1
1

00:00:00,360  -->  00:00:01,530
<v Narrator>Nessus.</v>
2

2

00:00:01,530  -->  00:00:03,720
In this lesson, we are going to start talking
3

3

00:00:03,720  -->  00:00:07,380
about a vulnerability scanner, and this one is Nessus.
4

4

00:00:07,380  -->  00:00:09,990
Now, Nessus is a commercial vulnerability scanner
5

5

00:00:09,990  -->  00:00:12,210
that's produced by Tenable Network Security
6

6

00:00:12,210  -->  00:00:15,420
for on-premise and cloud-based vulnerability scanning.
7

7

00:00:15,420  -->  00:00:17,160
Now, Nessus is a great product
8

8

00:00:17,160  -->  00:00:19,800
and as a home user, you are free to download it
9

9

00:00:19,800  -->  00:00:22,680
and use it on your home network free of charge,
10

10

00:00:22,680  -->  00:00:25,170
with even including an unlimited subscription.
11

11

00:00:25,170  -->  00:00:26,880
Now, if you're going to use it in a business environment,
12

12

00:00:26,880  -->  00:00:28,140
you do have to pay for it though,
13

13

00:00:28,140  -->  00:00:31,200
because it is considered a commercial piece of software.
14

14

00:00:31,200  -->  00:00:33,270
And so, if you want access to their subscription service,
15

15

00:00:33,270  -->  00:00:35,070
which has all the latest plug-ins
16

16

00:00:35,070  -->  00:00:37,200
that have all the vulnerabilities that you need to test for,
17

17

00:00:37,200  -->  00:00:38,640
you do need to have a subscription
18

18

00:00:38,640  -->  00:00:40,680
if you're using it under a commercial license.
19

19

00:00:40,680  -->  00:00:42,960
But for us, as home users, and you want to
20

20

00:00:42,960  -->  00:00:45,000
start getting practice with a vulnerability scanner,
21

21

00:00:45,000  -->  00:00:46,980
I definitely recommend downloading Nessus
22

22

00:00:46,980  -->  00:00:48,540
and start scanning your own network.
23

23

00:00:48,540  -->  00:00:51,240
Start getting used to what it looks like to run these scans
24

24

00:00:51,240  -->  00:00:53,880
and identify vulnerabilities within your own home networks.
25

25

00:00:53,880  -->  00:00:54,987
There is no cost to do so,
26

26

00:00:54,987  -->  00:00:57,570
and it would really help you out on the exam.
27

27

00:00:57,570  -->  00:01:00,750
Now, when we talk about plug-ins, Nessus uses plug-ins.
28

28

00:01:00,750  -->  00:01:02,353
And these are created using what's known
29

29

00:01:02,353  -->  00:01:05,460
as the Nessus Attack Scripting Language.
30

30

00:01:05,460  -->  00:01:06,840
Each of these plug-ins, there's one
31

31

00:01:06,840  -->  00:01:09,570
for every single vulnerability that it's going to test.
32

32

00:01:09,570  -->  00:01:11,370
So as you look at the plug-ins for Windows,
33

33

00:01:11,370  -->  00:01:13,620
there are hundreds of vulnerabilities in Windows
34

34

00:01:13,620  -->  00:01:15,780
and there are plug-ins for each one of those.
35

35

00:01:15,780  -->  00:01:17,880
That is essentially the signatures
36

36

00:01:17,880  -->  00:01:20,520
that Nessus is using to test those vulnerabilities
37

37

00:01:20,520  -->  00:01:22,110
across the network.
38

38

00:01:22,110  -->  00:01:23,790
Now, when you run a Nessus scan,
39

39

00:01:23,790  -->  00:01:25,950
you're going to get something that looks like this
40

40

00:01:25,950  -->  00:01:27,750
once the scan is done.
41

41

00:01:27,750  -->  00:01:29,700
This will give you your scan results.
42

42

00:01:29,700  -->  00:01:31,530
And now as you start looking at these results,
43

43

00:01:31,530  -->  00:01:33,600
it makes it really easy from this dashboard
44

44

00:01:33,600  -->  00:01:35,940
to identify what is vulnerable.
45

45

00:01:35,940  -->  00:01:38,179
For instance, just looking here on this screen,
46

46

00:01:38,179  -->  00:01:40,508
which do you think is the most vulnerable host
47

47

00:01:40,508  -->  00:01:42,150
that has the most amount of issues
48

48

00:01:42,150  -->  00:01:43,770
that I would want to look at first?
49

49

00:01:43,770  -->  00:01:46,950
Would it be WIN7, Accounts or Marketing?
50

50

00:01:46,950  -->  00:01:48,210
It'd be WIN7, right?
51

51

00:01:48,210  -->  00:01:50,967
Because it has the most critical and the most high
52

52

00:01:50,967  -->  00:01:53,040
and the most overall, in fact.
53

53

00:01:53,040  -->  00:01:54,600
And so, that Windows 7 machine
54

54

00:01:54,600  -->  00:01:57,120
is the most vulnerable of these three machines.
55

55

00:01:57,120  -->  00:01:59,160
Now, does that mean it holds the most danger?
56

56

00:01:59,160  -->  00:02:00,549
Well, maybe, maybe not.
57

57

00:02:00,549  -->  00:02:02,820
Depends what's that machine being used for?
58

58

00:02:02,820  -->  00:02:05,280
Again, the accounting machine might have
59

59

00:02:05,280  -->  00:02:06,480
all of our bank account numbers
60

60

00:02:06,480  -->  00:02:08,430
and all of our credit card processing data,
61

61

00:02:08,430  -->  00:02:10,290
in which case, it would be more of a vulnerability
62

62

00:02:10,290  -->  00:02:12,780
for me to go after, based on data criticality.
63

63

00:02:12,780  -->  00:02:14,370
So that's why you can't just take these numbers
64

64

00:02:14,370  -->  00:02:16,200
at their word, you have to look into them
65

65

00:02:16,200  -->  00:02:19,260
and use your brain to figure out what is most important.
66

66

00:02:19,260  -->  00:02:21,030
Now, from this screen, you can actually click
67

67

00:02:21,030  -->  00:02:23,490
into that number 18 where those criticals are
68

68

00:02:23,490  -->  00:02:25,740
and see a list of all the critical findings.
69

69

00:02:25,740  -->  00:02:28,020
And you can see here, all these were critical.
70

70

00:02:28,020  -->  00:02:30,240
You'll see the plug-in name, the plug-in family,
71

71

00:02:30,240  -->  00:02:32,490
and the amount of count that we have.
72

72

00:02:32,490  -->  00:02:35,610
So the top one there is actually a count of three.
73

73

00:02:35,610  -->  00:02:37,380
We only scanned three workstations,
74

74

00:02:37,380  -->  00:02:40,470
so that means all three of them have this vulnerability.
75

75

00:02:40,470  -->  00:02:41,760
As I look further down the list,
76

76

00:02:41,760  -->  00:02:43,530
I see some that only have one count,
77

77

00:02:43,530  -->  00:02:45,570
which may be only on the Windows 7 machine
78

78

00:02:45,570  -->  00:02:47,740
and not on Accounts or not on Marketing.
79

79

00:02:47,740  -->  00:02:49,350
And so, this is the idea of how you
80

80

00:02:49,350  -->  00:02:50,820
can start going through these reports
81

81

00:02:50,820  -->  00:02:53,370
and figuring out where you need to focus your attention.
82

82

00:02:53,370  -->  00:02:55,560
If I have something that has a three count,
83

83

00:02:55,560  -->  00:02:57,870
in this case 'cause I had three pieces on the network,
84

84

00:02:57,870  -->  00:03:00,360
that tells me that every machine is affected by this,
85

85

00:03:00,360  -->  00:03:01,950
which means it's pretty vulnerable,
86

86

00:03:01,950  -->  00:03:03,720
I have a very large attack surface.
87

87

00:03:03,720  -->  00:03:05,280
So I would want to look into that,
88

88

00:03:05,280  -->  00:03:06,330
figure out is there a way for me
89

89

00:03:06,330  -->  00:03:07,830
to protect ourself from this,
90

90

00:03:07,830  -->  00:03:10,073
whether that means blocking something at the firewall,
91

91

00:03:10,073  -->  00:03:13,410
installing a software patch, or something of that nature.
92

92

00:03:13,410  -->  00:03:15,390
Now, if you want to get even more details,
93

93

00:03:15,390  -->  00:03:16,770
you can click into one of those.
94

94

00:03:16,770  -->  00:03:19,214
For instance, let's go ahead and click into that first one
95

95

00:03:19,214  -->  00:03:21,414
that affects all three machines.
96

96

00:03:21,414  -->  00:03:24,150
As I click into that, I get a lot more details.
97

97

00:03:24,150  -->  00:03:25,680
So going from the top down,
98

98

00:03:25,680  -->  00:03:27,780
we're going to see this is a critical vulnerability.
99

99

00:03:27,780  -->  00:03:30,660
It is Microsoft 15-034.
100

100

00:03:30,660  -->  00:03:33,420
Now, Nessus is not showing me the CVE number here.
101

101

00:03:33,420  -->  00:03:35,820
They're showing me the knowledge base article number.
102

102

00:03:35,820  -->  00:03:37,560
So if I went to Microsoft's website
103

103

00:03:37,560  -->  00:03:41,460
and went to MS15-034, there's a patch that I can download
104

104

00:03:41,460  -->  00:03:44,250
and install to protect my systems based on that number.
105

105

00:03:44,250  -->  00:03:45,600
It'll gimme a short description
106

106

00:03:45,600  -->  00:03:47,940
of what this vulnerability is, what the solution is,
107

107

00:03:47,940  -->  00:03:49,950
in this case, there's a patch from Microsoft,
108

108

00:03:49,950  -->  00:03:51,600
go download it and install it,
109

109

00:03:51,600  -->  00:03:53,910
and then a direct link to the tech article
110

110

00:03:53,910  -->  00:03:56,580
for that knowledge base over on Microsoft's website
111

111

00:03:56,580  -->  00:03:58,020
where I can download it.
112

112

00:03:58,020  -->  00:03:59,520
It'll also show me what the output is
113

113

00:03:59,520  -->  00:04:02,610
that Nessus expects to see when it tries to probe for this,
114

114

00:04:02,610  -->  00:04:05,250
and any other information as you go down.
115

115

00:04:05,250  -->  00:04:06,630
As you look at the bottom, it actually tells you
116

116

00:04:06,630  -->  00:04:09,150
what ports were being used on this test and which hosts.
117

117

00:04:09,150  -->  00:04:10,620
And that's where my screen got cut off,
118

118

00:04:10,620  -->  00:04:11,970
but you could see Accounts.
119

119

00:04:11,970  -->  00:04:14,670
That machine was one that was being affected.
120

120

00:04:14,670  -->  00:04:15,870
On the right side, you could see
121

121

00:04:15,870  -->  00:04:17,550
the details about this plug-in.
122

122

00:04:17,550  -->  00:04:19,410
You could see it's a critical severity,
123

123

00:04:19,410  -->  00:04:20,880
you could see a unique ID number,
124

124

00:04:20,880  -->  00:04:22,500
you could see what version it is,
125

125

00:04:22,500  -->  00:04:24,600
whether it's a local type or a network type,
126

126

00:04:24,600  -->  00:04:25,920
if it's going to be in which type of family.
127

127

00:04:25,920  -->  00:04:27,600
In this case it's Microsoft Windows
128

128

00:04:27,600  -->  00:04:29,670
knowledge base articles, those bulletins.
129

129

00:04:29,670  -->  00:04:31,860
And then when it was published and when it was modified.
130

130

00:04:31,860  -->  00:04:33,300
You could also see some risk information.
131

131

00:04:33,300  -->  00:04:34,800
This is a critical risk factor.
132

132

00:04:34,800  -->  00:04:36,690
The CVSS score here is 10.0,
133

133

00:04:36,690  -->  00:04:39,180
which is the highest it could be, right?
134

134

00:04:39,180  -->  00:04:42,930
The temporal score is an 8.7, so it's been out for a while,
135

135

00:04:42,930  -->  00:04:44,520
so it is less severe at this point
136

136

00:04:44,520  -->  00:04:45,990
because it's older information
137

137

00:04:45,990  -->  00:04:47,970
and most people have been patched to it.
138

138

00:04:47,970  -->  00:04:49,620
As you go down to vulnerability information,
139

139

00:04:49,620  -->  00:04:51,750
you see some information about that as well,
140

140

00:04:51,750  -->  00:04:53,670
such as is there an exploit available?
141

141

00:04:53,670  -->  00:04:55,020
And if there are, that means
142

142

00:04:55,020  -->  00:04:56,340
it's going to be more of a risk to you,
143

143

00:04:56,340  -->  00:04:58,170
so you want to make sure you take care of that.
144

144

00:04:58,170  -->  00:04:59,400
And at the bottom, you could see
145

145

00:04:59,400  -->  00:05:01,500
it's exploitable with Core Impact.
146

146

00:05:01,500  -->  00:05:03,210
Now, what is Core Impact?
147

147

00:05:03,210  -->  00:05:05,400
Well, Core Impact is a commercially available
148

148

00:05:05,400  -->  00:05:07,320
penetration testing tool suite.
149

149

00:05:07,320  -->  00:05:10,710
Now, if Core Impact has a penetration test exploit for this,
150

150

00:05:10,710  -->  00:05:13,140
that means most hackers do too.
151

151

00:05:13,140  -->  00:05:15,240
So if it's already there with Core Impact,
152

152

00:05:15,240  -->  00:05:18,030
that means it is widely available, anyone can hack this.
153

153

00:05:18,030  -->  00:05:20,790
So this is something I want to fix right away
154

154

00:05:20,790  -->  00:05:23,460
because this is a big vulnerability for us.
155

155

00:05:23,460  -->  00:05:24,510
Now, in addition to looking
156

156

00:05:24,510  -->  00:05:26,250
at all this information within Nessus,
157

157

00:05:26,250  -->  00:05:28,110
I can actually go outside of Nessus
158

158

00:05:28,110  -->  00:05:30,600
and look up information on this vulnerability too.
159

159

00:05:30,600  -->  00:05:32,700
For example, if I go to SANS,
160

160

00:05:32,700  -->  00:05:34,860
I can get some information from the InfoSec Forums
161

161

00:05:34,860  -->  00:05:37,050
on this particular knowledge base article.
162

162

00:05:37,050  -->  00:05:39,690
Again, we can see this is a big vulnerability.
163

163

00:05:39,690  -->  00:05:42,420
It has that big red and yellow text there
164

164

00:05:42,420  -->  00:05:43,950
highlighted on the screen.
165

165

00:05:43,950  -->  00:05:47,070
It says, "We have seen this out in our honeypots."
166

166

00:05:47,070  -->  00:05:48,810
Their honeypots are on the internet,
167

167

00:05:48,810  -->  00:05:49,770
so if they're seeing it,
168

168

00:05:49,770  -->  00:05:51,840
it means there's exploits in the wild.
169

169

00:05:51,840  -->  00:05:53,820
This is something we want to get fixed.
170

170

00:05:53,820  -->  00:05:55,650
And so, this would be a bad vulnerability
171

171

00:05:55,650  -->  00:05:56,988
that we need to start prioritizing
172

172

00:05:56,988  -->  00:06:00,360
to patch our systems and get ourself corrected on this.
173

173

00:06:00,360  -->  00:06:01,800
That's the idea of how you can look
174

174

00:06:01,800  -->  00:06:03,750
at these reports inside of Nessus
175

175

00:06:03,750  -->  00:06:06,600
and how you can use this information to make decisions.
176

176

00:06:06,600  -->  00:06:08,250
Now, for the exam,
177

177

00:06:08,250  -->  00:06:10,710
you don't need to memorize specific vulnerabilities
178

178

00:06:10,710  -->  00:06:12,660
like the one I showed you here in this lesson
179

179

00:06:12,660  -->  00:06:14,610
or EternalBlue that I showed you before.
180

180

00:06:14,610  -->  00:06:16,110
But you do need to be able to read
181

181

00:06:16,110  -->  00:06:18,390
and think through a report or a snippet
182

182

00:06:18,390  -->  00:06:20,310
like what I showed you in this lesson.
183

183

00:06:20,310  -->  00:06:22,440
It would be completely fair on the exam
184

184

00:06:22,440  -->  00:06:25,080
to include something like a vulnerability scanners findings
185

185

00:06:25,080  -->  00:06:27,360
with a short report with one or two items
186

186

00:06:27,360  -->  00:06:29,070
and a description of those vulnerabilities
187

187

00:06:29,070  -->  00:06:30,540
and possible fixes.
188

188

00:06:30,540  -->  00:06:32,940
And then they can ask you to prioritize
189

189

00:06:32,940  -->  00:06:35,610
which should be mitigated first and how.
190

190

00:06:35,610  -->  00:06:37,290
In this example I just showed you,
191

191

00:06:37,290  -->  00:06:39,510
you could see it would be a critical vulnerability.
192

192

00:06:39,510  -->  00:06:42,480
There's an exploit that existed for it and a patch exists.
193

193

00:06:42,480  -->  00:06:44,010
So this would be something that would be
194

194

00:06:44,010  -->  00:06:46,050
a high priority for us to remediate,
195

195

00:06:46,050  -->  00:06:48,030
and we can do that by installing the software patch
196

196

00:06:48,030  -->  00:06:51,513
or update from the manufacturer, in this case, Microsoft.
