1
1

00:00:00,150  -->  00:00:01,800
<v Instructor>In this lesson, I'm going to show you</v>
2

2

00:00:01,800  -->  00:00:05,220
how you can conduct scanning using a tool like Nessus.
3

3

00:00:05,220  -->  00:00:06,510
Now, as we go through this lesson,
4

4

00:00:06,510  -->  00:00:08,880
I'm going to be going through my own sample lab
5

5

00:00:08,880  -->  00:00:11,010
and be able to do some scans with Nessus
6

6

00:00:11,010  -->  00:00:12,930
across these different devices.
7

7

00:00:12,930  -->  00:00:16,170
I'm doing these both individually and as a group.
8

8

00:00:16,170  -->  00:00:17,550
Now what you're seeing here on the screen
9

9

00:00:17,550  -->  00:00:20,790
is a visual representation of my current lab network.
10

10

00:00:20,790  -->  00:00:21,990
Over on the left side,
11

11

00:00:21,990  -->  00:00:26,303
you'll see that at IP address 192.168.1.116.
12

12

00:00:26,303  -->  00:00:29,460
That is a Mac machine and that's actually my desktop
13

13

00:00:29,460  -->  00:00:31,230
that I'm using to record this video
14

14

00:00:31,230  -->  00:00:33,360
to demonstrate how to use Nessus.
15

15

00:00:33,360  -->  00:00:35,790
In addition to that, I also have a Kali Linux machine,
16

16

00:00:35,790  -->  00:00:39,000
which is what I'm logged into now as a virtual machine.
17

17

00:00:39,000  -->  00:00:39,833
All of the things that are starting with
18

18

00:00:39,833  -->  00:00:44,833
192.168.150, dot something are part of my virtual network
19

19

00:00:45,330  -->  00:00:46,620
in the lab environment,
20

20

00:00:46,620  -->  00:00:49,020
whereas the Mac machine is part of my office network,
21

21

00:00:49,020  -->  00:00:51,090
which is why it has a different IP address
22

22

00:00:51,090  -->  00:00:54,570
starting with 192.168.1, dot something.
23

23

00:00:54,570  -->  00:00:55,800
Now as you look at the circle,
24

24

00:00:55,800  -->  00:00:57,330
you'll see that there are different devices
25

25

00:00:57,330  -->  00:00:59,310
that are connected to this virtual network,
26

26

00:00:59,310  -->  00:01:04,310
including a Windows 11 machine at 192.168.150.138.
27

27

00:01:04,710  -->  00:01:07,470
My local host, which is also my Kali Linux machine,
28

28

00:01:07,470  -->  00:01:11,400
which is 192.168.150.129,
29

29

00:01:11,400  -->  00:01:12,963
my Metasploitable 2 virtual machine,
30

30

00:01:12,963  -->  00:01:14,880
that is going to be a very vulnerable client
31

31

00:01:14,880  -->  00:01:17,370
for us to find a lot of issues and vulnerabilities with,
32

32

00:01:17,370  -->  00:01:21,540
and that's at 192.168.150.136,
33

33

00:01:21,540  -->  00:01:23,460
and an a Ubuntu Linux machine
34

34

00:01:23,460  -->  00:01:28,320
that is located at 192.168.150.137.
35

35

00:01:28,320  -->  00:01:30,747
Now the Windows 11 machine, the Ubuntu machine
36

36

00:01:30,747  -->  00:01:33,840
and the Kali Linux machine should all be relatively secure
37

37

00:01:33,840  -->  00:01:35,250
because they've just been installed
38

38

00:01:35,250  -->  00:01:37,950
and they've been updated with the latest security patches.
39

39

00:01:37,950  -->  00:01:39,990
The Metasploitable 2 machine, on the other hand,
40

40

00:01:39,990  -->  00:01:42,000
will probably find a lot of vulnerabilities
41

41

00:01:42,000  -->  00:01:44,490
because it is a vulnerable machine by default,
42

42

00:01:44,490  -->  00:01:45,810
and we use this to be able to practice
43

43

00:01:45,810  -->  00:01:47,190
our penetration testing skills
44

44

00:01:47,190  -->  00:01:49,380
or our cybersecurity analyst skills
45

45

00:01:49,380  -->  00:01:50,640
by finding those vulnerabilities
46

46

00:01:50,640  -->  00:01:53,490
and then trying to patch them, rescanning the machine
47

47

00:01:53,490  -->  00:01:55,620
and then seeing if we've solved those vulnerabilities
48

48

00:01:55,620  -->  00:01:56,880
in the network.
49

49

00:01:56,880  -->  00:01:58,770
Alright, now that we have a basic understanding
50

50

00:01:58,770  -->  00:02:00,420
of the network that we're going to be using,
51

51

00:02:00,420  -->  00:02:03,120
let's go ahead and move into looking at Nessus.
52

52

00:02:03,120  -->  00:02:05,670
Alright, here you can see the Tenable website
53

53

00:02:05,670  -->  00:02:07,380
and if you go to tenable.com,
54

54

00:02:07,380  -->  00:02:09,900
you can search for the Nessus Essentials tool.
55

55

00:02:09,900  -->  00:02:12,540
This is a free tool that used to be called Nessus home
56

56

00:02:12,540  -->  00:02:14,250
and it allows you to scan your environment,
57

57

00:02:14,250  -->  00:02:17,370
including all of your network up to 16 IP addresses
58

58

00:02:17,370  -->  00:02:20,640
per scanner, using the same high speed. in-depth assessments
59

59

00:02:20,640  -->  00:02:23,370
that you'd get with the professional version of Nessus.
60

60

00:02:23,370  -->  00:02:24,990
As a cybersecurity analyst,
61

61

00:02:24,990  -->  00:02:27,300
you need to get comfortable using vulnerability scanners
62

62

00:02:27,300  -->  00:02:29,100
like Nessus and OpenVOS,
63

63

00:02:29,100  -->  00:02:30,510
because depending on where you work,
64

64

00:02:30,510  -->  00:02:33,540
you'll either be using Nessus or OpenVOS or QualysGuard
65

65

00:02:33,540  -->  00:02:35,280
or some other vulnerability scanner,
66

66

00:02:35,280  -->  00:02:37,650
but most of them work pretty much the same way.
67

67

00:02:37,650  -->  00:02:40,050
So in this lesson we're going to use ESUs Essentials,
68

68

00:02:40,050  -->  00:02:41,730
because it is something that is free to use
69

69

00:02:41,730  -->  00:02:43,230
and you can download it and do this
70

70

00:02:43,230  -->  00:02:44,700
on your own home network as well
71

71

00:02:44,700  -->  00:02:46,980
to see what vulnerabilities exist there.
72

72

00:02:46,980  -->  00:02:49,140
To do that, simply go to this webpage,
73

73

00:02:49,140  -->  00:02:51,450
enter in your first name, last name, and email address.
74

74

00:02:51,450  -->  00:02:52,860
They'll take you to the download page
75

75

00:02:52,860  -->  00:02:54,660
and they'll email you an activation code
76

76

00:02:54,660  -->  00:02:57,480
with a license key that is good for about five years
77

77

00:02:57,480  -->  00:02:59,460
for you to be able to start playing with Nessus
78

78

00:02:59,460  -->  00:03:01,680
and getting used to how it works.
79

79

00:03:01,680  -->  00:03:03,870
Once you have Nessus installed on your computer,
80

80

00:03:03,870  -->  00:03:06,120
it's going to run as a program in the background
81

81

00:03:06,120  -->  00:03:07,740
and essentially starts up a web server
82

82

00:03:07,740  -->  00:03:10,110
that you can access on your local machine.
83

83

00:03:10,110  -->  00:03:14,040
To access this, you'll go to local host: 8834,
84

84

00:03:14,040  -->  00:03:16,560
which is Port 8834 on your local host,
85

85

00:03:16,560  -->  00:03:18,750
which is the machine you're accessing it from.
86

86

00:03:18,750  -->  00:03:21,360
In my case, that's my Kali Linux machine.
87

87

00:03:21,360  -->  00:03:22,860
Once you're there, you're going to walk through
88

88

00:03:22,860  -->  00:03:25,080
the setup wizard and then you'll create an account.
89

89

00:03:25,080  -->  00:03:26,640
In my case, I've already done that,
90

90

00:03:26,640  -->  00:03:28,830
so I'm just going to go ahead and log in using my account,
91

91

00:03:28,830  -->  00:03:30,093
which is Dion Training.
92

92

00:03:32,160  -->  00:03:33,120
Once you've done that,
93

93

00:03:33,120  -->  00:03:35,460
you'll be brought into the My scan screen.
94

94

00:03:35,460  -->  00:03:36,660
Now the first time you do this,
95

95

00:03:36,660  -->  00:03:38,280
you're going to have nothing listed here
96

96

00:03:38,280  -->  00:03:40,650
because it is going to be a blank scan
97

97

00:03:40,650  -->  00:03:42,450
because you haven't done anything with Nessus yet,
98

98

00:03:42,450  -->  00:03:43,980
because it's a brand new install.
99

99

00:03:43,980  -->  00:03:46,770
In my case, I've already done a couple of these scans for us
100

100

00:03:46,770  -->  00:03:48,300
so that way, we'll be able to look at the results
101

101

00:03:48,300  -->  00:03:50,550
without having to wait a long time for them to come back
102

102

00:03:50,550  -->  00:03:51,900
from doing the scans.
103

103

00:03:51,900  -->  00:03:53,700
These scans can take a really long time
104

104

00:03:53,700  -->  00:03:55,560
depending on the size of your network.
105

105

00:03:55,560  -->  00:03:58,650
Even for a really small lab environment like the one I have,
106

106

00:03:58,650  -->  00:04:00,810
I have that top scan, which is a basic scan
107

107

00:04:00,810  -->  00:04:02,580
of my entire network that has been running
108

108

00:04:02,580  -->  00:04:05,280
for about 45 minutes at this point.
109

109

00:04:05,280  -->  00:04:06,540
Now, in order to use Nessus,
110

110

00:04:06,540  -->  00:04:08,280
you need to create a scan profile
111

111

00:04:08,280  -->  00:04:11,100
and you can see I have several of them already created here.
112

112

00:04:11,100  -->  00:04:12,480
I'm going to walk you through how you can create
113

113

00:04:12,480  -->  00:04:14,550
your own scan profile and then we'll take a look at
114

114

00:04:14,550  -->  00:04:16,290
some of the results from my scanning profiles
115

115

00:04:16,290  -->  00:04:17,730
that have already been run.
116

116

00:04:17,730  -->  00:04:20,700
To do this, simply click new scan at the top right corner
117

117

00:04:20,700  -->  00:04:22,560
of your screen, and then from here,
118

118

00:04:22,560  -->  00:04:24,600
you'll see all the different types of scanners you have,
119

119

00:04:24,600  -->  00:04:26,790
including discovery scanners to be able to figure out
120

120

00:04:26,790  -->  00:04:29,400
what hosts are on the network, vulnerability scanners
121

121

00:04:29,400  -->  00:04:31,650
that will target specific vulnerabilities,
122

122

00:04:31,650  -->  00:04:33,960
or we also have compliance scans.
123

123

00:04:33,960  -->  00:04:35,760
Now, when you're using Nessus Essentials,
124

124

00:04:35,760  -->  00:04:37,290
compliance scans are not something
125

125

00:04:37,290  -->  00:04:38,700
you're going to be able to use.
126

126

00:04:38,700  -->  00:04:40,530
These compliance scans are things like
127

127

00:04:40,530  -->  00:04:43,020
PCI DSS, internal network scans
128

128

00:04:43,020  -->  00:04:44,790
or offline configuration audits
129

129

00:04:44,790  -->  00:04:47,760
or the PCI quarterly external scans that are required
130

130

00:04:47,760  -->  00:04:50,610
once a quarter if your organization takes credit cards
131

131

00:04:50,610  -->  00:04:52,440
as part of their business model.
132

132

00:04:52,440  -->  00:04:53,670
All these are things that are included
133

133

00:04:53,670  -->  00:04:55,830
with the Nessus professional and expert versions,
134

134

00:04:55,830  -->  00:04:58,560
but in the home version, which is Nessus Essentials,
135

135

00:04:58,560  -->  00:05:00,570
these are actually blocked out and you have to pay
136

136

00:05:00,570  -->  00:05:02,010
to get the access to those.
137

137

00:05:02,010  -->  00:05:02,880
For most of us though,
138

138

00:05:02,880  -->  00:05:04,230
if we're doing this in our home network,
139

139

00:05:04,230  -->  00:05:05,850
those don't actually matter that much
140

140

00:05:05,850  -->  00:05:07,620
because you're probably not processing credit cards
141

141

00:05:07,620  -->  00:05:10,320
on your home computer and instead you're more focused
142

142

00:05:10,320  -->  00:05:11,580
on the things that are above,
143

143

00:05:11,580  -->  00:05:12,900
which are the different vulnerabilities
144

144

00:05:12,900  -->  00:05:14,910
or the discovery scan.
145

145

00:05:14,910  -->  00:05:16,860
Now if you're looking at these different vulnerabilities,
146

146

00:05:16,860  -->  00:05:18,180
you'll notice these are targeted
147

147

00:05:18,180  -->  00:05:20,430
for specific groups of vulnerabilities.
148

148

00:05:20,430  -->  00:05:22,530
For example, you can see in the middle of my screen
149

149

00:05:22,530  -->  00:05:24,810
there's one called the WannaCry ransomware.
150

150

00:05:24,810  -->  00:05:27,330
This was really popular back in 2017
151

151

00:05:27,330  -->  00:05:29,730
and affected all Windows machines at the time.
152

152

00:05:29,730  -->  00:05:31,410
When something like that comes out,
153

153

00:05:31,410  -->  00:05:32,790
a lot of times Nessus will create
154

154

00:05:32,790  -->  00:05:36,150
a specific scan vulnerability for that one plugin.
155

155

00:05:36,150  -->  00:05:38,670
This way you can quickly look across your entire network
156

156

00:05:38,670  -->  00:05:40,740
even if you have a hundred or a thousand machines
157

157

00:05:40,740  -->  00:05:43,170
and check just for that one vulnerability.
158

158

00:05:43,170  -->  00:05:44,250
That's the reason why you're seeing
159

159

00:05:44,250  -->  00:05:45,570
these vulnerabilities listed here,
160

160

00:05:45,570  -->  00:05:47,040
because these are the ones that were really,
161

161

00:05:47,040  -->  00:05:48,630
really important to look for.
162

162

00:05:48,630  -->  00:05:52,410
Things like Spectra and Meltdown and WannaCry and Ripple 20
163

163

00:05:52,410  -->  00:05:53,880
and things like that.
164

164

00:05:53,880  -->  00:05:55,710
So for our cases we're not going to look at
165

165

00:05:55,710  -->  00:05:56,910
just a single vulnerability,
166

166

00:05:56,910  -->  00:05:58,860
but we want to look at what vulnerabilities exist
167

167

00:05:58,860  -->  00:06:01,800
across the entire network so we can get a better idea
168

168

00:06:01,800  -->  00:06:03,930
of exactly what vulnerabilities exist right now
169

169

00:06:03,930  -->  00:06:05,670
in our network and create a baseline
170

170

00:06:05,670  -->  00:06:07,470
for us to use as we move forward.
171

171

00:06:07,470  -->  00:06:09,930
To do this, we're going to do a basic scan.
172

172

00:06:09,930  -->  00:06:10,950
So I'm just going to click over here
173

173

00:06:10,950  -->  00:06:12,630
and do a basic network scan,
174

174

00:06:12,630  -->  00:06:15,780
which is a full system scan suitable for any host,
175

175

00:06:15,780  -->  00:06:18,600
and once I click on that, it's going to have me give it a name.
176

176

00:06:18,600  -->  00:06:20,670
In my case, I'm just going to call it Network scan
177

177

00:06:20,670  -->  00:06:22,170
and then I'm going to give it a description.
178

178

00:06:22,170  -->  00:06:24,030
Now this is really helpful because these scans
179

179

00:06:24,030  -->  00:06:25,170
are ones that you're going to create
180

180

00:06:25,170  -->  00:06:27,480
and then use week after week and month after month,
181

181

00:06:27,480  -->  00:06:29,700
and so six months from now you might forget
182

182

00:06:29,700  -->  00:06:31,620
why did you call this Network scan?
183

183

00:06:31,620  -->  00:06:35,520
So in my case I'm going to say "A lab demonstration
184

184

00:06:35,520  -->  00:06:39,537
of using Nessus as a vulnerability scanner."
185

185

00:06:40,530  -->  00:06:42,720
All right? And then we're going to save it into a folder.
186

186

00:06:42,720  -->  00:06:44,310
We can do it in the My scans folder,
187

187

00:06:44,310  -->  00:06:45,930
which you see in the top left corner,
188

188

00:06:45,930  -->  00:06:47,970
or you have the All scans folder.
189

189

00:06:47,970  -->  00:06:50,340
If I wanted to create a new folder, I can do that as well,
190

190

00:06:50,340  -->  00:06:52,260
but for our purposes, the My scan folder
191

191

00:06:52,260  -->  00:06:53,610
is going to be just fine,
192

192

00:06:53,610  -->  00:06:55,890
and then we're going to list out our targets.
193

193

00:06:55,890  -->  00:06:57,330
Now, when you're listing out your targets,
194

194

00:06:57,330  -->  00:07:00,570
you can do this based on domain names like diontraining.com
195

195

00:07:00,570  -->  00:07:02,670
or by using IP addresses.
196

196

00:07:02,670  -->  00:07:05,280
For example, if you're doing your internal local network,
197

197

00:07:05,280  -->  00:07:07,230
you're probably going to have to use IP addresses,
198

198

00:07:07,230  -->  00:07:09,000
because you probably don't have a domain name
199

199

00:07:09,000  -->  00:07:11,670
associated with each and every host on your network.
200

200

00:07:11,670  -->  00:07:16,670
Now in my case, I'm using the 192.168.150.0/24 network.
201

201

00:07:20,310  -->  00:07:22,380
Now if I didn't know any of my hosts on that network,
202

202

00:07:22,380  -->  00:07:25,410
I can scan the entire subnet of 256 hosts
203

203

00:07:25,410  -->  00:07:27,270
by using something like this.
204

204

00:07:27,270  -->  00:07:28,440
Now instead of doing this though,
205

205

00:07:28,440  -->  00:07:29,760
if I know what my hosts are,
206

206

00:07:29,760  -->  00:07:30,690
I can list them out
207

207

00:07:30,690  -->  00:07:33,060
individually by putting in their IP addresses.
208

208

00:07:33,060  -->  00:07:35,070
So in my case, I do know all of my hosts,
209

209

00:07:35,070  -->  00:07:38,940
which is 192.168.150.136,
210

210

00:07:38,940  -->  00:07:41,610
which is my Kali Linux machine, then I'll put comma
211

211

00:07:41,610  -->  00:07:42,780
and I'll add the next one.
212

212

00:07:42,780  -->  00:07:43,860
I want to put my Windows machine,
213

213

00:07:43,860  -->  00:07:48,090
which is 192.168.150.138.
214

214

00:07:48,090  -->  00:07:49,680
I'll also want to include my Ubuntu machine,
215

215

00:07:49,680  -->  00:07:53,400
which is 192.168.150.137,
216

216

00:07:53,400  -->  00:07:55,290
and I also want to add my Metasploitable 2 machine,
217

217

00:07:55,290  -->  00:07:59,160
which is 192.168.150.139,
218

218

00:07:59,160  -->  00:08:02,730
and I can even add my Mac machine, which is 192.168.1.116.
219

219

00:08:05,220  -->  00:08:08,040
Now notice those first four are all going to be
220

220

00:08:08,040  -->  00:08:12,690
right next to each other, 136, 138, 137, and 139.
221

221

00:08:12,690  -->  00:08:13,920
So instead of writing it out that way,
222

222

00:08:13,920  -->  00:08:15,270
which takes a lot of time,
223

223

00:08:15,270  -->  00:08:17,610
I can actually just use a dash in between
224

224

00:08:17,610  -->  00:08:21,870
and do 136-139 and then I can get rid of
225

225

00:08:21,870  -->  00:08:24,090
all of the rest of those and it will still scan
226

226

00:08:24,090  -->  00:08:26,430
all four of those hosts because I'm doing everything
227

227

00:08:26,430  -->  00:08:31,380
between 136 and 139, which includes 137 and 138.
228

228

00:08:31,380  -->  00:08:33,510
I would still need to have a comma here to separate
229

229

00:08:33,510  -->  00:08:36,390
that range from my Mac machine because my Mac machine
230

230

00:08:36,390  -->  00:08:39,360
is outside of that range and it's a separate subnet.
231

231

00:08:39,360  -->  00:08:41,910
Now in this case, this would give me five different machines
232

232

00:08:41,910  -->  00:08:44,130
to scan and I think that's fine.
233

233

00:08:44,130  -->  00:08:46,500
Another thing you can do is you can upload your targets
234

234

00:08:46,500  -->  00:08:48,840
by adding something like a CSV file.
235

235

00:08:48,840  -->  00:08:52,380
For example, you might have a CSV file with 1000 clients
236

236

00:08:52,380  -->  00:08:54,180
spread across multiple subnets.
237

237

00:08:54,180  -->  00:08:55,410
Instead of typing them all in,
238

238

00:08:55,410  -->  00:08:58,740
you can just import that file by clicking Add file here.
239

239

00:08:58,740  -->  00:08:59,970
The next thing we're going to do
240

240

00:08:59,970  -->  00:09:01,920
is go down to our schedule option.
241

241

00:09:01,920  -->  00:09:04,380
From schedule, we can enable or disable this,
242

242

00:09:04,380  -->  00:09:05,850
right now this is disabled,
243

243

00:09:05,850  -->  00:09:08,130
but I want to go ahead and enable this.
244

244

00:09:08,130  -->  00:09:10,380
Now by doing this, I can schedule scans
245

245

00:09:10,380  -->  00:09:12,780
and allow them to happen once a week, once a day,
246

246

00:09:12,780  -->  00:09:14,610
once a month, or once a year.
247

247

00:09:14,610  -->  00:09:16,170
For example, we mentioned the fact that
248

248

00:09:16,170  -->  00:09:17,913
there are these quarterly PCI DSS scans
249

249

00:09:17,913  -->  00:09:20,700
that we do all the time as cybersecurity analysts.
250

250

00:09:20,700  -->  00:09:23,040
You can set those up here and say "Once a quarter,
251

251

00:09:23,040  -->  00:09:24,690
on the first of every third month,
252

252

00:09:24,690  -->  00:09:27,750
I want you to run a full PCI DSS quarterly scan
253

253

00:09:27,750  -->  00:09:29,070
and give me those results."
254

254

00:09:29,070  -->  00:09:30,810
So a lot of this can be automated and set up
255

255

00:09:30,810  -->  00:09:31,643
so you don't have to sit here
256

256

00:09:31,643  -->  00:09:33,570
waiting for these scans to complete.
257

257

00:09:33,570  -->  00:09:35,250
In my case, I'm going to go ahead and enable this
258

258

00:09:35,250  -->  00:09:37,260
and we're going to say we want to do this as a frequency
259

259

00:09:37,260  -->  00:09:39,750
of weekly and I want to do this every Saturday morning
260

260

00:09:39,750  -->  00:09:41,190
starting at 1:00 AM.
261

261

00:09:41,190  -->  00:09:42,840
So I'll click on that and the first Saturday
262

262

00:09:42,840  -->  00:09:46,680
we're going to come to is going to be January 14th, 2023.
263

263

00:09:46,680  -->  00:09:48,660
You'll then select the time zone associated with that
264

264

00:09:48,660  -->  00:09:50,250
and for me that's going to be the East coast,
265

265

00:09:50,250  -->  00:09:52,530
which is New York inside of the United States
266

266

00:09:52,530  -->  00:09:54,120
and then I'll repeat this every week
267

267

00:09:54,120  -->  00:09:56,100
and I can choose which day I want it to happen,
268

268

00:09:56,100  -->  00:09:58,380
and in my case, I want it to happen every Saturday.
269

269

00:09:58,380  -->  00:10:00,630
So I'm just going to go ahead and highlight the Saturdays there
270

270

00:10:00,630  -->  00:10:02,040
and you can see the summary at the bottom.
271

271

00:10:02,040  -->  00:10:04,560
It repeats every week on Saturday at 1:00 AM,
272

272

00:10:04,560  -->  00:10:07,950
starting Saturday, January 14th, 2023,
273

273

00:10:07,950  -->  00:10:10,500
and that's how you can set up a scheduled scan.
274

274

00:10:10,500  -->  00:10:13,290
The next thing we can do is go to our notifications tab.
275

275

00:10:13,290  -->  00:10:16,194
Under notifications, we can configure an SMTP server
276

276

00:10:16,194  -->  00:10:19,230
and then we can send an email when our scans are complete.
277

277

00:10:19,230  -->  00:10:22,260
So after it scans this thing at 1:00 AM on Saturday,
278

278

00:10:22,260  -->  00:10:24,307
it can then email me a PDF report that says,
279

279

00:10:24,307  -->  00:10:26,370
"Here's all the vulnerabilities I found"
280

280

00:10:26,370  -->  00:10:28,890
and so again, this makes it a really nice automated process
281

281

00:10:28,890  -->  00:10:30,480
for us as cyber security analysts
282

282

00:10:30,480  -->  00:10:32,850
and sort of something you might want to go ahead and set up.
283

283

00:10:32,850  -->  00:10:35,250
In addition to that, you can also use results filters.
284

284

00:10:35,250  -->  00:10:37,680
So you can say, "Hey, only email me if this happens
285

285

00:10:37,680  -->  00:10:40,050
or don't email me when this happens."
286

286

00:10:40,050  -->  00:10:42,120
The next thing we're going to do is click on discovery.
287

287

00:10:42,120  -->  00:10:44,070
Under discovery, we're going to say what kind of types
288

288

00:10:44,070  -->  00:10:45,840
we want to use for our scans.
289

289

00:10:45,840  -->  00:10:47,220
Now by default, the most common
290

290

00:10:47,220  -->  00:10:50,010
is going to be doing a port scan of the common ports.
291

291

00:10:50,010  -->  00:10:52,530
This is usually the 1000 most commonly used ports,
292

292

00:10:52,530  -->  00:10:53,790
and this will be a much quicker way
293

293

00:10:53,790  -->  00:10:57,030
of doing a discovery scan, but you could miss some things.
294

294

00:10:57,030  -->  00:11:00,000
So personally I like to do a more comprehensive scan
295

295

00:11:00,000  -->  00:11:02,700
and I will do a scan of all ports on those machines
296

296

00:11:02,700  -->  00:11:04,770
or if you're looking for a specific port only,
297

297

00:11:04,770  -->  00:11:06,810
like which ones are web servers,
298

298

00:11:06,810  -->  00:11:09,600
I can do that by doing a custom port and in that case
299

299

00:11:09,600  -->  00:11:11,670
I would just select custom and then I would be able
300

300

00:11:11,670  -->  00:11:13,440
to choose my own discovery settings
301

301

00:11:13,440  -->  00:11:15,390
by doing the host discovery, port scanning,
302

302

00:11:15,390  -->  00:11:17,010
service discovery or identity
303

303

00:11:17,010  -->  00:11:18,810
and in this case it'd be service discovery
304

304

00:11:18,810  -->  00:11:21,090
that I would be looking for a particular type of web server
305

305

00:11:21,090  -->  00:11:24,900
like an Apache web server over port 80 or port 443.
306

306

00:11:24,900  -->  00:11:27,060
So again, this just gives you additional areas.
307

307

00:11:27,060  -->  00:11:28,500
For our use case though, we're going to go ahead
308

308

00:11:28,500  -->  00:11:30,240
and stick with the all port scan,
309

309

00:11:30,240  -->  00:11:32,610
which will go ahead and scan all of the ports available
310

310

00:11:32,610  -->  00:11:35,130
and it'll use Netstat if the credentials are provided
311

311

00:11:35,130  -->  00:11:37,740
and it'll use a SYN scanner if necessary,
312

312

00:11:37,740  -->  00:11:40,200
'cause sometimes PinkSCANs won't work.
313

313

00:11:40,200  -->  00:11:42,840
The next thing we're going to look at is our assessment.
314

314

00:11:42,840  -->  00:11:43,680
Under assessment,
315

315

00:11:43,680  -->  00:11:45,750
we're also going to choose the scan type here.
316

316

00:11:45,750  -->  00:11:48,210
The default is going to be our most basic scan,
317

317

00:11:48,210  -->  00:11:49,470
and right now we're not even scanning
318

318

00:11:49,470  -->  00:11:51,480
for web application vulnerabilities.
319

319

00:11:51,480  -->  00:11:53,493
This is fine if we're going to be scanning a bunch of hosts
320

320

00:11:53,493  -->  00:11:56,100
that are on a network such as people's workstations
321

321

00:11:56,100  -->  00:11:58,590
because they shouldn't be running web applications on those,
322

322

00:11:58,590  -->  00:12:00,360
but if you're checking a web server,
323

323

00:12:00,360  -->  00:12:02,820
you would want to enable those web application scans,
324

324

00:12:02,820  -->  00:12:04,530
and in my case, one of my machines,
325

325

00:12:04,530  -->  00:12:07,320
the Metasploitable 2 machine is running a web server.
326

326

00:12:07,320  -->  00:12:09,570
So I want to change that from default
327

327

00:12:09,570  -->  00:12:10,650
and I want to go ahead and say
328

328

00:12:10,650  -->  00:12:13,260
Scan for all web vulnerabilities complex.
329

329

00:12:13,260  -->  00:12:15,810
This is going to be our most thorough and in-depth scan,
330

330

00:12:15,810  -->  00:12:17,880
and again, there is an option to do a custom scan
331

331

00:12:17,880  -->  00:12:20,250
where you can set up all your different parameters.
332

332

00:12:20,250  -->  00:12:22,110
Next, we have our report.
333

333

00:12:22,110  -->  00:12:23,880
Under our report we have the ability
334

334

00:12:23,880  -->  00:12:25,380
to set up different things,
335

335

00:12:25,380  -->  00:12:27,030
including the ability to designate hosts
336

336

00:12:27,030  -->  00:12:29,460
by their DNS name, be able to show all the hosts
337

337

00:12:29,460  -->  00:12:30,690
that responded to a ping,
338

338

00:12:30,690  -->  00:12:32,460
display any hosts that were unreachable.
339

339

00:12:32,460  -->  00:12:34,950
For example, you said you expected a hundred machines
340

340

00:12:34,950  -->  00:12:37,590
to be online, but you only found 73.
341

341

00:12:37,590  -->  00:12:40,050
What were the other 27 machines that were offline?
342

342

00:12:40,050  -->  00:12:42,660
Well, if you display unreachable hosts there at the bottom,
343

343

00:12:42,660  -->  00:12:45,150
that will actually show that to you in your report
344

344

00:12:45,150  -->  00:12:47,280
and so all of these things are things that you can configure
345

345

00:12:47,280  -->  00:12:49,080
for part of your reporting.
346

346

00:12:49,080  -->  00:12:51,000
Then we'll go into our advanced tab, and again,
347

347

00:12:51,000  -->  00:12:52,410
here's another scan type.
348

348

00:12:52,410  -->  00:12:54,480
We're using the default right now, which is fine.
349

349

00:12:54,480  -->  00:12:56,280
If you're scanning over a low bandwidth link,
350

350

00:12:56,280  -->  00:12:59,400
such as a VPN or some kind of remote office connection,
351

351

00:12:59,400  -->  00:13:02,310
you may want to use that or again, you can use custom
352

352

00:13:02,310  -->  00:13:05,040
where you can use more or less scanners each time.
353

353

00:13:05,040  -->  00:13:06,750
In my case, using the default,
354

354

00:13:06,750  -->  00:13:07,920
this says I'm going to be able to scan
355

355

00:13:07,920  -->  00:13:09,750
up to 30 hosts at one time.
356

356

00:13:09,750  -->  00:13:12,120
I can do four checks per host at one time
357

357

00:13:12,120  -->  00:13:14,850
and I have a five second network readout timeout.
358

358

00:13:14,850  -->  00:13:16,920
If I wanted to increase that or decrease that,
359

359

00:13:16,920  -->  00:13:19,530
I could do that by using the custom area.
360

360

00:13:19,530  -->  00:13:21,540
The next tab we have is our credentials.
361

361

00:13:21,540  -->  00:13:23,640
Now as you know, you can either use credentialed
362

362

00:13:23,640  -->  00:13:25,260
or uncredentialed scans,
363

363

00:13:25,260  -->  00:13:26,730
and if you're going to use credentialed scans,
364

364

00:13:26,730  -->  00:13:28,800
that means you're giving it the username and password
365

365

00:13:28,800  -->  00:13:31,020
for an account on that given system.
366

366

00:13:31,020  -->  00:13:32,970
If you're using a Windows machine that you're scanning,
367

367

00:13:32,970  -->  00:13:34,200
you'll simply click on Windows
368

368

00:13:34,200  -->  00:13:36,360
and then enter in your username and password there
369

369

00:13:36,360  -->  00:13:38,250
and save that and it'll allow Nessus to connect
370

370

00:13:38,250  -->  00:13:40,590
to that machine using those user credentials
371

371

00:13:40,590  -->  00:13:41,790
and be able to get a better idea
372

372

00:13:41,790  -->  00:13:43,590
of what vulnerabilities exist.
373

373

00:13:43,590  -->  00:13:45,750
I've already done a scan of doing both a credentialed
374

374

00:13:45,750  -->  00:13:48,540
and non-credentialed scan against my Windows 11 machine,
375

375

00:13:48,540  -->  00:13:50,550
and you'll see that when we did a credentialed scan,
376

376

00:13:50,550  -->  00:13:52,620
we actually found one additional vulnerability
377

377

00:13:52,620  -->  00:13:55,560
that wasn't found when we did an uncredentialed scan.
378

378

00:13:55,560  -->  00:13:57,420
So it's important to realize this
379

379

00:13:57,420  -->  00:13:59,700
and determine which type of scan you want to do.
380

380

00:13:59,700  -->  00:14:01,320
If you're trying to see what vulnerabilities exist
381

381

00:14:01,320  -->  00:14:03,900
for an outside attacker, then doing an uncredentialed scan
382

382

00:14:03,900  -->  00:14:05,160
would be the way to go.
383

383

00:14:05,160  -->  00:14:06,900
If you want to see what an insider threat could do,
384

384

00:14:06,900  -->  00:14:08,640
who has a valid login and password,
385

385

00:14:08,640  -->  00:14:10,500
then using something like a credentialed scan
386

386

00:14:10,500  -->  00:14:14,250
would make sense and the final tab we have is our plug-ins.
387

387

00:14:14,250  -->  00:14:16,560
Now plug-ins inside Nessus are used to be able to
388

388

00:14:16,560  -->  00:14:18,570
check for certain vulnerabilities.
389

389

00:14:18,570  -->  00:14:20,490
Here you can see the plugin families down the left
390

390

00:14:20,490  -->  00:14:22,410
and then the plug-in names on the right.
391

391

00:14:22,410  -->  00:14:25,080
For example, if I go down here and I go all the way
392

392

00:14:25,080  -->  00:14:26,640
to the bottom, you'll see that we have
393

393

00:14:26,640  -->  00:14:28,350
three different ones for Windows.
394

394

00:14:28,350  -->  00:14:29,610
The first one in the Windows family
395

395

00:14:29,610  -->  00:14:31,470
has a whole bunch of plugins and you can see them
396

396

00:14:31,470  -->  00:14:32,580
listed on the right.
397

397

00:14:32,580  -->  00:14:35,220
For example, we could be checking to see if team viewers
398

398

00:14:35,220  -->  00:14:37,590
insecure directory permissions privilege escalation
399

399

00:14:37,590  -->  00:14:39,630
is something our machine is vulnerable with.
400

400

00:14:39,630  -->  00:14:42,930
That's because we have that plug in there, 135708,
401

401

00:14:42,930  -->  00:14:45,300
and it will check that when we're doing our scans.
402

402

00:14:45,300  -->  00:14:47,250
Right now, all these plug-ins are enabled
403

403

00:14:47,250  -->  00:14:49,680
and we're going to be using all of them when we do our scan,
404

404

00:14:49,680  -->  00:14:52,650
but we could check for just a single vulnerability as well.
405

405

00:14:52,650  -->  00:14:54,810
Essentially, if there is a vulnerability out there
406

406

00:14:54,810  -->  00:14:58,110
that's known, Nessus will go ahead and make a new plugin
407

407

00:14:58,110  -->  00:15:00,060
and release that to the client.
408

408

00:15:00,060  -->  00:15:02,160
Speaking of that, how do you update your scanner
409

409

00:15:02,160  -->  00:15:04,140
to ensure you have all the latest plugins?
410

410

00:15:04,140  -->  00:15:05,310
Well, the best way to do that
411

411

00:15:05,310  -->  00:15:07,530
is by clicking on the settings tab at the top,
412

412

00:15:07,530  -->  00:15:10,320
but we'll do that after we finish creating our scan.
413

413

00:15:10,320  -->  00:15:12,000
Now that we've looked at all the plug-ins we want,
414

414

00:15:12,000  -->  00:15:14,760
we can go ahead and hit save and that will save that for us
415

415

00:15:14,760  -->  00:15:16,830
and then from here it's asking us for the credentials
416

416

00:15:16,830  -->  00:15:18,240
for our Windows machine.
417

417

00:15:18,240  -->  00:15:19,680
In our case, we don't want to use that,
418

418

00:15:19,680  -->  00:15:21,360
so I'm just going to hit the X over here
419

419

00:15:21,360  -->  00:15:22,760
and then I'm going to hit Save.
420

420

00:15:24,060  -->  00:15:26,250
From here, we now see that my network scan
421

421

00:15:26,250  -->  00:15:29,130
is added to my list and it will run every week
422

422

00:15:29,130  -->  00:15:30,750
on Thursday at 1:00 AM.
423

423

00:15:30,750  -->  00:15:32,760
The reason it says Thursday is because that's today's date
424

424

00:15:32,760  -->  00:15:33,593
when I did it,
425

425

00:15:33,593  -->  00:15:35,820
but the first scheduled time is going to be Saturday
426

426

00:15:35,820  -->  00:15:39,030
at 1:00 AM based on the configuration we did.
427

427

00:15:39,030  -->  00:15:40,620
Now let's go ahead and take a look at
428

428

00:15:40,620  -->  00:15:42,300
how you can update your plugins.
429

429

00:15:42,300  -->  00:15:44,910
To do this, you're going to go and click on Settings at the top
430

430

00:15:44,910  -->  00:15:46,980
and from settings you'll then go down
431

431

00:15:46,980  -->  00:15:48,960
and look at your scanner health.
432

432

00:15:48,960  -->  00:15:50,010
From your scanner health,
433

433

00:15:50,010  -->  00:15:51,900
you'll see the overall health of your scanner.
434

434

00:15:51,900  -->  00:15:54,090
In my case, you can see how much memory is used,
435

435

00:15:54,090  -->  00:15:55,890
what CPU load is currently ongoing,
436

436

00:15:55,890  -->  00:15:58,500
and the hosts that are being scanned as well as some graphs
437

437

00:15:58,500  -->  00:16:00,210
showing all that information.
438

438

00:16:00,210  -->  00:16:02,670
In addition to that, we can look at the network activity
439

439

00:16:02,670  -->  00:16:04,680
by clicking on the network tab over here,
440

440

00:16:04,680  -->  00:16:05,940
and that will show us some information
441

441

00:16:05,940  -->  00:16:08,100
about the running scans and the active targets
442

442

00:16:08,100  -->  00:16:11,040
that we're looking at, as well as what sessions are there.
443

443

00:16:11,040  -->  00:16:13,020
If we want to be able to update our scanner,
444

444

00:16:13,020  -->  00:16:15,000
we want to make sure that we check our about area
445

445

00:16:15,000  -->  00:16:17,130
and this will tell us what version we have as well as
446

446

00:16:17,130  -->  00:16:19,800
what plugin set and policy template version we're using,
447

447

00:16:19,800  -->  00:16:21,930
as you can see over on the right hand side.
448

448

00:16:21,930  -->  00:16:23,910
In addition to that, you can see the fact that
449

449

00:16:23,910  -->  00:16:25,740
this was last updated today,
450

450

00:16:25,740  -->  00:16:27,210
and if I wanted to update it again,
451

451

00:16:27,210  -->  00:16:29,070
I would simply click on the little refresh button
452

452

00:16:29,070  -->  00:16:31,410
next to that to see when the last update was,
453

453

00:16:31,410  -->  00:16:33,120
and if you click on software update,
454

454

00:16:33,120  -->  00:16:35,220
you'll be able to see if it is configured properly
455

455

00:16:35,220  -->  00:16:38,010
to get all of the updates for the components for the plugins
456

456

00:16:38,010  -->  00:16:40,500
or if we disable automatic updates.
457

457

00:16:40,500  -->  00:16:42,840
Personally, I like to use automatic updates,
458

458

00:16:42,840  -->  00:16:44,610
especially when I'm a home user doing this
459

459

00:16:44,610  -->  00:16:45,990
in my home system.
460

460

00:16:45,990  -->  00:16:47,550
If you're in a corporate environment though,
461

461

00:16:47,550  -->  00:16:50,220
do check your policies because some organizations
462

462

00:16:50,220  -->  00:16:52,380
don't want you to update your components or plugins
463

463

00:16:52,380  -->  00:16:53,640
directly from Nessus
464

464

00:16:53,640  -->  00:16:56,037
and instead want to use their own custom server,
465

465

00:16:56,037  -->  00:16:58,620
and you can configure that here under the update server
466

466

00:16:58,620  -->  00:17:01,320
with your custom URL being added in there.
467

467

00:17:01,320  -->  00:17:02,610
All right, now that we have all that,
468

468

00:17:02,610  -->  00:17:04,470
let's go back to our scans and take a look
469

469

00:17:04,470  -->  00:17:06,270
at some of the things that I've already run
470

470

00:17:06,270  -->  00:17:08,310
so we can see what these scans look like.
471

471

00:17:08,310  -->  00:17:09,930
Alright, let's go ahead and take a look
472

472

00:17:09,930  -->  00:17:11,610
at our Windows machines first.
473

473

00:17:11,610  -->  00:17:13,440
Now, I mentioned I had two of them done here.
474

474

00:17:13,440  -->  00:17:16,500
One was a credentialed and one was an uncredentialed scan.
475

475

00:17:16,500  -->  00:17:19,110
Let's take a look at our uncredentialed scan first.
476

476

00:17:19,110  -->  00:17:20,820
If I click on my Windows machine,
477

477

00:17:20,820  -->  00:17:22,740
you'll see that it has its IP address
478

478

00:17:22,740  -->  00:17:25,230
and we have 10 vulnerabilities that were identified.
479

479

00:17:25,230  -->  00:17:27,600
Those vulnerabilities though aren't really that significant
480

480

00:17:27,600  -->  00:17:29,370
because they're just informational.
481

481

00:17:29,370  -->  00:17:33,330
There are no criticals, no highs, no mediums and no lows.
482

482

00:17:33,330  -->  00:17:34,590
As you look at the scan details,
483

483

00:17:34,590  -->  00:17:36,300
you could see when it started and when it stopped,
484

484

00:17:36,300  -->  00:17:39,780
and in this case it took me six minutes to scan one machine.
485

485

00:17:39,780  -->  00:17:42,240
In addition to that, you can click on vulnerabilities,
486

486

00:17:42,240  -->  00:17:44,160
and from here you'll see all 10 vulnerabilities
487

487

00:17:44,160  -->  00:17:46,350
that were found as well as what their severity is,
488

488

00:17:46,350  -->  00:17:49,620
whether it's info low, medium, high or critical,
489

489

00:17:49,620  -->  00:17:51,840
and in my case, they're all informational.
490

490

00:17:51,840  -->  00:17:53,730
In addition to that, you'll have a score
491

491

00:17:53,730  -->  00:17:55,710
that's associated with it, if it is a critical high,
492

492

00:17:55,710  -->  00:17:59,820
medium or low based on CVSS 3.0 or 3.1,
493

493

00:17:59,820  -->  00:18:01,920
as well as the name of that vulnerability,
494

494

00:18:01,920  -->  00:18:04,860
the family of plug-in it came from and the number of counts.
495

495

00:18:04,860  -->  00:18:06,600
In our case, there's only one count for each,
496

496

00:18:06,600  -->  00:18:08,340
because we only scanned one machine,
497

497

00:18:08,340  -->  00:18:09,870
but if I scanned my entire network,
498

498

00:18:09,870  -->  00:18:11,460
like the scan that we just set up,
499

499

00:18:11,460  -->  00:18:13,200
that would actually go and look at all the machines
500

500

00:18:13,200  -->  00:18:15,510
on the network, and in my case, there was five of them,
501

501

00:18:15,510  -->  00:18:17,220
and if two or three of those machines had it,
502

502

00:18:17,220  -->  00:18:19,830
we would see that number here under the count.
503

503

00:18:19,830  -->  00:18:21,720
In addition to that, we also have this tab,
504

504

00:18:21,720  -->  00:18:23,910
called the VPR top threats.
505

505

00:18:23,910  -->  00:18:25,800
Now, this is a proprietary technology
506

506

00:18:25,800  -->  00:18:27,690
used by Tenable the makers of Nessus
507

507

00:18:27,690  -->  00:18:30,120
to tell you what is the most vulnerable things.
508

508

00:18:30,120  -->  00:18:33,720
Now, similar to a CVSS score, you can't rely on these solely
509

509

00:18:33,720  -->  00:18:36,810
because this is just Nessus best guess at what they think
510

510

00:18:36,810  -->  00:18:37,890
is the most vulnerable,
511

511

00:18:37,890  -->  00:18:39,300
but they don't really understand your network
512

512

00:18:39,300  -->  00:18:40,440
as well as you do.
513

513

00:18:40,440  -->  00:18:42,420
For example, they may say that there's a server
514

514

00:18:42,420  -->  00:18:45,120
with a really critical vulnerability that has to be patched,
515

515

00:18:45,120  -->  00:18:46,560
but when you look at that server,
516

516

00:18:46,560  -->  00:18:48,900
it's actually in an isolated subnet that nobody can reach
517

517

00:18:48,900  -->  00:18:51,360
and therefore it's not really that vulnerable to attack,
518

518

00:18:51,360  -->  00:18:53,070
and so it may not be as big of a priority
519

519

00:18:53,070  -->  00:18:55,050
as something that's a high or medium
520

520

00:18:55,050  -->  00:18:57,180
that is publicly facing, such as a web server
521

521

00:18:57,180  -->  00:19:00,060
inside of a screen subnet or demilitarized zone
522

522

00:19:00,060  -->  00:19:02,370
and then the last tab we have is our history tab,
523

523

00:19:02,370  -->  00:19:04,230
and this shows us all the scans that have been made
524

524

00:19:04,230  -->  00:19:05,090
with that profile.
525

525

00:19:05,090  -->  00:19:06,690
In this case, that's my profile
526

526

00:19:06,690  -->  00:19:08,490
of Windows 11 uncredentialed,
527

527

00:19:08,490  -->  00:19:12,180
and you can see here I only scanned one machine one time.
528

528

00:19:12,180  -->  00:19:14,130
If I go back to the vulnerabilities tab,
529

529

00:19:14,130  -->  00:19:15,900
you can also see that these vulnerabilities
530

530

00:19:15,900  -->  00:19:18,390
when you click on them will give you additional information.
531

531

00:19:18,390  -->  00:19:20,700
For example, if I click on the device type,
532

532

00:19:20,700  -->  00:19:22,170
the reason this is informational
533

533

00:19:22,170  -->  00:19:24,630
is because it's saying based on the remote operating system,
534

534

00:19:24,630  -->  00:19:27,600
it's possible to determine what remote system type is,
535

535

00:19:27,600  -->  00:19:29,760
such as a printer, router, general purpose computer,
536

536

00:19:29,760  -->  00:19:31,767
or whatever it is, and we have a 70% confidence level
537

537

00:19:31,767  -->  00:19:34,860
that this is a Windows 11 general purpose machine
538

538

00:19:34,860  -->  00:19:37,440
based on the basic scan that we just did.
539

539

00:19:37,440  -->  00:19:38,460
In addition to all of that,
540

540

00:19:38,460  -->  00:19:40,200
once you have all your vulnerabilities,
541

541

00:19:40,200  -->  00:19:42,030
you don't have to just click through them all here.
542

542

00:19:42,030  -->  00:19:44,160
You can actually do it as a report too.
543

543

00:19:44,160  -->  00:19:46,440
In order to do this, simply click on report
544

544

00:19:46,440  -->  00:19:48,450
and then you'll select the type of report you want,
545

545

00:19:48,450  -->  00:19:51,120
whether you want a complete list of vulnerabilities by host,
546

546

00:19:51,120  -->  00:19:52,830
detailed vulnerabilities by host,
547

547

00:19:52,830  -->  00:19:54,660
detailed vulnerabilities by plugins
548

548

00:19:54,660  -->  00:19:56,910
or vulnerabilities operations.
549

549

00:19:56,910  -->  00:19:59,370
Now, when you do detailed vulnerabilities by host,
550

550

00:19:59,370  -->  00:20:01,020
this is what we're seeing here where we have
551

551

00:20:01,020  -->  00:20:03,660
10 vulnerabilities associated with this single host,
552

552

00:20:03,660  -->  00:20:07,170
but again, if I had five or 10 or 500 machines,
553

553

00:20:07,170  -->  00:20:09,540
I might want to look at the vulnerabilities by plugin
554

554

00:20:09,540  -->  00:20:11,070
so I could say which one has the most
555

555

00:20:11,070  -->  00:20:12,390
or which one is the most critical,
556

556

00:20:12,390  -->  00:20:14,730
and then I could see all the machines associated with that.
557

557

00:20:14,730  -->  00:20:16,320
In our case, we're going to do it by host,
558

558

00:20:16,320  -->  00:20:18,090
because we only have one host scanned here,
559

559

00:20:18,090  -->  00:20:19,920
and then we'll go ahead and hit Generate report here
560

560

00:20:19,920  -->  00:20:22,140
to generate our report as a PDF.
561

561

00:20:22,140  -->  00:20:24,300
You do have three options when generating your report.
562

562

00:20:24,300  -->  00:20:28,380
You can do it as an HTML file, a PDF or a CSV file.
563

563

00:20:28,380  -->  00:20:31,020
In my case, I used a PDF and you can see that PDF
564

564

00:20:31,020  -->  00:20:33,540
is created right here, and it's a 15 page document
565

565

00:20:33,540  -->  00:20:35,730
with all of the vulnerabilities and what they are
566

566

00:20:35,730  -->  00:20:37,140
and how we can fix them.
567

567

00:20:37,140  -->  00:20:39,000
So as we start scrolling through this,
568

568

00:20:39,000  -->  00:20:41,130
we can see that we have a vulnerabilities by host
569

569

00:20:41,130  -->  00:20:42,450
and there's only one host,
570

570

00:20:42,450  -->  00:20:44,220
and then if we go down to page four,
571

571

00:20:44,220  -->  00:20:46,170
we will now see the vulnerabilities.
572

572

00:20:46,170  -->  00:20:49,110
Here we have zero critical, zero high, zero medium
573

573

00:20:49,110  -->  00:20:51,930
and zero low, but we do have 10 informational.
574

574

00:20:51,930  -->  00:20:53,850
We could see when the scan started and stopped,
575

575

00:20:53,850  -->  00:20:55,620
we could see information about that host
576

576

00:20:55,620  -->  00:20:58,020
and then we start seeing the vulnerabilities themselves.
577

577

00:20:58,020  -->  00:20:59,850
For example, the first vulnerability we have
578

578

00:20:59,850  -->  00:21:02,760
is that common platform enumeration or CPE,
579

579

00:21:02,760  -->  00:21:04,830
and this says we are able to figure out
580

580

00:21:04,830  -->  00:21:07,890
what type of system it was, and so as we look at that,
581

581

00:21:07,890  -->  00:21:09,930
we can see the output from it and we can see that
582

582

00:21:09,930  -->  00:21:13,020
it identified us as a Windows host and that is correct.
583

583

00:21:13,020  -->  00:21:14,880
So that is a informational thing.
584

584

00:21:14,880  -->  00:21:16,290
It's not really a dangerous thing,
585

585

00:21:16,290  -->  00:21:17,490
but if you didn't want people to know
586

586

00:21:17,490  -->  00:21:18,810
you're running a Windows machine,
587

587

00:21:18,810  -->  00:21:21,030
you could do some things to obfuscate that
588

588

00:21:21,030  -->  00:21:22,980
and make it report that it's a Linux machine
589

589

00:21:22,980  -->  00:21:25,050
or a Mac machine or something like that.
590

590

00:21:25,050  -->  00:21:26,640
If you wanted to use some kind of security
591

591

00:21:26,640  -->  00:21:28,380
by obscurity technique.
592

592

00:21:28,380  -->  00:21:30,420
Then we can keep scrolling, we'll see the next thing.
593

593

00:21:30,420  -->  00:21:32,370
In our case, we see a device type,
594

594

00:21:32,370  -->  00:21:34,410
and again, we saw this was a general purpose machine.
595

595

00:21:34,410  -->  00:21:35,850
We saw that earlier when we were looking at
596

596

00:21:35,850  -->  00:21:37,920
inside of Nessus tool.
597

597

00:21:37,920  -->  00:21:39,000
As we continue to go down,
598

598

00:21:39,000  -->  00:21:41,430
you'll see more information of all the things we found.
599

599

00:21:41,430  -->  00:21:43,260
Now here, because these were informational,
600

600

00:21:43,260  -->  00:21:45,690
it's not nearly as helpful as when we find things
601

601

00:21:45,690  -->  00:21:47,130
that have true vulnerabilities,
602

602

00:21:47,130  -->  00:21:48,570
because then it will give us information
603

603

00:21:48,570  -->  00:21:51,030
about the vulnerability and how to solve it.
604

604

00:21:51,030  -->  00:21:53,400
Let me show you what that looks like in just a minute.
605

605

00:21:53,400  -->  00:21:55,770
Right now, let's go back to our scans and take a look
606

606

00:21:55,770  -->  00:21:57,360
at our credentialed scan.
607

607

00:21:57,360  -->  00:22:00,240
Now with the uncredentialed scan, we had 10 things found.
608

608

00:22:00,240  -->  00:22:01,710
Here in the credentialed scan,
609

609

00:22:01,710  -->  00:22:03,600
we do find that we have 11 things,
610

610

00:22:03,600  -->  00:22:05,250
and so we can compare the two
611

611

00:22:05,250  -->  00:22:06,780
and we can look at one versus the other
612

612

00:22:06,780  -->  00:22:07,770
and see what the difference is
613

613

00:22:07,770  -->  00:22:09,600
and what that one extra thing was,
614

614

00:22:09,600  -->  00:22:11,340
but again, because these are all informational,
615

615

00:22:11,340  -->  00:22:12,750
it's really not that big of a deal,
616

616

00:22:12,750  -->  00:22:14,610
and so we're going to go look at some other scans
617

617

00:22:14,610  -->  00:22:16,860
that may have some better information for us.
618

618

00:22:16,860  -->  00:22:17,880
The next one we're going to look at
619

619

00:22:17,880  -->  00:22:19,680
is going to be our Kali machine.
620

620

00:22:19,680  -->  00:22:22,560
Our Kali machine is actually a very secure machine as well,
621

621

00:22:22,560  -->  00:22:26,430
having 57 informational items and only one low item here
622

622

00:22:26,430  -->  00:22:27,870
as a vulnerability.
623

623

00:22:27,870  -->  00:22:29,910
This scan actually took 16 minutes to complete
624

624

00:22:29,910  -->  00:22:32,460
on this single machine, and we look at the vulnerabilities,
625

625

00:22:32,460  -->  00:22:34,470
we have 44 of them total.
626

626

00:22:34,470  -->  00:22:36,900
Now the reason there's 44 is because there's lots of them
627

627

00:22:36,900  -->  00:22:40,290
that have multiple issues such as HTTP has three,
628

628

00:22:40,290  -->  00:22:44,280
SSH has four, SSL has five, and things like that.
629

629

00:22:44,280  -->  00:22:46,860
When we look at the SSL one, you can see it says mixed,
630

630

00:22:46,860  -->  00:22:48,450
and the reason for that is when I click on this,
631

631

00:22:48,450  -->  00:22:49,830
it works almost like a folder.
632

632

00:22:49,830  -->  00:22:51,420
You could see there was four informational
633

633

00:22:51,420  -->  00:22:53,550
and one medium vulnerability.
634

634

00:22:53,550  -->  00:22:54,780
This is our first vulnerability
635

635

00:22:54,780  -->  00:22:57,200
that actually is a number or score associated with it.
636

636

00:22:57,200  -->  00:23:01,200
In this case, that's 6.5, giving us a medium classification.
637

637

00:23:01,200  -->  00:23:03,780
If I click on that, we could see the additional information,
638

638

00:23:03,780  -->  00:23:05,790
and in this case it says the SSL certificate
639

639

00:23:05,790  -->  00:23:08,070
cannot be trusted and the reason for this
640

640

00:23:08,070  -->  00:23:10,170
as we look at the output below from the scanner
641

641

00:23:10,170  -->  00:23:12,810
is that we got information from the system we were scanning,
642

642

00:23:12,810  -->  00:23:14,550
in this case, our Kali Linux machine,
643

643

00:23:14,550  -->  00:23:16,290
and it did have information about the subject
644

644

00:23:16,290  -->  00:23:18,150
and issuer of that digital certificate,
645

645

00:23:18,150  -->  00:23:20,730
but it was a self-signed certificate
646

646

00:23:20,730  -->  00:23:22,290
and therefore it's being registered
647

647

00:23:22,290  -->  00:23:24,540
as signed by an unknown certificate authority
648

648

00:23:24,540  -->  00:23:27,270
and that is why this is considered a vulnerability.
649

649

00:23:27,270  -->  00:23:29,460
Now, in my case, because I'm in a lab environment,
650

650

00:23:29,460  -->  00:23:31,560
this isn't really a big vulnerability, and again,
651

651

00:23:31,560  -->  00:23:33,180
it's only a medium level of vulnerability,
652

652

00:23:33,180  -->  00:23:35,700
but it is the only vulnerability we have on the system,
653

653

00:23:35,700  -->  00:23:38,430
and that tells me this Kali machine is rather secure.
654

654

00:23:38,430  -->  00:23:39,990
If I wanted to solve this problem,
655

655

00:23:39,990  -->  00:23:41,580
I could then go through and figure out
656

656

00:23:41,580  -->  00:23:43,470
why is this using a self-signed certificate
657

657

00:23:43,470  -->  00:23:45,510
and how can I get it its own certificate?
658

658

00:23:45,510  -->  00:23:47,700
In this case, it tells me my solution is to purchase
659

659

00:23:47,700  -->  00:23:49,590
or generate a proper SSL certificate
660

660

00:23:49,590  -->  00:23:51,330
for this service, and I can actually go look
661

661

00:23:51,330  -->  00:23:53,190
at those two links to see how to do that
662

662

00:23:53,190  -->  00:23:56,310
or get more information about this particular vulnerability.
663

663

00:23:56,310  -->  00:23:58,350
Let's go ahead and go back to our scans,
664

664

00:23:58,350  -->  00:24:00,750
and from here we're going to go and look at our Mac machine.
665

665

00:24:00,750  -->  00:24:03,390
Now, the Mac machine is a machine I use on a daily basis,
666

666

00:24:03,390  -->  00:24:06,390
and here you can see I have 33 informational
667

667

00:24:06,390  -->  00:24:08,850
and one that is a medium vulnerability.
668

668

00:24:08,850  -->  00:24:10,290
Let's see what that one is.
669

669

00:24:10,290  -->  00:24:12,030
As I click on the vulnerabilities tab,
670

670

00:24:12,030  -->  00:24:13,860
I see there are multiple SSL issues
671

671

00:24:13,860  -->  00:24:16,770
and it's the exact same issue we had on Kali.
672

672

00:24:16,770  -->  00:24:17,790
Now, why is this?
673

673

00:24:17,790  -->  00:24:21,000
Well, on my Mac system, I also have Nessus there
674

674

00:24:21,000  -->  00:24:24,240
and Nessus is using that same self-signed certificate again
675

675

00:24:24,240  -->  00:24:26,910
inside of that installation on my Mac machine,
676

676

00:24:26,910  -->  00:24:28,680
and therefore we're getting the same vulnerability,
677

677

00:24:28,680  -->  00:24:31,710
so I would want to go ahead and install a real certificate
678

678

00:24:31,710  -->  00:24:33,870
instead of using the self-signed one from Nessus
679

679

00:24:33,870  -->  00:24:35,910
to avoid this vulnerability.
680

680

00:24:35,910  -->  00:24:37,650
Next, let's go back to my scans,
681

681

00:24:37,650  -->  00:24:39,450
and from here we're going to look at Ubuntu.
682

682

00:24:39,450  -->  00:24:41,790
Now this a Ubuntu is one that I just installed
683

683

00:24:41,790  -->  00:24:44,070
straight off the CD and all I did
684

684

00:24:44,070  -->  00:24:45,960
was create a user account and then scan it.
685

685

00:24:45,960  -->  00:24:47,970
So there is no patches that have been done,
686

686

00:24:47,970  -->  00:24:50,250
but you can see that Ubuntu is pretty secure
687

687

00:24:50,250  -->  00:24:52,020
straight from its installation.
688

688

00:24:52,020  -->  00:24:54,090
This is because as part of the installation process,
689

689

00:24:54,090  -->  00:24:56,250
Ubuntu usually will download any new patches
690

690

00:24:56,250  -->  00:24:57,960
and vulnerability updates that it has
691

691

00:24:57,960  -->  00:24:59,700
before finishing the installation,
692

692

00:24:59,700  -->  00:25:00,533
and that's why we're seeing
693

693

00:25:00,533  -->  00:25:02,400
that this is a pretty secure machine.
694

694

00:25:02,400  -->  00:25:03,840
If we look at these vulnerabilities,
695

695

00:25:03,840  -->  00:25:05,460
they're all informational again,
696

696

00:25:05,460  -->  00:25:07,560
and from here you can see it's most of the same stuff.
697

697

00:25:07,560  -->  00:25:09,390
We're getting information about the system
698

698

00:25:09,390  -->  00:25:12,330
such as its Mac address, it's IP protocols being scanned
699

699

00:25:12,330  -->  00:25:13,860
and things like that.
700

700

00:25:13,860  -->  00:25:15,870
Let's go back to our scans one more time,
701

701

00:25:15,870  -->  00:25:16,860
and from here you can see that
702

702

00:25:16,860  -->  00:25:18,810
my other two scans are still running.
703

703

00:25:18,810  -->  00:25:20,457
The basic scan of my entire network
704

704

00:25:20,457  -->  00:25:22,410
and the Metasploitable 2 one.
705

705

00:25:22,410  -->  00:25:24,450
Let me go ahead and look at Metasploitable 2 first,
706

706

00:25:24,450  -->  00:25:27,000
because this one has a lot of vulnerabilities.
707

707

00:25:27,000  -->  00:25:29,190
Now, you'll notice here that I can't export this
708

708

00:25:29,190  -->  00:25:30,870
as a report yet, and the reason is,
709

709

00:25:30,870  -->  00:25:32,790
it's still running this scan.
710

710

00:25:32,790  -->  00:25:34,920
I started this scan over an hour ago
711

711

00:25:34,920  -->  00:25:36,660
and we're still at only 99%,
712

712

00:25:36,660  -->  00:25:38,940
but we found a lot of vulnerabilities.
713

713

00:25:38,940  -->  00:25:42,990
Here even at 99%, we can see 171 informational,
714

714

00:25:42,990  -->  00:25:47,430
eight lows, 44 mediums, 13 highs, and 15 criticals.
715

715

00:25:47,430  -->  00:25:49,230
This is a really vulnerable system,
716

716

00:25:49,230  -->  00:25:50,970
and if this was on your production network,
717

717

00:25:50,970  -->  00:25:52,500
you would definitely want to start remediating
718

718

00:25:52,500  -->  00:25:53,730
all these issues.
719

719

00:25:53,730  -->  00:25:55,140
So what are some of these issues?
720

720

00:25:55,140  -->  00:25:57,090
Well, let's go ahead and click on our vulnerabilities
721

721

00:25:57,090  -->  00:25:58,770
and we'll look at the first one we have,
722

722

00:25:58,770  -->  00:26:01,950
which is NFS Exported share Information disclosure,
723

723

00:26:01,950  -->  00:26:04,770
and this is a 10.0, which is critical.
724

724

00:26:04,770  -->  00:26:07,440
You could see it's under the RPC or Remote Procedure Call
725

725

00:26:07,440  -->  00:26:10,830
family of plugins, and it happened one time on the system.
726

726

00:26:10,830  -->  00:26:13,470
If I click on it, I can get more information about it,
727

727

00:26:13,470  -->  00:26:15,420
going down the left, I'll see the description,
728

728

00:26:15,420  -->  00:26:17,820
the solution, and the output we got from the scanner,
729

729

00:26:17,820  -->  00:26:20,010
and on the right we'll see information about the plugin
730

730

00:26:20,010  -->  00:26:22,890
such as its ID, the severity, the version,
731

731

00:26:22,890  -->  00:26:25,290
the type, the family, when it was published
732

732

00:26:25,290  -->  00:26:27,030
and when it was last modified.
733

733

00:26:27,030  -->  00:26:28,860
As you can see, this is a really well known
734

734

00:26:28,860  -->  00:26:32,130
and old vulnerability from all the way back in 2003
735

735

00:26:32,130  -->  00:26:33,750
over 20 years ago.
736

736

00:26:33,750  -->  00:26:35,640
In addition to that, we could see risk information
737

737

00:26:35,640  -->  00:26:38,280
such as what the risk factor, is in this case critical,
738

738

00:26:38,280  -->  00:26:40,170
and the score that it's associated with it,
739

739

00:26:40,170  -->  00:26:42,120
in this case, a 10.0 critical
740

740

00:26:42,120  -->  00:26:44,880
under the CVSS version two standard.
741

741

00:26:44,880  -->  00:26:48,570
Now, why isn't CVSS version three or version 3.1 here?
742

742

00:26:48,570  -->  00:26:50,910
Well, because this is a really old vulnerability
743

743

00:26:50,910  -->  00:26:52,860
from 20 years ago and they haven't updated it
744

744

00:26:52,860  -->  00:26:54,120
to the latest scoring system,
745

745

00:26:54,120  -->  00:26:56,640
but we still know it's very vulnerable.
746

746

00:26:56,640  -->  00:26:59,010
Then we could see vulnerability information on the right
747

747

00:26:59,010  -->  00:27:01,170
that says things like, "Is there an exploit available?"
748

748

00:27:01,170  -->  00:27:02,490
True, yes, there is.
749

749

00:27:02,490  -->  00:27:04,200
That again, makes it even more serious for us
750

750

00:27:04,200  -->  00:27:05,430
to patch this vulnerability,
751

751

00:27:05,430  -->  00:27:07,020
because not only are we vulnerable,
752

752

00:27:07,020  -->  00:27:09,270
but attackers also know how to exploit it.
753

753

00:27:09,270  -->  00:27:11,460
In addition to that, we can see the ease of that exploit
754

754

00:27:11,460  -->  00:27:13,440
is that exploits are publicly available
755

755

00:27:13,440  -->  00:27:15,660
and the vulnerability was first known
756

756

00:27:15,660  -->  00:27:18,270
back on January 1st of 1985,
757

757

00:27:18,270  -->  00:27:21,060
so it's really, really old vulnerability here.
758

758

00:27:21,060  -->  00:27:22,470
You can see what you can exploit it with.
759

759

00:27:22,470  -->  00:27:24,510
In this case, you can use Metasploite,
760

760

00:27:24,510  -->  00:27:26,100
and we can see reference information
761

761

00:27:26,100  -->  00:27:28,050
including the CVEs associated with it,
762

762

00:27:28,050  -->  00:27:29,720
which were all written back in 1999,
763

763

00:27:29,720  -->  00:27:33,780
and you can see that because it says CVE-1999 dash,
764

764

00:27:33,780  -->  00:27:35,820
and then the number for the three CVEs
765

765

00:27:35,820  -->  00:27:37,710
associated with this vulnerability.
766

766

00:27:37,710  -->  00:27:39,660
Let's go back to our vulnerabilities again.
767

767

00:27:39,660  -->  00:27:40,680
We'll click on the next one,
768

768

00:27:40,680  -->  00:27:44,610
which is the REXECD service detection.
769

769

00:27:44,610  -->  00:27:46,800
Here we see that that service is running on the host
770

770

00:27:46,800  -->  00:27:48,420
and it's designed to allow users of the network
771

771

00:27:48,420  -->  00:27:49,830
to execute commands remotely,
772

772

00:27:49,830  -->  00:27:51,360
which could be a bad thing for us
773

773

00:27:51,360  -->  00:27:53,070
as cyber security professionals.
774

774

00:27:53,070  -->  00:27:55,260
So to fix it, you would comment out the exec line
775

775

00:27:55,260  -->  00:27:59,370
inside the /etsy/inetd.configfile
776

776

00:27:59,370  -->  00:28:02,040
and then restart the INETD process.
777

777

00:28:02,040  -->  00:28:03,870
So this one's a pretty easy one to fix,
778

778

00:28:03,870  -->  00:28:06,060
and so we can go in, comment out that line,
779

779

00:28:06,060  -->  00:28:07,740
and then we would be able to restart the process,
780

780

00:28:07,740  -->  00:28:09,180
rescan our system, and verify
781

781

00:28:09,180  -->  00:28:12,060
that this critical vulnerability is no longer there.
782

782

00:28:12,060  -->  00:28:13,920
Let's go ahead and look at our vulnerabilities again.
783

783

00:28:13,920  -->  00:28:15,450
Let's scroll down here and take a look at
784

784

00:28:15,450  -->  00:28:17,670
our bind shell backdoor detection.
785

785

00:28:17,670  -->  00:28:19,980
This one has a 9.8 rating, and again,
786

786

00:28:19,980  -->  00:28:22,860
you can see that this is a shell listening on a remote port
787

787

00:28:22,860  -->  00:28:24,900
without any authentication being required,
788

788

00:28:24,900  -->  00:28:26,160
and this would be a really bad thing
789

789

00:28:26,160  -->  00:28:27,240
because the attacker can use it
790

790

00:28:27,240  -->  00:28:28,530
to connect to the remote port
791

791

00:28:28,530  -->  00:28:30,570
and send commands directly to that system.
792

792

00:28:30,570  -->  00:28:31,560
How do we solve this?
793

793

00:28:31,560  -->  00:28:33,360
Well, we want to verify if the remote host
794

794

00:28:33,360  -->  00:28:35,370
has been compromised and then reinstall the system
795

795

00:28:35,370  -->  00:28:36,360
if necessary.
796

796

00:28:36,360  -->  00:28:38,340
Essentially, we think this is a backdoor
797

797

00:28:38,340  -->  00:28:39,630
or a root kit of some kind,
798

798

00:28:39,630  -->  00:28:41,160
and this would be a really bad thing,
799

799

00:28:41,160  -->  00:28:42,900
so we would want to be able to fix that
800

800

00:28:42,900  -->  00:28:44,640
and again, you can see all the details there,
801

801

00:28:44,640  -->  00:28:48,060
including the CVSS scores over on the right hand side.
802

802

00:28:48,060  -->  00:28:49,620
If we go back to our vulnerabilities,
803

803

00:28:49,620  -->  00:28:50,730
we can look at some other ones,
804

804

00:28:50,730  -->  00:28:53,100
such as our highs, our mediums, or our lows
805

805

00:28:53,100  -->  00:28:54,270
by clicking through all of these,
806

806

00:28:54,270  -->  00:28:56,130
but because there are so many here,
807

807

00:28:56,130  -->  00:28:59,610
what I would probably do is instead I would run my report,
808

808

00:28:59,610  -->  00:29:02,370
export that as a PDF, showing me all the vulnerabilities,
809

809

00:29:02,370  -->  00:29:04,920
including all of the solutions for those vulnerabilities,
810

810

00:29:04,920  -->  00:29:07,170
and then we can pass that over to our system administrators
811

811

00:29:07,170  -->  00:29:08,400
in a prioritized manner,
812

812

00:29:08,400  -->  00:29:10,320
which tells 'em which things we want them to fix first,
813

813

00:29:10,320  -->  00:29:12,150
and then once they tell us they've done that,
814

814

00:29:12,150  -->  00:29:15,240
we would re-scan the system to see if our 95 vulnerabilities
815

815

00:29:15,240  -->  00:29:19,890
now went down to 50 or 40 or 20 or 10 or maybe even zero,
816

816

00:29:19,890  -->  00:29:22,140
but that's probably not going to happen because as you saw,
817

817

00:29:22,140  -->  00:29:25,350
even really secure hosts still have five or 10 or 15
818

818

00:29:25,350  -->  00:29:27,870
of these informational things and on this system,
819

819

00:29:27,870  -->  00:29:29,610
we have quite a few informational as well
820

820

00:29:29,610  -->  00:29:32,610
with 57% of our findings being informational,
821

821

00:29:32,610  -->  00:29:34,830
but again, what I'm really worried about is these criticals,
822

822

00:29:34,830  -->  00:29:36,840
these highs, and then even the mediums.
823

823

00:29:36,840  -->  00:29:38,790
The lows don't usually worry me as much,
824

824

00:29:38,790  -->  00:29:39,660
and then the informational
825

825

00:29:39,660  -->  00:29:41,460
don't usually worry me as much either.
826

826

00:29:41,460  -->  00:29:42,810
These are the kind of things you need to look at
827

827

00:29:42,810  -->  00:29:45,060
as you're going through a tool like Nessus.
828

828

00:29:45,060  -->  00:29:46,740
The last one we have is our basic scan
829

829

00:29:46,740  -->  00:29:48,180
of the entire network.
830

830

00:29:48,180  -->  00:29:50,130
Now here you can see that I had four machines
831

831

00:29:50,130  -->  00:29:52,380
inside of the scope of this particular scan,
832

832

00:29:52,380  -->  00:29:54,240
and the one that isn't there is Metasploitable
833

833

00:29:54,240  -->  00:29:57,030
because I added that in after this scan started.
834

834

00:29:57,030  -->  00:29:59,910
Now because of that, you can see which machines we have
835

835

00:29:59,910  -->  00:30:03,420
in this case, the dot 136 is my Kali Linux machine.
836

836

00:30:03,420  -->  00:30:05,850
The dot 116 is my MAC system.
837

837

00:30:05,850  -->  00:30:08,490
The dot 138 is my Windows 11 system,
838

838

00:30:08,490  -->  00:30:11,160
and my dot 137 is my Ubuntu system.
839

839

00:30:11,160  -->  00:30:13,350
As you can see here, this is what you want your network
840

840

00:30:13,350  -->  00:30:14,183
to look like.
841

841

00:30:14,183  -->  00:30:15,840
This is a nice clean scan.
842

842

00:30:15,840  -->  00:30:17,730
We only have two low vulnerabilities,
843

843

00:30:17,730  -->  00:30:19,800
and those low vulnerabilities were basically
844

844

00:30:19,800  -->  00:30:21,690
self-signed certificates for the SSL
845

845

00:30:21,690  -->  00:30:23,820
being run on the Nessus scanner itself.
846

846

00:30:23,820  -->  00:30:26,040
So that tells me these systems aren't that vulnerable
847

847

00:30:26,040  -->  00:30:28,200
to attack and they're in a pretty good shape.
848

848

00:30:28,200  -->  00:30:29,820
This is what you want your systems to look like
849

849

00:30:29,820  -->  00:30:32,160
by the time you're done doing all your remediation.
850

850

00:30:32,160  -->  00:30:34,590
Unfortunately though, in most production networks,
851

851

00:30:34,590  -->  00:30:36,990
your scans are going to look a lot more like this
852

852

00:30:36,990  -->  00:30:38,820
than they are the one that I just showed you
853

853

00:30:38,820  -->  00:30:41,220
and the reason for that is sometimes systems are offline
854

854

00:30:41,220  -->  00:30:42,510
when people push patches.
855

855

00:30:42,510  -->  00:30:44,550
Sometimes the systems don't take the patches.
856

856

00:30:44,550  -->  00:30:46,080
Sometimes people say, Remind me later,
857

857

00:30:46,080  -->  00:30:48,030
instead of installing those security patches,
858

858

00:30:48,030  -->  00:30:49,140
and for all those reasons,
859

859

00:30:49,140  -->  00:30:51,360
you start getting vulnerabilities in your system.
860

860

00:30:51,360  -->  00:30:53,640
The nice thing about using a tool like Nessus though,
861

861

00:30:53,640  -->  00:30:56,370
is by going through these and scanning an entire network,
862

862

00:30:56,370  -->  00:30:57,810
you're going to be able to see very quickly
863

863

00:30:57,810  -->  00:31:00,000
which machines you need to focus your efforts on.
864

864

00:31:00,000  -->  00:31:02,910
So if I saw these four, plus the Metasploitable 2 VM
865

865

00:31:02,910  -->  00:31:03,930
on the screen,
866

866

00:31:03,930  -->  00:31:06,420
I would know immediately that the Metasploitable 2 VM
867

867

00:31:06,420  -->  00:31:07,830
is the one I need to worry about,
868

868

00:31:07,830  -->  00:31:10,080
because it already had so much other things
869

869

00:31:10,080  -->  00:31:12,360
that were critical, high, medium, and low
870

870

00:31:12,360  -->  00:31:13,860
in addition to the informational
871

871

00:31:13,860  -->  00:31:15,930
and so that's where my attention would go.
872

872

00:31:15,930  -->  00:31:17,580
That's the idea of using one of these tools
873

873

00:31:17,580  -->  00:31:19,230
to identify what things are on your network
874

874

00:31:19,230  -->  00:31:20,910
that are vulnerable and what things you can do
875

875

00:31:20,910  -->  00:31:22,383
to fix those vulnerabilities.
