Penetration Testing mailing list archives
Re: Vulnerability Assessment
From: Pete Herzog <lists () isecom org>
Date: Tue, 24 Jul 2007 13:35:38 +0200
Hi,Just a thought but why? Why do you want a vulnerability scanning tool? You never said. How can we help you if you don't tell us why you need it. If you asked us to help you chose between 2 cars, we couldn't tell you which to buy unless you told us why you think you need a car and how it will be used. So I'll give it a shot here:
If you say that you need to keep up on vulnerabilities than you're going in the wrong direction because they are not that current and you can forget about verifying against rumored 0days.
If you say you want to verify if the vulnerability is real then you're going in the wrong direction because they don't usually exploit.
If you say you want to spend a lot of money to make sure that you can check a whole backlog list of vulnerabilities against various services without having to think at all but think you can use it to cover your ass to management then you're right on and get the one that tickles your fancy (yay, I NEVER get to use that phrase anymore!).
There are easier ways and cheaper ways to do vuln management but they all require you to do the analysis (not the exploiting). Which means know what you have and compare it to new exploits that come out. It can even be automated. When in doubt, you can use a verifying tool like Metasploit or one of the commercial ones like from Core Security. Classes like the OPSA or OPST can go a long way to help you out here too.
Sincerely, -pete. jfvanmeter () comcast net wrote:
My two shiny centvos --- I would use Nessus, its free, there is a port to Windows, you can write you own plugins, I've seen tenable fix fail postives in a day, if you want to pay for the plug in feed its only 1200 dollars US. if you pay for the plugin feed you can use the compliance checks, Tenable has pre configured checks you can download or you can write them yourself.check it out, www.nessus.orgI'm not a employee of Tenable Security, I've tried all of the others... Foundscan, retina, ISS, Satan, Saint, etc and I still personnel like Nessus. -------------- Original message ----------------------From: "Deepak Parashar" <deep231982 () gmail com>
------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
Current thread:
- Re: Vulnerability Assessment Mondai Ji (Jul 23)
- <Possible follow-ups>
- Re: Vulnerability Assessment Colin Grady (Jul 23)
- Re: Vulnerability Assessment Danux (Jul 23)
- Re: Vulnerability Assessment Kish Pent (Jul 25)
- Re: Vulnerability Assessment Danux (Jul 23)
- Re: Vulnerability Assessment Deepak Parashar (Jul 23)
- Re: Vulnerability Assessment US Infosec (Jul 24)
- Re: Vulnerability Assessment jfvanmeter (Jul 24)
- Re: Vulnerability Assessment Pete Herzog (Jul 24)
- RE: Vulnerability Assessment Uzair Hashmi (Jul 25)
- Re: Vulnerability Assessment US Infosec (Jul 27)
- Re: Vulnerability Assessment Tima Soni (Jul 31)
- Re: Vulnerability Assessment Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (Jul 31)
- Re: Vulnerability Assessment Pete Herzog (Jul 25)
- Re: Vulnerability Assessment Pete Herzog (Jul 25)