当前位置:网站首页>[kali-vulnerability scanning] (2.1) Nessus lifts IP restrictions, scans quickly without results, and plugins are deleted (middle)
[kali-vulnerability scanning] (2.1) Nessus lifts IP restrictions, scans quickly without results, and plugins are deleted (middle)
2022-08-03 21:13:00 【The Black Zone (Rise)】
目录
三、Scanning is fast with no results
一、解除IP限制
1.1、识别版本号
在浏览器中输入
https://plugins.nessus.org/v2/plugins.php
1.2、修改配置文件
修改 plugin_feed_info.inc 文件
sudo find /opt -name plugin_feed_info.inc
看不见,就用root打开
If it doesn't exist, create a new oneplugin_feed_info.inc
并将内容改为
(Replace the original file if any/opt/nessus/lib/nessus/plugin_feed_info.inc)
PLUGIN_SET = "202208020542"; PLUGIN_FEED = "ProfessionalFeed (Direct)"; PLUGIN_FEED_TRANSPORT = "Tenable Network Security Lightning";
将 /opt/nessus/lib/nessus/plugins/plugin_feed_info.inc 文件删除
(Or replace this one too)
rm -rf /opt/nessus/lib/nessus/plugins/plugin_feed_info.inc
1.3、重启服务
重启nessus服务
sudo service nessusd restart
1.4、访问
浏览器访问nessus(https://localhost:8843)
等待nessus初始化插件
设置页面显示 unlimited,则解除IP限制
二、Resolve plugin was removed
2.1、分析
Nessus服务每次重启后,都会重置plugin_feed_info.inc,会使nessus/plugins目录下所有的插件都被删除,无法扫描
2.2、方法一:
Manually update the plugin package every time
pluginsThe content of the file can be obtained by updating the plugin again(Take advantage of that plugin package we got)
2.3、方法二:
先停止nessus服务,将nessus服务设置为手动
sudo systemctl disable nessusd sudo service nessusd stop
It's the same operation after every reset,重新配置
Can be written as batch processing
sudo vim crack_nessus.sh
service nessusd stop; cp /root/plugin_feed_info.inc /opt/nessus/var/nessus/; rm -rf /opt/nessus/lib/nessus/plugins/plugin_feed_info.inc; service nessusd start;
将crack_nessus.shWritten in the system startup script
每次重启,Release will be performed automaticallyIP限制
sudo chmod +x /etc/rc.d/rc.local sudo vim /etc/rc.d/rc.local
添加如下内容到rc.local
/bin/bash /root/crack_nessus.sh
nessus解除IP限制
三、Scanning is fast with no results
3.1、分析
When creating a new scan item,很快就结束,无扫描结果
查看plugins目录内容是否被删除
sudo du -h /opt/nessus/lib/nessus/plugins
Generally check the file size
3.2、恢复
使用备份(The premise is that it is backed upplugins目录)
service nessusd stop; rm -rf /opt/nessus/lib/nessus/plugins cp -r ./plugins /opt/nessus/lib/nessus/ cp /root/plugin_feed_info.inc /opt/nessus/var/nessus/; rm -rf /opt/nessus/lib/nessus/plugins/plugin_feed_info.inc; service nessusd start;
然后打开浏览器,访问nessus(https://localhost:8843)
等待更新完成
边栏推荐
- 剑指 Offer 16. 数值的整数次方
- 安全基础8 ---XSS
- D - Project Planning--二分
- ValidationError: Progress Plugin Invalid Options
- 从开发到软件测试:除了扎实的测试基础,还有哪些必须掌握 ?
- 尚医通项目总结
- 不专业面试官的经验总结
- 15 years experience in software architect summary: in the field of ML, tread beginners, five hole
- 卷起来!阿里高工携 18 位高级架构师耗时 57 天整合的 1658 页面试总结
- 华为设备VRRP配置命令
猜你喜欢
随机推荐
15年软件架构师经验总结:在ML领域,初学者踩过的五个坑
独立站卖家在哪些平台做社交媒体营销效果最好?
if _name_ == “__main__“:NameError: name ‘_name_‘ is not defined
基于data.table的tidyverse?
AI首席架构师13-AICA-智能文档分析技术在行业场景中的应用
chart.js多条曲线图插件
简单又有效的基本折线图制作方法
A. Color the Picture- Codeforces Round #810 (Div. 1)
LitJson报错记录
Orcad Capture Cadence 新建原理图多部分smybol和Homogeneous、Heterogeneous类型介绍教程
Often forget HiFlow 】 【 check-in?Use tencent cloud scenario connector to remind you every day.
反射机制
From September 1st, my country has granted zero-tariff treatment to 98% of tax items from 16 countries including Togo
NAACL 2022 | 具有元重加权的鲁棒自增强命名实体识别技术
B. Paranoid String
XSS practice - cycle and two cycle problem at a time
分分钟教你读取 resources 目录下的文件路径
《富爸爸,穷爸爸》思维导图和学习笔记
2021年数据泄露成本报告解读
chartjs自定义柱状图插件