Book Image

Learning Nessus for Penetration Testing

By : Himanshu Kumar
Book Image

Learning Nessus for Penetration Testing

By: Himanshu Kumar

Overview of this book

<p>IT security is a vast and exciting domain, with vulnerability assessment and penetration testing being the most important and commonly performed security activities across organizations today. The Nessus tool gives the end user the ability to perform these kinds of security tests quickly and effectively.</p> <p>Nessus is a widely used tool for vulnerability assessment, and Learning Nessus for Penetration Testing gives you a comprehensive insight into the use of this tool. This book is a step-by-step guide that will teach you about the various options available in the Nessus vulnerability scanner tool so you can conduct a vulnerability assessment that helps to identify exposures in IT infrastructure quickly and efficiently. This book will also give you an insight into penetration testing and how to conduct compliance checks using Nessus.</p> <p>This book starts off with an introduction to vulnerability assessment and penetration testing before moving on to show you the steps needed to install Nessus on Windows and Linux platforms.</p> <p>Throughout the course of this book, you will learn about the various administrative options available in Nessus such as how to create a new user. You will also learn about important concepts like how to analyze results to remove false positives and criticality. At the end of this book, you will also be introduced to the compliance check feature of Nessus and given an insight into how it is different from regular vulnerability scanning.</p> <p>Learning Nessus for Penetration Testing teaches you everything you need to know about how to perform VA/PT effectively using Nessus to secure your IT infrastructure and to meet compliance requirements in an effective and efficient manner.</p>
Table of Contents (12 chapters)

Summary


In this chapter, we learned to set up Nessus for vulnerability scanning. Scan configuration in Nessus involves two major steps, namely configuration of a scan policy and launching a scan using the configured policy.

Scan prerequisites including deciding on the scope of the scan, getting approval in place, deciding on the scan window, updating plugins, making a backup, having proper network access opened, identifying the point of contact, and deciding on credential or noncredential scanning were also discussed.

Among the prerequisites, the first key step is to set up the scan policy, which will include four default policy templates (external, internal, PCI DSS, and web application). Nessus also offers an option to create a customized policy using the New Policy option.

There are four setting options available while creating a new policy, namely General Settings and Advance settings (including the name of the policy, visibility, port scanning options, scan performance, and safe checks...