pen-test
[Top] [All Lists]

Re: Question about vulnerability scanning

To: <Andy.Kitzke@insinkerator.com>, <pen-test@securityfocus.com>
Subject: Re: Question about vulnerability scanning
From: "Utmost Bastard" <utmostbastard@gmail.com>
Date: Wed, 23 May 2007 21:04:00 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:from:to:references:subject:date:mime-version:content-type:content-transfer-encoding:x-priority:x-msmail-priority:x-mailer:x-mimeole; b=cCgyNAq5DfzaOqWdf5SkRZ5Ch1p45DTkfLqzijb0Rt8ifvhIE6/YOwCP4ePRLyxVVOLwXWsESMVthrYnODd0MChsW10qNbWlteWcqtmzxfnaylP3NHYy0sDdd6HlUK74gN96gwtpDFecNpkIKW9x4ljkx7m1ooEZyskiCNSDlCc=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:from:to:references:subject:date:mime-version:content-type:content-transfer-encoding:x-priority:x-msmail-priority:x-mailer:x-mimeole; b=aRz0KwXtGP3uK/Xwm8kXekaOzkEaYRnx2eN9kZvpqE/fCo5stcre+8vraVFcOXafmDmwPN68/s8Mlvb8f9SqlsS8xQ9Hs9THblLtsYbDxNrRRlHNbdF3e9mcVrFC+EB88M6B1g4htd1rG0BkT0EB63g2GEWUPbqXCQtEPp2eZfQ=
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <20070523184831.14076.qmail@securityfocus.com>
Resent-date: Wed, 23 May 2007 18:56:57 -0600 (MDT)
Resent-from: pen-test-return-1078484235@securityfocus.com
Resent-message-id: <20070524005657.E537B1438C0@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
For free (and over most commercial scanners too) nothing in my eyes beats Nessus.

Just add SMB credentials for the scan to have admin rights to the workstations/servers in question.

Google away for Nessus documentation.

I also prefer the output of the Java client NessJ.

That is my two cents on the subject.

UB
----- Original Message ----- From: <Andy.Kitzke@insinkerator.com>
To: <pen-test@securityfocus.com>
Sent: Wednesday, May 23, 2007 2:48 PM
Subject: Question about vulnerability scanning


I had a question and was looking for some information pertaining to it. I have no doubt that this has been covered in the past, but I can't find any emails with it right now.


I'm looking for a good vulnerability scanner that I can run from a single workstation/server. I would like somewhat detailed reports about what patches are missing and if Anti-Virus is installed. I know there are many solutions out that can be purchased but I'm wondering what free solutions exist and how well they stand up to paid for solutions.


If anyone has any information on or white papers about any solutions let me know.


Thanks!

Andy

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>