KALI – How to Install OpenVAS on Kali Debian Linux – The Visual Guide

KALI – How to Install OpenVAS on Kali Debian Linux – The Visual Guide

31/08/2013

OpenVAS is an alternative to the Nessus scanner.

Step 1 – Download the Plugins for OpenVAS

Applications > Kali > Vulnerability Analysis

OpenVAS > Initial Setup

OpenVAS will now download all the plugins required (a few minutes)

openvas1 plugins

The default user id is admin.

Enter a password.

******

Step 2 – Iceweasel Local Host – Port 9392

Iceweasel

https://127.0.0.1:9392

or

https://localhost:9392

I Understand the risks

openvas2 port 9392

Confirm Security Exception

openvas3 add security exceptionNote:

If you can’t connect under local host, then go

Edit > Preferences

Advanced Tab

View Certificates

advanced preferences

Look for the OpenVAS self signed certificate and delete it.  Then go through adding the exception for Openvas 9392.

******

Step 3 – OpenVAS Login Box

openvas4 greenbone login screenDefault username = admin

Password (whatever you entered during setup)

******

OpenVAS Security Assistant screen (Hermione Granger wizard appears)

openvas5 security asst screen******

Step 4 – Update your Vulnerability Database Feeds

Administration > NVT Feed > Synchronise with Feed Now

nvt feedThis step is critical.  if you do not update the vulnerability database feeds, it will generate errors later on.

Administration > NVT Feed

Administration  > SCAP Database Feed (these are xml files for the reports)

Administration > Cert Feed

*******

Add Users

Administration > Users

Add Users

add users

*******

Step 5 – Set Targets to Scan

Configuration > Targets

Localhost will be there by default.

Add your router as a target eg 192.168.1.1 or 192.168.1.254

configure targets

Look for the Blue box with a White star – click the  star

White star = New Target

star

Viola…

new targetEnter IP of Router, and port options (eg all TCP)

Create Target Button

router scanscan set

*****

Step 6 – Create a Task

Scan Management >  New Task

new task

Home Router scan

Create Task Button

Scan Config = Full and Fast

new task completed

NEW STATUS (Green)

tasks set

Green Arrow to Run this new task

actions

******

Step 7 – To watch LIVE

Set No Refresh dropdown box – to 30 seconds

refresh*****

Errors & Solutions

1. Kali > Vulnerability Analysis > OpenVAS > OpenVAS Check Setup  = may report what’s wrong and how to fix it.

2. Login failed. OMP service is down. (Not enough in NVT Feed)

Administration > NVT Feed

openvasmd –rebuild

openvasmd –update

openvasmd –migrate

******

KALI – How to install NESSUS on Kali – The Visual Guide

http://uwnthesis.wordpress.com/2013/07/31/kali-how-to-install-nessus-on-kali/

*****

KALI – How to easily install FLASH, JAVA, NAUTILUS, METASPLOIT, ETTERCAP & OPENVAS- LAZY KALI SCRIPT – The Visual Guide

http://uwnthesis.wordpress.com/2013/07/31/kali-how-to-easily-update-kali-lazy-kali-script/

*****

KALI – How to use SQLMAP for SQL Injection, to find Admin Password

https://uwnthesis.wordpress.com/2014/02/01/kali-linux-how-to-hack-use-sqlmap-for-auto-sql-injection-find-website-admin-password/

Ethtool Command to Increase/ Decrease speed of Network card in Linux

http://www.systempandit.com/ethtool-command-to-increase-decrease-speed-of-network-card-in-linux/

Cheops-ng A Network Management Tool

http://rasmoodi.persiangig.com/SoftWare/cheops-ng-0.2.3.tgz

swf intruder

http://rasmoodi.persiangig.com/SoftWare/swfintruder-0.9.1.tgz

sec tool market

http://sectoolmarket.com



Rank
#
LogoVulnerability ScannerVersionVendorDetection AccuracyChart
1
IronWASP0.9.1.0Lavakumar Kuppan100.00% Detection Rate
0.00% False Positives
(108/108)
(0/6)
2
WebInspect9.20.277.0HP Application Security Center61.11% Detection Rate
0.00% False Positives
(66/108)
(0/6)
3
Wapiti2.2.1OWASP57.41% Detection Rate
0.00% False Positives
(62/108)
(0/6)
4
Acunetix WVS (Commercial Edition)8.0Acunetix44.44% Detection Rate
0.00% False Positives
(48/108)
(0/6)
4
arachni0.4.0.3Tasos Laskos44.44% Detection Rate
0.00% False Positives
(48/108)
(0/6)
4
Netsparker (Commercial Edition)2.1.0Mavituna Security44.44% Detection Rate
0.00% False Positives
(48/108)
(0/6)
4
Syhunt Dynamic (Sandcat Pro)4.5.0.0Syhunt44.44% Detection Rate
0.00% False Positives
(48/108)
(0/6)
4
Syhunt Mini (Sandcat Mini)4.4.3.0Syhunt44.44% Detection Rate
0.00% False Positives
(48/108)
(0/6)
5
SkipFish2.07Michal Zalewski - Google44.44% Detection Rate
16.67% False Positives
(48/108)
(1/6)
6
Ammonite1.2RyscCorp.44.44% Detection Rate
33.33% False Positives
(48/108)
(2/6)
7
Vega1.0Subgraph33.33% Detection Rate
0.00% False Positives
(36/108)
(0/6)
8
JSky (Commercial Edition)3.5.1NoSec22.22% Detection Rate
0.00% False Positives
(24/108)
(0/6)
9
W3AF1.2W3AF developers11.11% Detection Rate
16.67% False Positives
(12/108)
(1/6)

Ten things we(GOOGLE) know to be true

Focus on the user and all else will follow.

It’s best to do one thing really, really well.

Fast is better than slow.

Democracy on the web works.

You don’t need to be at your desk to need an answer.

You can make money without doing evil.

There’s always more information out there.

The need for information crosses all borders.

You can be serious without a suit.

Great just isn’t good enough.

جایزه برای آسیب پذیریهای گوگل

http://www.google.com/about/appsecurity/reward-program

owasp

https://www.youtube.com/playlist?list=PLpr-xdpM8wG8ODR2zWs06JkMmlRiLyBXU

https://www.its.fh-muenster.de/owasp-appseceu13/rooms/Aussichtsreich_+_Freiraum/medium_quality_iProd/

http://owasp.blogspot.co.uk/

bizim yerler

39.243205,47.186558 yozgooyoo

yaralja 38.73387,46.883807

TOOLS

satan security administrator tool for analyzing networks   SATAN http://www.porcupine.org/satan

Microsoft Baseline Security Analyzer  http://www.microsoft.com/en-us/download/details.aspx?id=7558