
Nessus scanners can be distributed throughout an entire enterprise, inside DMZs, and across physically separate networks.
Nessus is supported by a world renowned research team and has the largest vulnerability knowledge base, making it suitable for even the most complex environments.
www.tenablesecurity.com /products/nessus.shtml   (177 words)

  
 BigAdmin Feature Article: Nessus: An Automated Network-Based Security Scanner
The machine where Nessus is built requires a compiler, lexical parser and analyzer, and GNU m4.
Nessus keeps its own user database so that multiple people can be authorized to use the same nessus server for disparate portions of the network.
Nessus noted that it judged the sendmail version solely by the SMTP banner, and there was also a note specifically about Sun Microsystems, which informed me that Sun doesn't update the SMTP version number with patches, so this hole might be a false positive.
www.sun.com /bigadmin/features/articles/nessus_scanner.html   (2427 words)

  
 Nessus (Centaur, Hercules foe)
Hearing his wife’s screams, Hercules rushed to her rescue with his arrows, which had been dipped in the blood of the Hydra, at the ready and fired upon Nessus.
In his death-throes, Nessus gathered some of his blood tainted by the Hydra and presented it to Deianeira as a love talisman in case Hercules’ eyes should wander to another woman.
On the other hand, Hercules’ memories of Nessus resembling the Hulk, Deianeira as the Scarlet Witch and Jason as Thor (or perhaps a long-haired Captain America) might be subliminal figments of his imagination.
www.marvunapp.com /Appendix/nessuscent.htm   (1421 words)

  
 Nessus security tool closes its source | Tech News on ZDNet   (Site not responding. Last check: 2007-10-13)
Nessus, which Deraison says is used by 75,000 organizations worldwide, scans networks for vulnerabilities.
The programmer is the author of Nmap, a complementary network-scanning tool to Nessus, which is widely used among security professionals.
He raised the possibility that the community could "fork" version 2 of the software--that is, start developing a divergent version of Nessus from the one officially supported by Tenable.
news.zdnet.com /2100-3513_22-5890093.html   (954 words)

  
 O'Reilly Network -- Writing Nessus Plugins   (Site not responding. Last check: 2007-10-13)
Nessus provides an excellent framework in which to write custom vulnerability checks, so there is no need to write scanners from scratch.
Nessus can optimize scans, if you select the appropriate checkbox in the Scan Option tab of the GUI client.
When this option is enabled, Nessus scans for vulnerabilities related to the applications running on the open ports of the target host.
www.onlamp.com /pub/a/security/2004/06/03/nessus_plugins.html   (941 words)

  
 Nessus
Nessus is a remote security scanner that uses a rules based system for scanning remote systems.
Nessus scans everything using small script based plug-ins which makes updating it with the latest vulnerabilities easy.
The best mitigation is to keep your machines up to date with patches, use the best scanner you can afford to find, purchase a security audit from security professionals, improve you and your staff's security knowledge through training and experience, and be sure to fix any weaknesses apparent on your machines.
www.securityinnovation.com /security-report/october/tools/Nessus.htm   (438 words)

  
 ISS X-Force Database: nessus-ftplogin-bo(12059): Nessus ftp_log_in() buffer overflow
Nessus is a freely available broad-spectrum vulnerability assessment tool for Unix and Linux-based systems.
Nessus versions prior to 2.0.6 are vulnerable to a denial of service attack, caused by a buffer overflow in the ftp_log_in() function.
If the 'plugins_upload' option is enabled (the default setting is disabled) and a local attacker has a valid Nessus account, the attacker can pass an overly long 'user' or 'pass' argument to the ftp_log_in() function to cause the Nessus Attack Scripting Language (NASL) script to crash.
xforce.iss.net /xforce/xfdb/12059   (331 words)

  
 Nessus 3.0 :: OSDir.com :: Open Source, Linux News & Software   (Site not responding. Last check: 2007-10-13)
Nessus 3.0 was developed in response to growing market demand from enterprises, government agencies and consultants for a commercially licensed version of Nessus.
Nessus 3.0 users will now have access to a number of commercial support and training options from Tenable Network Security.
Nessus 3.0 is immediately available for download from Tenable at http://www.nessus.org/download.
osdir.com /Article8044.phtml   (562 words)

  
 Nessus 3.0 Closes the Book on Open Source
Tenable Network Security, the firm that sponsors and commercially provides Nessus, has recently released version 3.0 of the vulnerability scanner, the first version of the scanner not to be released under the GPL.
Tenable's Nessus license flip flop has raised the ire of many in the open source community and has even led to a fork of the project that is backed by an influential community based open source organization, Software in the Public Interest (SPI).
The fact that Nessus 3.0 is no longer GPL licensed doesn't present any development issues to Tenable, according to Gula.
www.internetnews.com /dev-news/article.php/3573341   (947 words)

  
 NESSUS - FAQ
The current release of NESSUS is available on Windows NT/2000/XP, HP-UX 11.x, IRIX 6.5, and Solaris 7/8.
No specific patches are known to be required for the Windows NT and derivative operating systems, but it is always recommended to have the latest "Service Packs" from Microsoft installed.
NESSUS has been validated against the 1.3.1 version of Java.
www.nessus.swri.org /faq-install.shtml   (399 words)

  
 O'Reilly -- Safari Books Online - 1931836086 - Nessus Network Auditing
Nessus will do both types and the book details how to do either, or both of them.
The Nessus scripting language is covered in detail in Appendix A instead of the main portion of the book; a choice I appreciated very much as it allowed the flow of the book to not be interrupted by such a highly technical section.
Nessus Network Auditing is a highly recommended book for anyone interested in auditing their network to find potential problems before they become reality.
safari.oreilly.com /1931836086   (1084 words)

  
 Nabble - nessus to PCI
Nessus can be used to help make statements about being compliant with
Nessus can be used in conjunction with 6.1 and 6.2 -- to verify that timely
Nessus has to be placed in the "right spot" and
www.nabble.com /nessus-to-PCI-t90778.html   (1063 words)

  
 Nessus
Before he died, however, Nessus gave Deianira his blood and told her that it would ensure Heracles' love for her for ever.
When she later gave a garment soaked in the centaur's blood to her husband, it poisoned him.
Article "Nessus" created on 16 May 1999; last modified on 16 May 1999 (Revision 1).
www.pantheon.org /articles/n/nessus.html   (98 words)

  
 Evaluate Options as Nessus Becomes Commercialized
However, all enterprises using Nessus need to begin planning for the longer-term consequences of Nessus' commercialization, which will depend largely on how the enterprise obtains the software: through a service provider, bundled with a commercial product, or through any channel that delivers GPL software.
Nessus is embedded in many vulnerability management products, so IT decision-makers must determine whether Nessus is required for any products they use and analyze their providers' relationships with Tenable.
Through a third-party channel using the GPL: If you are using Nessus source code in any way, evaluate open-source vulnerability assessment alternatives (such as the six currently available GPL "forks" of previous Nessus versions, including the Open VAS project).
www.gartner.com /DisplayDocument?doc_cd=136178   (617 words)

  
 Nessus Plugins
The Open Source Nessus scanner supports a plugin architecture that allows anyone to develop security checks in the NASL (Nessus Attack Scripting Language) language.
Because the administrator of Nessus, or others, may modify the source for multiple language support, bugfixes, etc., these files are linked directly to the CVS server on nessus.org.
If you have not yet used Nessus, it is worth the time to check it out, as it beats the commercial scanners hands-down.
www.cirt.net /code/nessus.shtml   (166 words)

  
 oreilly.com -- Online Catalog: Nessus Network Auditing   (Site not responding. Last check: 2007-10-13)
Nessus is the premier Open Source vulnerability assessment tool, and was recently voted the "most popular" open source security tool of any kind.
This is the first book available on Nessus and it is written by the world's premier Nessus developers led by the creator of Nessus, Renaud Deraison.
This book focuses on installing, configuring and optimizing Nessus, which is a remote security scanner for Linux, BSD, Solaris, and other Unices.
www.oreilly.com /catalog/1931836086   (217 words)

Try your search on: Qwika (all wikis)

Factbites
  About us   |   Why use us?   |   Reviews   |   Press   |   Contact us  
Copyright © 2005-2007 www.factbites.com Usage implies agreement with terms.