当前位置:网站首页>渗透测试 ( 7 ) --- 漏洞扫描工具 Nessus
渗透测试 ( 7 ) --- 漏洞扫描工具 Nessus
2022-07-06 09:27:00 【擒贼先擒王】
Nessus 官网:https://www.tenable.com/products/nessus/nessus-professional
下载 nusses:https://www.tenable.com/downloads/nessus?loginAttempted=true
1、Nessus 简介、下载、安装
简 介
Nessus 是世界上很流行的漏洞扫描程序,全世界很多组织都有在使用它。该工具提供完整的电脑漏洞扫描服务,并随时更新其漏洞数据库。Nessus 不同于传统的漏洞扫描软件,Nessus 可同时在本机或远端上遥控,进行系统的漏洞分析扫描
Nessus Pro10.1.2 配合20220328最新版本插件:https://www.iculture.cc/software/pig=12467
下载、安装
Linux 安装:
安装:dpkg -i Nessus.deb
启动:systemctl start nessusd.service
浏览器访问:https://127.0.0.1:8834
Windows 安装:
下载 Nessus 解压后直接安装,浏览器访问:https://127.0.0.1:8834





下载 Nessus pro 插件并更新
Linux 执行命令:sudo /opt/nessus/sbin/nessuscli update all-2.0.tar.gz
Windows 执行命令:

重启 Nessus 服务
/bin/systemctl start nessusd.service进行 插件配置
Linux:sudo vi /opt/nessus/var/nessus/plugin_feed_info.inc
Windows:
添加内容:
PLUGIN_SET = "202203282143";
PLUGIN_FEED = "ProfessionalFeed (Direct)";
PLUGIN_FEED_TRANSPORT = "Tenable Network Security Lightning";

关闭 Nessus 服务.,再重启 Nessus 服务。
然后在重新访问: https://127.0.0.1:8834




kali 安装 nessus
:https://zhuanlan.zhihu.com/p/338454648
下载对应版本的 nusses:https://www.tenable.com/downloads/nessus?loginAttempted=true
进入下载目录:sodu dpkg -i Nessus-10.1.1-debian6_amd64.deb
按照提示先启动服务 /bin/systemctl start nessusd.service
# 从deb 安装包安装Nessus
sudo dpkg -i Nessus-8.10.0-debian6_amd64.deb# 启动nessus
sudo /etc/init.d/nessusd start# 访问nessu web ui ,通过以下途径设置账号密码
http://localhost:8834
Managed Scanner ---> Tenable.sc ---> [root:root]# 升级插件包
sudo /opt/nessus/sbin/nessuscli update all-2.0.tar.gz# 提取文件
sudo tar -zxvf all-2.0.tar.gz plugin_feed_info.inc
sudo vim plugin_feed_info.inc
cat plugin_feed_info.inc
PLUGIN_SET = "202004162028";
PLUGIN_FEED = "ProfessionalFeed (Direct)";
PLUGIN_FEED_TRANSPORT = "Tenable Network Security Lightning";# 移动文件
sudo cp plugin_feed_info.inc /opt/nessus/var/nessus/
sudo cp plugin_feed_info.inc /opt/nessus/lib/nessus/plugins/# 重启nessus
sudo /etc/init.d/nessusd stop
sudo /etc/init.d/nessusd start

边栏推荐
- Matlab comprehensive exercise: application in signal and system
- Opencv learning log 14 - count the number of coins in the picture (regardless of overlap)
- MySQL授予用户指定内容的操作权限
- China potato slicer market trend report, technical dynamic innovation and market forecast
- 【练习-11】4 Values whose Sum is 0(和为0的4个值)
- mysql导入数据库报错 [Err] 1273 – Unknown collation: ‘utf8mb4_0900_ai_ci’
- MATLAB实例:阶跃函数的两种表达方式
- Market trend report, technical innovation and market forecast of Chinese hospital respiratory humidification equipment
- Cost accounting [13]
- Accounting regulations and professional ethics [5]
猜你喜欢
随机推荐
学习记录:TIM—基本定时器
Learning records: serial communication and solutions to errors encountered
Gartner:关于零信任网络访问最佳实践的五个建议
Research Report of pharmaceutical solvent industry - market status analysis and development prospect prediction
【高老师软件需求分析】20级云班课习题答案合集
用C语言写网页游戏
Opencv learning log 13 corrosion, expansion, opening and closing operations
Opencv learning log 33 Gaussian mean filtering
Research Report of exterior wall insulation system (ewis) industry - market status analysis and development prospect prediction
Es6---es6 content details
Cost accounting [21]
JS --- BOM details of JS (V)
MATLAB综合练习:信号与系统中的应用
Opencv learning log 16 paperclip count
【练习4-1】Cake Distribution(分配蛋糕)
0-1 knapsack problem (I)
cs零基础入门学习记录
Research Report on market supply and demand and strategy of China's Medical Automation Industry
SSM框架常用配置文件
学习记录:如何进行PWM 输出









