当前位置:网站首页>渗透测试 ( 7 ) --- 漏洞扫描工具 Nessus
渗透测试 ( 7 ) --- 漏洞扫描工具 Nessus
2022-07-06 09:27:00 【擒贼先擒王】
Nessus 官网:https://www.tenable.com/products/nessus/nessus-professional
下载 nusses:https://www.tenable.com/downloads/nessus?loginAttempted=true
1、Nessus 简介、下载、安装
简 介
Nessus 是世界上很流行的漏洞扫描程序,全世界很多组织都有在使用它。该工具提供完整的电脑漏洞扫描服务,并随时更新其漏洞数据库。Nessus 不同于传统的漏洞扫描软件,Nessus 可同时在本机或远端上遥控,进行系统的漏洞分析扫描
Nessus Pro10.1.2 配合20220328最新版本插件:https://www.iculture.cc/software/pig=12467
下载、安装
Linux 安装:
安装:dpkg -i Nessus.deb
启动:systemctl start nessusd.service
浏览器访问:https://127.0.0.1:8834
Windows 安装:
下载 Nessus 解压后直接安装,浏览器访问:https://127.0.0.1:8834





下载 Nessus pro 插件并更新
Linux 执行命令:sudo /opt/nessus/sbin/nessuscli update all-2.0.tar.gz
Windows 执行命令:

重启 Nessus 服务
/bin/systemctl start nessusd.service进行 插件配置
Linux:sudo vi /opt/nessus/var/nessus/plugin_feed_info.inc
Windows:
添加内容:
PLUGIN_SET = "202203282143";
PLUGIN_FEED = "ProfessionalFeed (Direct)";
PLUGIN_FEED_TRANSPORT = "Tenable Network Security Lightning";

关闭 Nessus 服务.,再重启 Nessus 服务。
然后在重新访问: https://127.0.0.1:8834




kali 安装 nessus
:https://zhuanlan.zhihu.com/p/338454648
下载对应版本的 nusses:https://www.tenable.com/downloads/nessus?loginAttempted=true
进入下载目录:sodu dpkg -i Nessus-10.1.1-debian6_amd64.deb
按照提示先启动服务 /bin/systemctl start nessusd.service
# 从deb 安装包安装Nessus
sudo dpkg -i Nessus-8.10.0-debian6_amd64.deb# 启动nessus
sudo /etc/init.d/nessusd start# 访问nessu web ui ,通过以下途径设置账号密码
http://localhost:8834
Managed Scanner ---> Tenable.sc ---> [root:root]# 升级插件包
sudo /opt/nessus/sbin/nessuscli update all-2.0.tar.gz# 提取文件
sudo tar -zxvf all-2.0.tar.gz plugin_feed_info.inc
sudo vim plugin_feed_info.inc
cat plugin_feed_info.inc
PLUGIN_SET = "202004162028";
PLUGIN_FEED = "ProfessionalFeed (Direct)";
PLUGIN_FEED_TRANSPORT = "Tenable Network Security Lightning";# 移动文件
sudo cp plugin_feed_info.inc /opt/nessus/var/nessus/
sudo cp plugin_feed_info.inc /opt/nessus/lib/nessus/plugins/# 重启nessus
sudo /etc/init.d/nessusd stop
sudo /etc/init.d/nessusd start

边栏推荐
- Learning record: Tim - Basic timer
- Research Report of pharmaceutical solvent industry - market status analysis and development prospect prediction
- MATLAB实例:阶跃函数的两种表达方式
- Opencv learning log 18 Canny operator
- Research Report on medical anesthesia machine industry - market status analysis and development prospect prediction
- Opencv learning log 15 count the number of solder joints and output
- JS --- detailed explanation of JS facing objects (VI)
- Opencv learning log 14 - count the number of coins in the picture (regardless of overlap)
- 【练习-7】(Uva 10976)Fractions Again?!(分数拆分)
- Cost accounting [20]
猜你喜欢

JS --- detailed explanation of JS DOM (IV)

学习记录:使用STM32外部输入中断

学习记录:TIM—基本定时器

ucorelab3

UCORE Lab 1 system software startup process

信息安全-威胁检测引擎-常见规则引擎底座性能比较

C语言数组的概念

STM32 learning record: play with keys to control buzzer and led

Learning record: STM32F103 clock system overview working principle

JS --- BOM details of JS (V)
随机推荐
毕业才知道IT专业大学生毕业前必做的1010件事
C 基本语法
Matlab comprehensive exercise: application in signal and system
Research Report of cylindrical grinder industry - market status analysis and development prospect forecast
Learning record: use STM32 external input interrupt
初入Redis
C语言学习笔记
China's salt water membrane market trend report, technological innovation and market forecast
JS --- detailed explanation of JS DOM (IV)
Learning record: how to perform PWM output
【练习-7】(Uva 10976)Fractions Again?!(分数拆分)
China earth moving machinery market trend report, technical dynamic innovation and market forecast
入门C语言基础问答
【高老师软件需求分析】20级云班课习题答案合集
STM32 learning record: LED light flashes (register version)
STM32 learning record: play with keys to control buzzer and led
STM32学习记录:LED灯闪烁(寄存器版)
C语言数组的概念
Cost accounting [22]
China's earthwork tire market trend report, technical dynamic innovation and market forecast