1
1

00:00:00,330  -->  00:00:02,089
<v Narrator>OpenVAS and Qualys.</v>
2

2

00:00:02,089  -->  00:00:05,280
In the last lesson, we talked about Nessus,
3

3

00:00:05,280  -->  00:00:07,320
which is a commercially available scanner.
4

4

00:00:07,320  -->  00:00:08,153
In this lesson,
5

5

00:00:08,153  -->  00:00:11,356
I wanted to talk about two more, OpenVAS and Qualys.
6

6

00:00:11,356  -->  00:00:14,815
Now Nessus began its life as an open source software project
7

7

00:00:14,815  -->  00:00:18,000
which means it was available for anybody to download
8

8

00:00:18,000  -->  00:00:19,620
and modify its source code,
9

9

00:00:19,620  -->  00:00:20,940
and the whole community worked
10

10

00:00:20,940  -->  00:00:22,615
at building that product together.
11

11

00:00:22,615  -->  00:00:24,150
At a certain point though,
12

12

00:00:24,150  -->  00:00:25,800
Nessus decided they wanted to switch
13

13

00:00:25,800  -->  00:00:28,320
and they became a commercially viable product.
14

14

00:00:28,320  -->  00:00:29,670
And so they started charging money
15

15

00:00:29,670  -->  00:00:31,140
for commercial users to use it,
16

16

00:00:31,140  -->  00:00:32,753
and they gave it away for home users.
17

17

00:00:32,753  -->  00:00:35,329
Now, when that happened, another product took up,
18

18

00:00:35,329  -->  00:00:37,307
and this is known as OpenVAS.
19

19

00:00:37,307  -->  00:00:40,410
OpenVAS is an open source vulnerability scanner
20

20

00:00:40,410  -->  00:00:43,495
that began its development when Nessus' code base was split.
21

21

00:00:43,495  -->  00:00:46,110
And they split, Nessus went into the commercial realm
22

22

00:00:46,110  -->  00:00:48,630
and OpenVAS went into the open source realm.
23

23

00:00:48,630  -->  00:00:49,710
And from that point forward,
24

24

00:00:49,710  -->  00:00:52,269
OpenVAS has stayed as an open source product.
25

25

00:00:52,269  -->  00:00:55,710
Now, OpenVAS looks a lot like an old school Nessus.
26

26

00:00:55,710  -->  00:00:57,330
If you look at some of the older versions of Nessus,
27

27

00:00:57,330  -->  00:00:58,991
they actually looked almost identical.
28

28

00:00:58,991  -->  00:01:02,280
Over time, Nessus has upgraded their user interface
29

29

00:01:02,280  -->  00:01:03,113
so it looks different,
30

30

00:01:03,113  -->  00:01:05,640
but they still do basically the same functions.
31

31

00:01:05,640  -->  00:01:07,380
So if I look here on the screen,
32

32

00:01:07,380  -->  00:01:09,433
you could see an example of what OpenVAS looks like.
33

33

00:01:09,433  -->  00:01:11,042
You can see that we get a nice report
34

34

00:01:11,042  -->  00:01:13,229
with some donut rings and some bar graphs
35

35

00:01:13,229  -->  00:01:15,570
of all the different vulnerabilities we found,
36

36

00:01:15,570  -->  00:01:16,740
and then we can dig into those
37

37

00:01:16,740  -->  00:01:18,596
and get the information on each of the hosts.
38

38

00:01:18,596  -->  00:01:20,790
Now, the other product I want to talk about
39

39

00:01:20,790  -->  00:01:22,092
here real quick is Qualys.
40

40

00:01:22,092  -->  00:01:24,030
Now, Qualys is a cloud-based
41

41

00:01:24,030  -->  00:01:25,331
vulnerability management solution
42

42

00:01:25,331  -->  00:01:27,090
with installed sensor agents
43

43

00:01:27,090  -->  00:01:28,646
at various points in your network.
44

44

00:01:28,646  -->  00:01:31,311
And then those sensors upload data to the cloud platform
45

45

00:01:31,311  -->  00:01:33,508
and you go to this cloud platform's website
46

46

00:01:33,508  -->  00:01:35,121
to do your analysis.
47

47

00:01:35,121  -->  00:01:37,524
When you do that, it looks something like this.
48

48

00:01:37,524  -->  00:01:41,438
Again, it's another UI similar to what you saw with Nessus.
49

49

00:01:41,438  -->  00:01:43,440
We have some bar graphs and some charts
50

50

00:01:43,440  -->  00:01:44,741
so we can see what's vulnerable.
51

51

00:01:44,741  -->  00:01:46,650
We can see what the top vulnerabilities are,
52

52

00:01:46,650  -->  00:01:48,210
and the top tickets we're working,
53

53

00:01:48,210  -->  00:01:49,890
and we can see the most vulnerable hosts
54

54

00:01:49,890  -->  00:01:51,990
so we know which ones we should look at first.
55

55

00:01:51,990  -->  00:01:53,671
This is the idea of using one of these dashboards
56

56

00:01:53,671  -->  00:01:55,894
to really help you identify what you need to do.
57

57

00:01:55,894  -->  00:01:58,283
Now, again, this was a very short lesson
58

58

00:01:58,283  -->  00:02:00,060
and it was just to introduce you to the idea
59

59

00:02:00,060  -->  00:02:02,342
that there are other vulnerability scanners out there.
60

60

00:02:02,342  -->  00:02:04,761
For the exam, you don't need to know
61

61

00:02:04,761  -->  00:02:07,126
a specific vulnerability scanner in depth.
62

62

00:02:07,126  -->  00:02:10,170
You don't need to be able to use Nessus or OpenVAS
63

63

00:02:10,170  -->  00:02:12,339
or Qualys, or any of the other scanners out there.
64

64

00:02:12,339  -->  00:02:15,090
But you should be comfortable reading the common outputs
65

65

00:02:15,090  -->  00:02:16,732
from each of them in your findings.
66

66

00:02:16,732  -->  00:02:18,000
Now, for the exam,
67

67

00:02:18,000  -->  00:02:19,931
you're not going to get a specific assessment tools output,
68

68

00:02:19,931  -->  00:02:22,020
but instead you're going to get something
69

69

00:02:22,020  -->  00:02:24,360
that looks more whitewashed into a common denominator
70

70

00:02:24,360  -->  00:02:26,612
of what a vulnerability scanner's output might look like.
71

71

00:02:26,612  -->  00:02:27,991
Now, what do I mean by that?
72

72

00:02:27,991  -->  00:02:30,020
Well, if you've already taken the A Plus exam
73

73

00:02:30,020  -->  00:02:32,423
back in the day, you may have gotten a question that said,
74

74

00:02:32,423  -->  00:02:36,199
"Go set up email on a smartphone or on a tablet."
75

75

00:02:36,199  -->  00:02:37,200
And if you did that,
76

76

00:02:37,200  -->  00:02:39,180
they didn't give you an iOS email client
77

77

00:02:39,180  -->  00:02:40,530
or an Android email client.
78

78

00:02:40,530  -->  00:02:42,244
They gave you something that kind of looked like both,
79

79

00:02:42,244  -->  00:02:43,980
but it kind of looked like neither.
80

80

00:02:43,980  -->  00:02:45,766
It was just a generic email program.
81

81

00:02:45,766  -->  00:02:48,870
Now, the same thing's going to apply here with CYSA.
82

82

00:02:48,870  -->  00:02:50,824
They're not going to give you a Nessus output
83

83

00:02:50,824  -->  00:02:53,528
or a Qualys output or an OpenVAS output,
84

84

00:02:53,528  -->  00:02:56,040
but they're going to give you a lot of the same information
85

85

00:02:56,040  -->  00:02:57,935
from that output in a different format.
86

86

00:02:57,935  -->  00:02:59,040
So if you're comfortable
87

87

00:02:59,040  -->  00:03:00,493
with using any of those three tools,
88

88

00:03:00,493  -->  00:03:02,196
you're going to do fine on the exam
89

89

00:03:02,196  -->  00:03:04,140
when you get the output they're going to give you
90

90

00:03:04,140  -->  00:03:05,215
to be able to do your own analysis
91

91

00:03:05,215  -->  00:03:06,693
and pick the right answer.
