Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Nessus-Users
[Top] [All Lists]

Re: Nessus and networking equipment

Subject: Re: Nessus and networking equipment
Date: Wed, 26 Sep 2007 08:27:07 -0700
I would strongly suggest, based on experience with Nessus, of starting 
your scanning process by sticking with just network equipment, a few 
devices at a time, and ensuring no reboots/hangs other issues occurred. As 
ron said, you'll find more missing patches/firmware updates than you 
realized.  Get all your network devices happy with the scanning process by 
ensuring they experience no outages/reboots.  That will ensure that the 
rest of your scan results are reliable as well.  (part of that selection 
process is ensuring that if you're scanning multiple network devices at 
once, that an outage/reboot of one, won't affect the scan results of 
another -- easily resolved by limiting things to 1 host at a time if 
feasible, until you know how your network devices will respond)

The next step is working with the network team to ensure you scan devices 
right after they do any firmware or config changes, to ensure you keep 
things running smoothly.  This process has worked well for me in my past 
experience with nessus.

Of course, if you have a test environment, starting your scanning there is 
best.  However, it's my experience that sometimes what's in test, and 
what's in production, arent' the same, between versions, firmware, patch 
level, etc....






"Mike Adams" <sobe8503@gmail.com> 
Sent by: nessus-bounces@list.nessus.org
09/26/2007 07:31 AM

To

cc

Subject
Nessus and networking equipment






Hello,
 
I recently just switched from using ISS in windows to Nessus in RHEL.  I 
did a test scan of my network and it caused some major issues with 
connectivity.  Is there anything I should know about in Nessus when it 
comes to networking equipment? 
 
Thanx!
 
Mike_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

GIF image

_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus
<Prev in Thread] Current Thread [Next in Thread>