1
00:00:00,150 --> 00:00:01,800
In this lesson, I'm going to show you

2
00:00:01,800 --> 00:00:05,250
how you can conduct scanning using a tool like Nessus.

3
00:00:05,250 --> 00:00:06,540
Now, as we go through this lesson,

4
00:00:06,540 --> 00:00:08,910
I'm going to be going through my own sample lab

5
00:00:08,910 --> 00:00:10,290
and be able to do some scans

6
00:00:10,290 --> 00:00:12,960
with Nessus across these different devices.

7
00:00:12,960 --> 00:00:16,230
I'm doing these both individually and as a group.

8
00:00:16,230 --> 00:00:17,580
Now what you're seeing here on the screen

9
00:00:17,580 --> 00:00:20,850
is a visual representation of my current lab network.

10
00:00:20,850 --> 00:00:23,430
Over on the left side, you'll see that at IP address

11
00:00:23,430 --> 00:00:26,670
192.168.1.116.

12
00:00:26,670 --> 00:00:28,140
That is a Mac machine

13
00:00:28,140 --> 00:00:30,240
and that's actually my desktop that I'm using

14
00:00:30,240 --> 00:00:33,390
to record this video to demonstrate how to use Nessus.

15
00:00:33,390 --> 00:00:35,850
In addition to that, I also have a Kali Linux machine,

16
00:00:35,850 --> 00:00:39,030
which is what I'm logged into now as a virtual machine.

17
00:00:39,030 --> 00:00:40,690
All of the things that are starting with

18
00:00:40,690 --> 00:00:45,360
192.168.150.something are part of my virtual network

19
00:00:45,360 --> 00:00:46,680
in the lab environment,

20
00:00:46,680 --> 00:00:49,050
whereas the Mac machine is part of my office network,

21
00:00:49,050 --> 00:00:51,120
which is why it has a different IP address

22
00:00:51,120 --> 00:00:54,600
starting with 192.168.1.something.

23
00:00:54,600 --> 00:00:55,830
Now, as you look at the circle,

24
00:00:55,830 --> 00:00:57,390
you'll see that there are different devices

25
00:00:57,390 --> 00:00:59,340
that are connected to this virtual network,

26
00:00:59,340 --> 00:01:02,777
including a Windows 11 machine at 192.168.150.138.

27
00:01:04,769 --> 00:01:07,500
My local host, which is also my Kali Linux machine,

28
00:01:07,500 --> 00:01:11,430
which is 192.168.150.129.

29
00:01:11,430 --> 00:01:13,830
My Metasploitable 2 virtual machine is going to be

30
00:01:13,830 --> 00:01:16,170
a very vulnerable client for us to us find a lot of issues

31
00:01:16,170 --> 00:01:21,170
and vulnerabilities with and that's at 192.168.150.136.

32
00:01:21,537 --> 00:01:23,103
And an Ubuntu Linux machine

33
00:01:23,103 --> 00:01:28,103
that is located at 192.168.150.137.

34
00:01:28,350 --> 00:01:30,777
Now, the Windows 11 machine, the Ubuntu machine,

35
00:01:30,777 --> 00:01:33,930
and the Kali Linux machine should all be relatively secure

36
00:01:33,930 --> 00:01:35,280
because they've just been installed

37
00:01:35,280 --> 00:01:37,980
and they've been updated with the latest security patches.

38
00:01:37,980 --> 00:01:40,020
The Metasploitable 2 machine, on the other hand,

39
00:01:40,020 --> 00:01:42,030
will probably find a lot of vulnerabilities

40
00:01:42,030 --> 00:01:44,550
because it is a vulnerable machine by default,

41
00:01:44,550 --> 00:01:45,840
and we use this to be able to practice

42
00:01:45,840 --> 00:01:47,220
our penetration testing skills

43
00:01:47,220 --> 00:01:49,410
or our cybersecurity analyst skills

44
00:01:49,410 --> 00:01:50,670
by finding those vulnerabilities

45
00:01:50,670 --> 00:01:53,550
and then trying to patch them, re-scanning the machine,

46
00:01:53,550 --> 00:01:54,810
and then seeing if we've solved

47
00:01:54,810 --> 00:01:56,940
those vulnerabilities in the network.

48
00:01:56,940 --> 00:01:58,800
All right, now that we have a basic understanding

49
00:01:58,800 --> 00:02:00,480
of the network that we're going to be using,

50
00:02:00,480 --> 00:02:03,180
let's go ahead and move into looking at Nessus.

51
00:02:03,180 --> 00:02:05,700
All right. Here you can see the Tenable website,

52
00:02:05,700 --> 00:02:08,009
and if you go to tenable.com, you can search

53
00:02:08,009 --> 00:02:09,960
for the Nessus Essentials tool.

54
00:02:09,960 --> 00:02:12,570
This is a free tool that used to be called Nessus Home,

55
00:02:12,570 --> 00:02:14,310
and it allows you to scan your environment,

56
00:02:14,310 --> 00:02:15,840
including all of your network,

57
00:02:15,840 --> 00:02:18,330
up to 16 IP addresses per scanner,

58
00:02:18,330 --> 00:02:20,670
using the same high speed in-depth assessments

59
00:02:20,670 --> 00:02:23,400
that you'd get with the professional version of Nessus.

60
00:02:23,400 --> 00:02:25,020
As a cybersecurity analyst,

61
00:02:25,020 --> 00:02:27,360
you need to get comfortable using vulnerability scanners

62
00:02:27,360 --> 00:02:29,130
like Nessus and OpenVAS,

63
00:02:29,130 --> 00:02:30,540
because depending on where you work,

64
00:02:30,540 --> 00:02:33,570
you'll either be using Nessus or OpenVAS or QualysGuard

65
00:02:33,570 --> 00:02:35,310
or some other vulnerability scanner,

66
00:02:35,310 --> 00:02:37,710
but most of them work pretty much the same way.

67
00:02:37,710 --> 00:02:40,080
So in this lesson we're going to use Nessus Essentials

68
00:02:40,080 --> 00:02:41,730
because it is something that is free to use

69
00:02:41,730 --> 00:02:42,690
and you can download it

70
00:02:42,690 --> 00:02:44,760
and do this on your own home network as well,

71
00:02:44,760 --> 00:02:47,010
to see what vulnerabilities exist there.

72
00:02:47,010 --> 00:02:49,200
To do that, simply go to this webpage,

73
00:02:49,200 --> 00:02:51,510
enter in your first name, last name, and email address.

74
00:02:51,510 --> 00:02:52,920
They'll take you to the download page

75
00:02:52,920 --> 00:02:55,530
and they'll email you an activation code with a license key

76
00:02:55,530 --> 00:02:57,540
that is good for about five years

77
00:02:57,540 --> 00:02:59,460
for you to be able to start playing with Nessus

78
00:02:59,460 --> 00:03:01,740
and getting used to how it works.

79
00:03:01,740 --> 00:03:03,900
Once you have Nessus installed on your computer,

80
00:03:03,900 --> 00:03:06,150
it's going to run as a program in the background

81
00:03:06,150 --> 00:03:07,770
and essentially starts up a web server

82
00:03:07,770 --> 00:03:10,140
that you can access on your local machine.

83
00:03:10,140 --> 00:03:14,100
To access this, you'll go to local host colon 8834,

84
00:03:14,100 --> 00:03:16,620
which is port 8834 on your local host,

85
00:03:16,620 --> 00:03:18,780
which is the machine you're accessing it from.

86
00:03:18,780 --> 00:03:21,390
In my case, that's my Kali Linux machine.

87
00:03:21,390 --> 00:03:23,250
Once you're there, you're going to walk through the setup

88
00:03:23,250 --> 00:03:25,110
wizard and then you'll create an account.

89
00:03:25,110 --> 00:03:26,700
In my case, I've already done that,

90
00:03:26,700 --> 00:03:28,890
so I'm just going to go ahead and log in using my account,

91
00:03:28,890 --> 00:03:30,123
which is Dion Training.

92
00:03:32,220 --> 00:03:34,020
Once you've done that, you'll be brought into

93
00:03:34,020 --> 00:03:35,520
the My Scan screen.

94
00:03:35,520 --> 00:03:36,690
Now the first time you do this,

95
00:03:36,690 --> 00:03:38,310
you're going to have nothing listed here

96
00:03:38,310 --> 00:03:40,710
because it is going to be a blank scan

97
00:03:40,710 --> 00:03:42,480
because you haven't done anything with Nessus yet

98
00:03:42,480 --> 00:03:44,010
because it's a brand new install.

99
00:03:44,010 --> 00:03:46,140
In my case, I've already done a couple of these scans

100
00:03:46,140 --> 00:03:48,360
for us, so that way we'll be able to look at the results

101
00:03:48,360 --> 00:03:49,920
without having to wait a long time

102
00:03:49,920 --> 00:03:51,960
for them to come back from doing the scans.

103
00:03:51,960 --> 00:03:53,730
These scans can take a really long time

104
00:03:53,730 --> 00:03:55,590
depending on the size of your network.

105
00:03:55,590 --> 00:03:58,710
Even for a really small lab environment like the one I have,

106
00:03:58,710 --> 00:03:59,910
I have that top scan,

107
00:03:59,910 --> 00:04:02,040
which is a basic scan of my entire network.

108
00:04:02,040 --> 00:04:05,340
It has been running for about 45 minutes at this point.

109
00:04:05,340 --> 00:04:06,570
Now, in order to use Nessus,

110
00:04:06,570 --> 00:04:08,340
you need to create a scan profile

111
00:04:08,340 --> 00:04:11,160
and you can see I have several of them already created here.

112
00:04:11,160 --> 00:04:12,870
I'm going to walk you through how you can create your own

113
00:04:12,870 --> 00:04:14,520
scan profile, and then we'll take a look

114
00:04:14,520 --> 00:04:16,320
at some of the results from my scanning profiles

115
00:04:16,320 --> 00:04:17,760
that have already been run.

116
00:04:17,760 --> 00:04:20,730
To do this, simply click New Scan at the top right corner

117
00:04:20,730 --> 00:04:22,950
of your screen, and then from here you'll see

118
00:04:22,950 --> 00:04:24,630
all the different types of scanners you have,

119
00:04:24,630 --> 00:04:26,850
including discovery scanners, to be able to figure out

120
00:04:26,850 --> 00:04:29,460
what hosts are on the network, vulnerability scanners

121
00:04:29,460 --> 00:04:31,680
that will target specific vulnerabilities,

122
00:04:31,680 --> 00:04:34,020
or we also have compliance scans.

123
00:04:34,020 --> 00:04:35,820
Now, when you're using Nessus Essentials,

124
00:04:35,820 --> 00:04:37,320
compliance scans are not something

125
00:04:37,320 --> 00:04:38,760
you're going to be able to use.

126
00:04:38,760 --> 00:04:40,560
These compliance scans are things like

127
00:04:40,560 --> 00:04:43,080
PCI DSS internal network scans

128
00:04:43,080 --> 00:04:44,850
or offline configuration audits,

129
00:04:44,850 --> 00:04:46,980
or the PCI quarterly external scans

130
00:04:46,980 --> 00:04:48,630
that are required once a quarter

131
00:04:48,630 --> 00:04:50,670
if your organization takes credit cards

132
00:04:50,670 --> 00:04:52,470
as part of their business model.

133
00:04:52,470 --> 00:04:53,700
All these are things that are included

134
00:04:53,700 --> 00:04:55,860
with the Nessus professional and expert versions,

135
00:04:55,860 --> 00:04:58,590
but in the home version, which is Nessus Essentials,

136
00:04:58,590 --> 00:04:59,940
these are actually blocked out

137
00:04:59,940 --> 00:05:02,070
and you have to pay to get access to those.

138
00:05:02,070 --> 00:05:02,903
For most of us though,

139
00:05:02,903 --> 00:05:04,290
if we're doing this in our home network,

140
00:05:04,290 --> 00:05:05,910
those don't actually matter that much

141
00:05:05,910 --> 00:05:07,650
because you're probably not processing credit cards

142
00:05:07,650 --> 00:05:10,320
on your home computer and instead you're more focused

143
00:05:10,320 --> 00:05:11,610
on the things that are above,

144
00:05:11,610 --> 00:05:12,960
which are the different vulnerabilities

145
00:05:12,960 --> 00:05:14,940
or the discovery scan.

146
00:05:14,940 --> 00:05:16,890
Now, if you're looking at these different vulnerabilities,

147
00:05:16,890 --> 00:05:18,240
you'll notice these are targeted

148
00:05:18,240 --> 00:05:20,490
for specific groups of vulnerabilities.

149
00:05:20,490 --> 00:05:22,590
For example, you can see in the middle of my screen

150
00:05:22,590 --> 00:05:24,870
there's one called the WannaCry Ransomware.

151
00:05:24,870 --> 00:05:27,390
This was really popular back in 2017

152
00:05:27,390 --> 00:05:29,760
and affected all Windows machines at the time.

153
00:05:29,760 --> 00:05:31,470
When something like that comes out,

154
00:05:31,470 --> 00:05:32,850
a lot of times Nessus will create

155
00:05:32,850 --> 00:05:36,180
a specific scan vulnerability for that one plugin.

156
00:05:36,180 --> 00:05:38,730
This way you can quickly look across your entire network,

157
00:05:38,730 --> 00:05:40,800
even if you have a hundred or a thousand machines,

158
00:05:40,800 --> 00:05:43,230
and check just for that one vulnerability.

159
00:05:43,230 --> 00:05:44,310
That's the reason why you're seeing

160
00:05:44,310 --> 00:05:45,257
these vulnerabilities listed here,

161
00:05:45,257 --> 00:05:47,910
because these are the ones that were really, really important

162
00:05:47,910 --> 00:05:50,580
to look for, things like Specter and Meltdown

163
00:05:50,580 --> 00:05:53,910
and WannaCry and Ripple20, and things like that.

164
00:05:53,910 --> 00:05:56,340
So for our cases, we're not going to look at just a single

165
00:05:56,340 --> 00:05:57,630
vulnerability, but we want to look at

166
00:05:57,630 --> 00:06:00,360
what vulnerabilities exist across the entire network

167
00:06:00,360 --> 00:06:03,150
so we can get a better idea of exactly what vulnerabilities

168
00:06:03,150 --> 00:06:04,650
exist right now in our network

169
00:06:04,650 --> 00:06:07,530
and create a baseline for us to use as we move forward.

170
00:06:07,530 --> 00:06:09,960
To do this, we're going to do a basic scan.

171
00:06:09,960 --> 00:06:11,040
So I'm just going to click over here

172
00:06:11,040 --> 00:06:12,690
and do a basic network scan,

173
00:06:12,690 --> 00:06:15,840
which is a full system scan suitable for any host,

174
00:06:15,840 --> 00:06:18,600
and once I click on that, it's going to have me give it a name.

175
00:06:18,600 --> 00:06:20,730
In my case, I'm just going to call it network scan,

176
00:06:20,730 --> 00:06:22,200
and then I'm going to give it a description.

177
00:06:22,200 --> 00:06:24,060
Now this is really helpful because these scans

178
00:06:24,060 --> 00:06:25,200
are ones that you're going to create

179
00:06:25,200 --> 00:06:27,540
and then use week after week and month after month,

180
00:06:27,540 --> 00:06:29,760
and so six months from now you might forget

181
00:06:29,760 --> 00:06:31,680
why did you call this "Network scan"?

182
00:06:31,680 --> 00:06:34,720
So in my case, I'm going to say a lab demonstration

183
00:06:35,580 --> 00:06:39,483
of using Nessus as a vulnerability scanner.

184
00:06:40,560 --> 00:06:42,750
All right, and then we're going to save it into a folder.

185
00:06:42,750 --> 00:06:44,370
We can do it in the my scans folder,

186
00:06:44,370 --> 00:06:45,960
which you see in the top left corner,

187
00:06:45,960 --> 00:06:48,030
or you have the all scans folder.

188
00:06:48,030 --> 00:06:50,370
If I wanted to create a new folder, I can do that as well,

189
00:06:50,370 --> 00:06:52,290
but for our purposes, the my scan folder

190
00:06:52,290 --> 00:06:53,670
is going to be just fine.

191
00:06:53,670 --> 00:06:55,950
And then we're going to list out our targets.

192
00:06:55,950 --> 00:06:57,360
Now, when you're listing out your targets,

193
00:06:57,360 --> 00:07:00,630
you can do this based on domain names like diontraining.com,

194
00:07:00,630 --> 00:07:02,700
or by using IP addresses.

195
00:07:02,700 --> 00:07:05,310
For example, if you're doing your internal local network,

196
00:07:05,310 --> 00:07:07,290
you're probably going to have to use IP addresses

197
00:07:07,290 --> 00:07:09,510
because you probably don't have a domain name associated

198
00:07:09,510 --> 00:07:11,700
with each and every host on your network.

199
00:07:11,700 --> 00:07:16,700
Now in my case, I'm using the 192.168.150.0/24 network.

200
00:07:20,340 --> 00:07:22,440
Now, if I didn't know any of my hosts on that network,

201
00:07:22,440 --> 00:07:25,440
I can scan the entire subnet of 256 hosts

202
00:07:25,440 --> 00:07:27,300
by using something like this.

203
00:07:27,300 --> 00:07:28,500
Now, instead of doing this though,

204
00:07:28,500 --> 00:07:29,790
if I know what my hosts are,

205
00:07:29,790 --> 00:07:31,380
I can list them out individually

206
00:07:31,380 --> 00:07:33,090
by putting in their IP addresses.

207
00:07:33,090 --> 00:07:35,100
So in my case, I do know all of my hosts,

208
00:07:35,100 --> 00:07:38,970
which is 192.168.150.136,

209
00:07:38,970 --> 00:07:40,770
which is my Kali Linux machine.

210
00:07:40,770 --> 00:07:42,810
Then I'll put comma and I'll add the next one.

211
00:07:42,810 --> 00:07:43,890
I want to put my Windows machine,

212
00:07:43,890 --> 00:07:48,120
which is 192.168.150.138.

213
00:07:48,120 --> 00:07:49,710
I'll also want to include my Ubuntu machine,

214
00:07:49,710 --> 00:07:53,430
which is 192.168.150.137.

215
00:07:53,430 --> 00:07:55,320
And I also want to add my Metasploitable 2 machine,

216
00:07:55,320 --> 00:07:59,190
which is 192.168.150.139,

217
00:07:59,190 --> 00:08:01,140
and I can even add my Mac machine,

218
00:08:01,140 --> 00:08:05,280
which is 192.168.1.116.

219
00:08:05,280 --> 00:08:08,100
Now notice those first four are all going to be

220
00:08:08,100 --> 00:08:12,720
right next to each other, 136, 138, 137, and 139.

221
00:08:12,720 --> 00:08:13,980
So instead of writing it out that way,

222
00:08:13,980 --> 00:08:15,300
which takes a lot of time,

223
00:08:15,300 --> 00:08:17,670
I can actually just use a dash in between

224
00:08:17,670 --> 00:08:21,090
and do 136 dash 139,

225
00:08:21,090 --> 00:08:23,040
and then I can get rid of all of the rest of those

226
00:08:23,040 --> 00:08:25,470
and it will still scan all four of those hosts

227
00:08:25,470 --> 00:08:28,650
because I'm doing everything between 136 and 139,

228
00:08:28,650 --> 00:08:31,410
which includes 137 and 138.

229
00:08:31,410 --> 00:08:33,539
I would still need to have a comma here to separate

230
00:08:33,539 --> 00:08:35,580
that range from my Mac machine,

231
00:08:35,580 --> 00:08:37,620
because my Mac machine is outside of that range

232
00:08:37,620 --> 00:08:39,419
and it's a separate subnet.

233
00:08:39,419 --> 00:08:41,940
Now in this case, this would give me five different machines

234
00:08:41,940 --> 00:08:44,159
to scan, and I think that's fine.

235
00:08:44,159 --> 00:08:46,530
Another thing you can do is you can upload your targets

236
00:08:46,530 --> 00:08:48,870
by adding something like a CSV file.

237
00:08:48,870 --> 00:08:51,060
For example, you might have a CSV file

238
00:08:51,060 --> 00:08:54,210
with 1000 clients spread across multiple subnets.

239
00:08:54,210 --> 00:08:56,700
Instead of typing them all in, you can just import that file

240
00:08:56,700 --> 00:08:58,800
by clicking add file here.

241
00:08:58,800 --> 00:09:00,450
The next thing we're going to do is go down

242
00:09:00,450 --> 00:09:01,950
to our schedule option.

243
00:09:01,950 --> 00:09:04,440
From schedule we can enable or disable this.

244
00:09:04,440 --> 00:09:05,910
Right now this is disabled,

245
00:09:05,910 --> 00:09:08,130
but I want to go ahead and enable this.

246
00:09:08,130 --> 00:09:10,410
Now by doing this, I can schedule scans

247
00:09:10,410 --> 00:09:12,840
and allow them to happen once a week, once a day,

248
00:09:12,840 --> 00:09:14,640
once a month, or once a year.

249
00:09:14,640 --> 00:09:16,110
For example, we mentioned the fact

250
00:09:16,110 --> 00:09:18,330
that there are these quarterly PCI DSS scans

251
00:09:18,330 --> 00:09:20,730
that we do all the time as cybersecurity analysts.

252
00:09:20,730 --> 00:09:21,990
You can set those up here

253
00:09:21,990 --> 00:09:24,720
and say once a quarter on the first of every third month,

254
00:09:24,720 --> 00:09:27,780
I want you to run a full PCI DSS quarterly scan

255
00:09:27,780 --> 00:09:29,130
and give me those results.

256
00:09:29,130 --> 00:09:30,870
So a lot of this can be automated and setup,

257
00:09:30,870 --> 00:09:31,980
so you don't have to sit here waiting

258
00:09:31,980 --> 00:09:33,630
for these scans to complete.

259
00:09:33,630 --> 00:09:35,310
In my case, I'm going to go ahead and enable this

260
00:09:35,310 --> 00:09:37,320
and we're going to say we want to do this as a frequency

261
00:09:37,320 --> 00:09:39,780
of weekly, and I want to do this every Saturday morning

262
00:09:39,780 --> 00:09:41,250
starting at 1:00 AM.

263
00:09:41,250 --> 00:09:42,870
So I'll click on that and the first Saturday

264
00:09:42,870 --> 00:09:46,740
we're going to come to is going to be January 14th, 2023.

265
00:09:46,740 --> 00:09:48,690
You'll then select the time zone associated with that,

266
00:09:48,690 --> 00:09:50,310
and for me that's going to be the East coast,

267
00:09:50,310 --> 00:09:52,560
which is New York inside of the United States.

268
00:09:52,560 --> 00:09:54,180
And then I'll repeat this every week

269
00:09:54,180 --> 00:09:56,190
and I can choose which day I want it to happen,

270
00:09:56,190 --> 00:09:58,440
and in my case, I want it to happen every Saturday.

271
00:09:58,440 --> 00:10:00,120
So I'm just going to go ahead and highlight the Saturdays

272
00:10:00,120 --> 00:10:02,070
there, and you can see the summary at the bottom.

273
00:10:02,070 --> 00:10:04,620
It repeats every week on Saturday at 1:00 AM

274
00:10:04,620 --> 00:10:08,040
starting Saturday, January 14th, 2023,

275
00:10:08,040 --> 00:10:10,530
and that's how you can set up a scheduled scan.

276
00:10:10,530 --> 00:10:11,420
The next thing we can do is go

277
00:10:11,420 --> 00:10:13,320
to our notifications tab.

278
00:10:13,320 --> 00:10:16,530
Under notifications, we can configure an SMTP server

279
00:10:16,530 --> 00:10:19,260
and then we can send an email when our scans are complete.

280
00:10:19,260 --> 00:10:22,290
So after it scans this thing at 1:00 AM on Saturday,

281
00:10:22,290 --> 00:10:24,420
it can then email me a PDF report that says,

282
00:10:24,420 --> 00:10:26,400
here's all the vulnerabilities I found.

283
00:10:26,400 --> 00:10:28,920
And so again, this makes it a really nice automated process

284
00:10:28,920 --> 00:10:30,540
for us as cybersecurity analysts,

285
00:10:30,540 --> 00:10:31,950
and so it is something you might want to go ahead

286
00:10:31,950 --> 00:10:32,880
and set up.

287
00:10:32,880 --> 00:10:35,280
In addition to that, you can also use results filters.

288
00:10:35,280 --> 00:10:37,710
So you can say, hey, only email me if this happens

289
00:10:37,710 --> 00:10:40,110
or don't email me when this happens.

290
00:10:40,110 --> 00:10:42,150
The next thing we're going to do is click on discovery.

291
00:10:42,150 --> 00:10:44,400
Under discovery, we're going to say what kind of types we want

292
00:10:44,400 --> 00:10:45,900
to use for our scans.

293
00:10:45,900 --> 00:10:48,180
Now by default, the most common is going to be doing a port

294
00:10:48,180 --> 00:10:50,040
scan of the common ports.

295
00:10:50,040 --> 00:10:52,590
This is usually the 1000 most commonly used ports,

296
00:10:52,590 --> 00:10:53,820
and this will be a much quicker way

297
00:10:53,820 --> 00:10:57,060
of doing a discovery scan, but you could miss some things.

298
00:10:57,060 --> 00:11:00,060
So personally I like to do a more comprehensive scan

299
00:11:00,060 --> 00:11:02,730
and I will do a scan of all ports on those machines,

300
00:11:02,730 --> 00:11:04,800
or if you're looking for a specific port only,

301
00:11:04,800 --> 00:11:06,870
like which ones are web servers,

302
00:11:06,870 --> 00:11:09,000
I can do that by doing a custom port.

303
00:11:09,000 --> 00:11:11,010
And in that case I would just select custom

304
00:11:11,010 --> 00:11:13,500
and then I would be able to choose my own discovery settings

305
00:11:13,500 --> 00:11:15,420
by doing the host discovery, port scanning,

306
00:11:15,420 --> 00:11:17,040
service discovery or identity.

307
00:11:17,040 --> 00:11:18,840
And in this case it'd be service discovery

308
00:11:18,840 --> 00:11:20,400
that I would be looking for a particular type

309
00:11:20,400 --> 00:11:22,350
of web server like an Apache web server

310
00:11:22,350 --> 00:11:24,930
over port 80 or port 443.

311
00:11:24,930 --> 00:11:27,090
So again, this just gives you additional areas.

312
00:11:27,090 --> 00:11:28,530
For our use case though, we're going to go ahead

313
00:11:28,530 --> 00:11:30,270
and stick with the all port scan,

314
00:11:30,270 --> 00:11:32,640
which will go ahead and scan all of the ports available

315
00:11:32,640 --> 00:11:35,130
and it'll use Netstat if the credentials are provided

316
00:11:35,130 --> 00:11:37,800
and it'll use a SYN scanner if necessary,

317
00:11:37,800 --> 00:11:40,230
because sometimes ping scans won't work.

318
00:11:40,230 --> 00:11:42,870
The next thing we're going to look at is our assessment.

319
00:11:42,870 --> 00:11:44,460
Under assessment, we're also going to choose

320
00:11:44,460 --> 00:11:45,780
the scan type here.

321
00:11:45,780 --> 00:11:48,240
The default is going to be our most basic scan,

322
00:11:48,240 --> 00:11:49,500
and right now we're not even scanning

323
00:11:49,500 --> 00:11:51,510
for web application vulnerabilities.

324
00:11:51,510 --> 00:11:53,790
This is fine if we're going to be scanning a bunch of hosts

325
00:11:53,790 --> 00:11:56,160
that are on a network such as people's workstations

326
00:11:56,160 --> 00:11:58,650
because they shouldn't be running web applications on those.

327
00:11:58,650 --> 00:12:00,360
But if you're checking a web server,

328
00:12:00,360 --> 00:12:02,850
you would want to enable those web application scans,

329
00:12:02,850 --> 00:12:04,590
and in my case, one of my machines,

330
00:12:04,590 --> 00:12:07,380
the Metasploitable 2 machine is running a web server.

331
00:12:07,380 --> 00:12:09,600
So I want to change that from default

332
00:12:09,600 --> 00:12:11,220
and I want to go ahead and say scan for

333
00:12:11,220 --> 00:12:13,320
all web vulnerabilities complex,

334
00:12:13,320 --> 00:12:15,840
this is going to be our most thorough and in-depth scan.

335
00:12:15,840 --> 00:12:17,910
And again, there is an option to do a custom scan

336
00:12:17,910 --> 00:12:20,280
where you can set up all your different parameters.

337
00:12:20,280 --> 00:12:22,140
Next, we have our report.

338
00:12:22,140 --> 00:12:23,940
Under our report, we have the ability

339
00:12:23,940 --> 00:12:25,440
to set up different things,

340
00:12:25,440 --> 00:12:28,440
including the ability to designate hosts by their DNS name,

341
00:12:28,440 --> 00:12:30,000
be able to show all the hosts that responded

342
00:12:30,000 --> 00:12:32,490
to a ping, display any hosts that were unreachable.

343
00:12:32,490 --> 00:12:34,980
For example, you said you expected 100 machines

344
00:12:34,980 --> 00:12:37,620
to be online, but you only found 73.

345
00:12:37,620 --> 00:12:40,080
What were the other 27 machines that were offline?

346
00:12:40,080 --> 00:12:42,690
Well, if you display unreachable hosts there at the bottom,

347
00:12:42,690 --> 00:12:45,180
that will actually show that to you in your report.

348
00:12:45,180 --> 00:12:47,310
And so all of these things are things that you can configure

349
00:12:47,310 --> 00:12:49,110
for part of your reporting.

350
00:12:49,110 --> 00:12:50,640
Then we'll go into our advanced tab,

351
00:12:50,640 --> 00:12:52,440
and again, here's another scan type.

352
00:12:52,440 --> 00:12:54,510
We're using the default right now, which is fine.

353
00:12:54,510 --> 00:12:57,540
If you're scanning over a low bandwidth link such as a VPN

354
00:12:57,540 --> 00:12:59,460
or some kind of remote office connection,

355
00:12:59,460 --> 00:13:01,380
you may want to use that or again,

356
00:13:01,380 --> 00:13:04,140
you can use custom, or you can use more or less scanners

357
00:13:04,140 --> 00:13:05,100
each time.

358
00:13:05,100 --> 00:13:06,780
In my case, using the default,

359
00:13:06,780 --> 00:13:08,850
this says I'm going to be able to scan up to 30 hosts

360
00:13:08,850 --> 00:13:09,780
at one time.

361
00:13:09,780 --> 00:13:12,150
I can do four checks per host at one time,

362
00:13:12,150 --> 00:13:14,910
and I have a five second network read timeout.

363
00:13:14,910 --> 00:13:16,980
If I wanted to increase that or decrease that,

364
00:13:16,980 --> 00:13:19,560
I could do that by using the custom area.

365
00:13:19,560 --> 00:13:21,600
The next tab we have is our credentials.

366
00:13:21,600 --> 00:13:23,670
Now, as you know, you can either use credentialed

367
00:13:23,670 --> 00:13:25,290
or un-credentialed scans,

368
00:13:25,290 --> 00:13:26,760
and if you're going to use credentialed scans,

369
00:13:26,760 --> 00:13:28,830
that means you're giving it the username and password

370
00:13:28,830 --> 00:13:31,050
for an account on that given system.

371
00:13:31,050 --> 00:13:33,030
If you're using a Windows machine that you're scanning,

372
00:13:33,030 --> 00:13:34,260
you'll simply click on Windows

373
00:13:34,260 --> 00:13:36,390
and then enter in your username and password there

374
00:13:36,390 --> 00:13:38,280
and save that, and it'll allow Nessus to connect

375
00:13:38,280 --> 00:13:40,650
to that machine using those user credentials,

376
00:13:40,650 --> 00:13:41,850
and be able to get a better idea

377
00:13:41,850 --> 00:13:43,650
of what vulnerabilities exist.

378
00:13:43,650 --> 00:13:45,780
I've already done a scan of doing both a credentialed

379
00:13:45,780 --> 00:13:48,600
and non-credentialed scan against my Windows 11 machine,

380
00:13:48,600 --> 00:13:50,580
and you'll see that when we did a credentialed scan,

381
00:13:50,580 --> 00:13:52,680
we actually found one additional vulnerability

382
00:13:52,680 --> 00:13:55,620
that wasn't found when we did an un-credentialed scan.

383
00:13:55,620 --> 00:13:57,450
So it's important to realize this

384
00:13:57,450 --> 00:13:59,730
and determine which type of scan you want to do.

385
00:13:59,730 --> 00:14:01,380
If you're trying to see what vulnerabilities exist

386
00:14:01,380 --> 00:14:02,730
for an outside attacker,

387
00:14:02,730 --> 00:14:05,190
then doing an un-credentialed scan would be the way to go.

388
00:14:05,190 --> 00:14:06,930
If you want to see what an insider threat could do,

389
00:14:06,930 --> 00:14:08,670
who has a valid login and password,

390
00:14:08,670 --> 00:14:10,530
then using something like a credentialed scan

391
00:14:10,530 --> 00:14:11,940
would make sense.

392
00:14:11,940 --> 00:14:14,280
And the final tab we have is our plugins.

393
00:14:14,280 --> 00:14:16,920
Now plugins inside of Nessus are used to be able to check

394
00:14:16,920 --> 00:14:18,600
for certain vulnerabilities.

395
00:14:18,600 --> 00:14:20,520
Here you can see the plugin families down the left

396
00:14:20,520 --> 00:14:22,440
and then the plugin names on the right.

397
00:14:22,440 --> 00:14:24,510
For example, if I go down here

398
00:14:24,510 --> 00:14:25,800
and I go all the way to the bottom,

399
00:14:25,800 --> 00:14:28,380
you'll see that we have three different ones for Windows.

400
00:14:28,380 --> 00:14:30,360
The first one in the Windows family has a whole bunch

401
00:14:30,360 --> 00:14:32,640
of plugins and you can see them listed on the right.

402
00:14:32,640 --> 00:14:35,280
For example, we could be checking to see if team viewers

403
00:14:35,280 --> 00:14:37,650
insecure directory permissions privilege escalation

404
00:14:37,650 --> 00:14:39,660
is something our machine is vulnerable with.

405
00:14:39,660 --> 00:14:42,960
That's because we have that plugin there, 135708,

406
00:14:42,960 --> 00:14:45,330
and it will check that when we're doing our scans.

407
00:14:45,330 --> 00:14:47,280
Right now, all these plugins are enabled

408
00:14:47,280 --> 00:14:49,740
and we're going to be using all of them when we do our scan,

409
00:14:49,740 --> 00:14:52,680
but we could check for just a single vulnerability as well.

410
00:14:52,680 --> 00:14:54,870
Essentially, if there is a vulnerability out there

411
00:14:54,870 --> 00:14:58,140
that's known, Nessus will go ahead and make a new plugin

412
00:14:58,140 --> 00:15:00,090
and release that to the client.

413
00:15:00,090 --> 00:15:02,220
Speaking of that, how do you update your scanner

414
00:15:02,220 --> 00:15:04,170
to ensure you have all the latest plugins?

415
00:15:04,170 --> 00:15:05,490
Well, the best way to do that is

416
00:15:05,490 --> 00:15:07,590
by clicking on the settings tab at the top,

417
00:15:07,590 --> 00:15:10,350
but we'll do that after we finish creating our scan.

418
00:15:10,350 --> 00:15:12,060
Now that we've looked at all the plugins we want,

419
00:15:12,060 --> 00:15:14,790
we can go ahead and hit save and that will save that for us.

420
00:15:14,790 --> 00:15:16,860
And then from here it's asking us for the credentials

421
00:15:16,860 --> 00:15:18,270
for our Windows machine.

422
00:15:18,270 --> 00:15:19,740
In our case, we don't want to use that,

423
00:15:19,740 --> 00:15:21,390
so I'm just going to hit the X over here

424
00:15:21,390 --> 00:15:22,790
and then I'm going to hit save.

425
00:15:24,120 --> 00:15:26,280
From here we now see that my network scan

426
00:15:26,280 --> 00:15:27,480
is added to my list

427
00:15:27,480 --> 00:15:30,780
and it will run every week on Thursday at 1:00 AM.

428
00:15:30,780 --> 00:15:31,890
The reason it says Thursday is

429
00:15:31,890 --> 00:15:33,420
because that's today's date when I did it,

430
00:15:33,420 --> 00:15:36,750
but the first scheduled time is going to be Saturday at 1:00 AM

431
00:15:36,750 --> 00:15:39,060
based on the configuration we did.

432
00:15:39,060 --> 00:15:40,650
Now let's go ahead and take a look at

433
00:15:40,650 --> 00:15:42,330
how you can update your plugins.

434
00:15:42,330 --> 00:15:44,970
To do this, you're going to go and click on settings at the top

435
00:15:44,970 --> 00:15:47,040
and from settings you'll then go down

436
00:15:47,040 --> 00:15:48,990
and look at your scanner health.

437
00:15:48,990 --> 00:15:50,040
From your scanner health,

438
00:15:50,040 --> 00:15:51,960
you'll see the overall health of your scanner.

439
00:15:51,960 --> 00:15:54,120
In my case, you could see how much memory is used,

440
00:15:54,120 --> 00:15:55,950
what CPU load is currently ongoing,

441
00:15:55,950 --> 00:15:57,934
and the hosts that are being scanned,

442
00:15:57,934 --> 00:16:00,240
as well as some graphs showing all that information.

443
00:16:00,240 --> 00:16:02,700
In addition to that, we can look at the network activity

444
00:16:02,700 --> 00:16:04,710
by clicking on the network tab over here,

445
00:16:04,710 --> 00:16:06,690
and that will show us some information about the running

446
00:16:06,690 --> 00:16:09,030
scans and the active targets that we're looking at,

447
00:16:09,030 --> 00:16:11,100
as well as what sessions are there.

448
00:16:11,100 --> 00:16:13,080
If we want to be able to update our scanner,

449
00:16:13,080 --> 00:16:15,060
we want to make sure that we check our about area,

450
00:16:15,060 --> 00:16:16,800
and this will tell us what version we have

451
00:16:16,800 --> 00:16:19,110
as well as what plugin set and policy template version

452
00:16:19,110 --> 00:16:21,990
we're using, as you can see over on the right hand side.

453
00:16:21,990 --> 00:16:23,850
In addition to that, you can see the fact

454
00:16:23,850 --> 00:16:25,800
that this was last updated today,

455
00:16:25,800 --> 00:16:27,240
and if I wanted to update it again,

456
00:16:27,240 --> 00:16:29,100
I would simply click on the little refresh button

457
00:16:29,100 --> 00:16:31,470
next to that to see when the last update was,

458
00:16:31,470 --> 00:16:33,150
and if you click on software update,

459
00:16:33,150 --> 00:16:35,280
you'll be able to see if it is configured properly

460
00:16:35,280 --> 00:16:38,070
to get all of the updates for the components for the plugins

461
00:16:38,070 --> 00:16:40,530
or if we disable automatic updates.

462
00:16:40,530 --> 00:16:42,870
Personally, I like to use automatic updates,

463
00:16:42,870 --> 00:16:44,220
especially when I'm a home user

464
00:16:44,220 --> 00:16:46,020
doing this in my home system.

465
00:16:46,020 --> 00:16:47,610
If you're in a corporate environment though,

466
00:16:47,610 --> 00:16:49,020
do check your policies

467
00:16:49,020 --> 00:16:50,790
because some organizations don't want you

468
00:16:50,790 --> 00:16:53,670
to update your components or plugins directly from Nessus

469
00:16:53,670 --> 00:16:56,067
and instead want to use their own custom server,

470
00:16:56,067 --> 00:16:58,650
and you can configure that here under the update server

471
00:16:58,650 --> 00:17:01,350
with your custom URL being added in there.

472
00:17:01,350 --> 00:17:02,640
All right, now that we have all that,

473
00:17:02,640 --> 00:17:03,870
let's go back to our scans

474
00:17:03,870 --> 00:17:05,339
and take a look at some of the things

475
00:17:05,339 --> 00:17:07,440
that I've already run so we can see what these scans

476
00:17:07,440 --> 00:17:08,339
look like.

477
00:17:08,339 --> 00:17:09,450
All right, let's go ahead

478
00:17:09,450 --> 00:17:11,670
and take a look at our Windows machines first.

479
00:17:11,670 --> 00:17:13,470
Now, I mentioned I had two of them done here.

480
00:17:13,470 --> 00:17:16,530
One was a credentialed and one was an un-credentialed scan.

481
00:17:16,530 --> 00:17:19,140
Let's take a look at our un-credentialed scan first.

482
00:17:19,140 --> 00:17:20,849
If I click on my Windows machine,

483
00:17:20,849 --> 00:17:22,770
you'll see that it has its IP address

484
00:17:22,770 --> 00:17:25,260
and we have 10 vulnerabilities that were identified.

485
00:17:25,260 --> 00:17:27,660
Those vulnerabilities though aren't really that significant

486
00:17:27,660 --> 00:17:29,400
because they're just informational.

487
00:17:29,400 --> 00:17:31,230
There are no criticals, no highs,

488
00:17:31,230 --> 00:17:33,360
no mediums, and no lows.

489
00:17:33,360 --> 00:17:34,650
As you look at the scan details,

490
00:17:34,650 --> 00:17:36,360
you could see when it started and when it stopped,

491
00:17:36,360 --> 00:17:39,810
and in this case it took me six minutes to scan one machine.

492
00:17:39,810 --> 00:17:42,270
In addition to that, you can click on vulnerabilities,

493
00:17:42,270 --> 00:17:44,160
and from here you'll see all 10 vulnerabilities

494
00:17:44,160 --> 00:17:46,380
that were found as well as what their severity is,

495
00:17:46,380 --> 00:17:49,650
whether it's info, low, medium, high or critical,

496
00:17:49,650 --> 00:17:51,900
and in my case, they're all informational.

497
00:17:51,900 --> 00:17:54,360
In addition to that, you'll have a score that's associated

498
00:17:54,360 --> 00:17:56,730
with it if it is a critical high, medium, or low

499
00:17:56,730 --> 00:17:59,850
based on CVSS 3.0 or 3.1,

500
00:17:59,850 --> 00:18:01,980
as well as the name of that vulnerability,

501
00:18:01,980 --> 00:18:04,920
the family of plugin it came from, and the number of counts.

502
00:18:04,920 --> 00:18:06,630
In our case, there's only one count for each

503
00:18:06,630 --> 00:18:08,370
because we only scanned one machine.

504
00:18:08,370 --> 00:18:09,930
But if I scan my entire network,

505
00:18:09,930 --> 00:18:11,490
like the scan that we just set up,

506
00:18:11,490 --> 00:18:12,323
that would actually go

507
00:18:12,323 --> 00:18:13,527
and look at all the machines on the network,

508
00:18:13,527 --> 00:18:15,540
and in my case, there was five of them,

509
00:18:15,540 --> 00:18:17,280
and if two or three of those machines had it,

510
00:18:17,280 --> 00:18:19,860
we would see that number here under the count.

511
00:18:19,860 --> 00:18:21,750
In addition to that, we also have this tab

512
00:18:21,750 --> 00:18:23,970
called the VPR Top Threats.

513
00:18:23,970 --> 00:18:25,830
Now, this is a proprietary technology

514
00:18:25,830 --> 00:18:27,720
used by Tenable, the makers of Nessus,

515
00:18:27,720 --> 00:18:30,150
to tell you what is the most vulnerable things.

516
00:18:30,150 --> 00:18:32,010
Now similar to a CVSS score,

517
00:18:32,010 --> 00:18:33,750
you can't rely on these solely

518
00:18:33,750 --> 00:18:36,210
because this is just Nessus' best guess

519
00:18:36,210 --> 00:18:37,890
at what they think is the most vulnerable,

520
00:18:37,890 --> 00:18:38,880
but they don't really understand

521
00:18:38,880 --> 00:18:40,470
your network as well as you do.

522
00:18:40,470 --> 00:18:42,450
For example, they may say that there's a server

523
00:18:42,450 --> 00:18:45,180
with a really critical vulnerability that has to be patched,

524
00:18:45,180 --> 00:18:46,620
but when you look at that server,

525
00:18:46,620 --> 00:18:48,960
it's actually in an isolated subnet that nobody can reach

526
00:18:48,960 --> 00:18:51,360
and therefore it's not really that vulnerable to attack,

527
00:18:51,360 --> 00:18:53,130
and so it may not be as big of a priority

528
00:18:53,130 --> 00:18:55,080
as something that's a high or medium

529
00:18:55,080 --> 00:18:56,250
that is publicly facing,

530
00:18:56,250 --> 00:18:58,440
such as a web server inside of a screen subnet

531
00:18:58,440 --> 00:19:00,090
or demilitarized zone.

532
00:19:00,090 --> 00:19:02,400
And then the last tab we have is our history tab,

533
00:19:02,400 --> 00:19:03,690
and this shows us all the scans

534
00:19:03,690 --> 00:19:05,150
that have been made with that profile.

535
00:19:05,150 --> 00:19:08,490
In this case, that's my profile of Windows un-credentialed,

536
00:19:08,490 --> 00:19:12,210
and you can see here I only scanned one machine, one time.

537
00:19:12,210 --> 00:19:14,190
If I go back to the vulnerabilities tab,

538
00:19:14,190 --> 00:19:15,960
you can also see that these vulnerabilities

539
00:19:15,960 --> 00:19:16,793
when you click on them

540
00:19:16,793 --> 00:19:18,450
will give you additional information.

541
00:19:18,450 --> 00:19:20,730
For example, if I click on the device type,

542
00:19:20,730 --> 00:19:22,350
the reason this is informational is

543
00:19:22,350 --> 00:19:24,660
because it's saying based on the remote operating system,

544
00:19:24,660 --> 00:19:27,630
it's possible to determine what remote system type is,

545
00:19:27,630 --> 00:19:29,790
such as a printer, router, general purpose computer,

546
00:19:29,790 --> 00:19:32,520
or whatever it is, and we have a 70% confidence level

547
00:19:32,520 --> 00:19:34,890
that this is a Windows 11 general purpose machine

548
00:19:34,890 --> 00:19:37,470
based on the basic scan that we just did.

549
00:19:37,470 --> 00:19:39,060
In addition to all of that, once you have

550
00:19:39,060 --> 00:19:40,230
all your vulnerabilities,

551
00:19:40,230 --> 00:19:42,060
you don't have to just click through them all here.

552
00:19:42,060 --> 00:19:44,220
You can actually do it as a report too.

553
00:19:44,220 --> 00:19:46,500
In order to do this, simply click on report

554
00:19:46,500 --> 00:19:48,510
and then you'll select the type of report you want,

555
00:19:48,510 --> 00:19:51,150
whether you want a complete list of vulnerabilities by host,

556
00:19:51,150 --> 00:19:53,790
detailed vulnerabilities by host, detailed vulnerabilities

557
00:19:53,790 --> 00:19:56,940
by plugins, or vulnerability operations.

558
00:19:56,940 --> 00:19:59,430
Now, when you do detailed vulnerabilities by host,

559
00:19:59,430 --> 00:20:00,660
this is what we're seeing here

560
00:20:00,660 --> 00:20:01,860
where we have 10 vulnerabilities

561
00:20:01,860 --> 00:20:03,720
associated with this single host.

562
00:20:03,720 --> 00:20:07,200
But again, if I had 5 or 10 or 500 machines,

563
00:20:07,200 --> 00:20:09,570
I might want to look at the vulnerabilities by plugin

564
00:20:09,570 --> 00:20:11,100
so I could say which one has the most

565
00:20:11,100 --> 00:20:12,420
or which one is the most critical,

566
00:20:12,420 --> 00:20:14,790
and then I could see all the machines associated with that.

567
00:20:14,790 --> 00:20:16,350
In our case, we're going to do it by host

568
00:20:16,350 --> 00:20:18,120
because we only have one host scanned here,

569
00:20:18,120 --> 00:20:19,980
and then we'll go ahead and hit generate report here

570
00:20:19,980 --> 00:20:22,170
to generate our report as a PDF.

571
00:20:22,170 --> 00:20:24,330
You do have three options when generating a report.

572
00:20:24,330 --> 00:20:28,440
You can do it as an HTML file, a PDF or a CSV file.

573
00:20:28,440 --> 00:20:30,030
In my case, I used a PDF

574
00:20:30,030 --> 00:20:31,907
and you can see that PDF is created right here.

575
00:20:31,907 --> 00:20:35,040
It's a 15-page document with all of the vulnerabilities

576
00:20:35,040 --> 00:20:37,170
and what they are and how we can fix them.

577
00:20:37,170 --> 00:20:39,030
So as we start scrolling through this,

578
00:20:39,030 --> 00:20:41,160
we can see that we have a vulnerabilities by host

579
00:20:41,160 --> 00:20:42,480
and there's only one host.

580
00:20:42,480 --> 00:20:44,250
And then if we go down to page four,

581
00:20:44,250 --> 00:20:46,200
we will now see the vulnerabilities.

582
00:20:46,200 --> 00:20:49,140
Here we have zero critical, zero high, zero medium,

583
00:20:49,140 --> 00:20:51,990
and zero low, but we do have 10 informational.

584
00:20:51,990 --> 00:20:53,880
We could see when the scan started and stopped,

585
00:20:53,880 --> 00:20:55,650
we could see information about that host,

586
00:20:55,650 --> 00:20:58,050
and then we start seeing the vulnerabilities themself.

587
00:20:58,050 --> 00:21:00,030
For example, the first vulnerability we have is

588
00:21:00,030 --> 00:21:02,820
that common platform enumeration or CPE,

589
00:21:02,820 --> 00:21:04,890
and this says we are able to figure out

590
00:21:04,890 --> 00:21:06,630
what type of system it was.

591
00:21:06,630 --> 00:21:07,920
And so as we look at that,

592
00:21:07,920 --> 00:21:09,330
we can see the output from it

593
00:21:09,330 --> 00:21:10,890
and we can see that it identified us

594
00:21:10,890 --> 00:21:13,050
as a Windows host and that is correct.

595
00:21:13,050 --> 00:21:14,910
So that is a informational thing.

596
00:21:14,910 --> 00:21:16,320
It's not really a dangerous thing,

597
00:21:16,320 --> 00:21:17,850
but if you didn't want people to know you're running

598
00:21:17,850 --> 00:21:19,830
a Windows machine, you could do some things

599
00:21:19,830 --> 00:21:21,750
to obfuscate that and make it report

600
00:21:21,750 --> 00:21:23,970
that it's a Linux machine or a Mac machine

601
00:21:23,970 --> 00:21:25,080
or something like that,

602
00:21:25,080 --> 00:21:26,700
if you wanted to use some kind of security

603
00:21:26,700 --> 00:21:28,410
by obscurity technique.

604
00:21:28,410 --> 00:21:30,480
Then we can keep scrolling, we'll see the next thing.

605
00:21:30,480 --> 00:21:32,400
In our case, we see a device type,

606
00:21:32,400 --> 00:21:34,470
and again, we saw this was a general purpose machine.

607
00:21:34,470 --> 00:21:35,880
We saw that earlier when we were looking at

608
00:21:35,880 --> 00:21:37,980
inside of the Nessus tool.

609
00:21:37,980 --> 00:21:39,960
As we continue to go down, you'll see more information

610
00:21:39,960 --> 00:21:41,460
of all the things we found.

611
00:21:41,460 --> 00:21:43,290
Now here, because these were informational,

612
00:21:43,290 --> 00:21:44,790
it's not nearly as helpful

613
00:21:44,790 --> 00:21:47,160
as when we find things that have true vulnerabilities

614
00:21:47,160 --> 00:21:48,630
because then it will give us information

615
00:21:48,630 --> 00:21:51,090
about the vulnerability and how to solve it.

616
00:21:51,090 --> 00:21:53,430
Let me show you what that looks like in just a minute.

617
00:21:53,430 --> 00:21:55,170
Right now, let's go back to our scans

618
00:21:55,170 --> 00:21:57,390
and take a look at our credentialed scan.

619
00:21:57,390 --> 00:22:00,300
Now with the un-credentialed scan we had 10 things found.

620
00:22:00,300 --> 00:22:02,340
Here in the credentialed scan we do find

621
00:22:02,340 --> 00:22:03,447
that we have 11 things.

622
00:22:03,447 --> 00:22:05,310
And so we can compare the two

623
00:22:05,310 --> 00:22:06,810
and we can look at one versus the other

624
00:22:06,810 --> 00:22:07,800
and see what the difference is

625
00:22:07,800 --> 00:22:09,660
and what that one extra thing was.

626
00:22:09,660 --> 00:22:11,400
But again, because these are all informational,

627
00:22:11,400 --> 00:22:12,780
it's really not that big of a deal,

628
00:22:12,780 --> 00:22:14,640
and so we're going to go look at some other scans

629
00:22:14,640 --> 00:22:16,920
that may have some better information for us.

630
00:22:16,920 --> 00:22:18,450
The next one we're going to look at is going to be

631
00:22:18,450 --> 00:22:19,710
our Kali machine.

632
00:22:19,710 --> 00:22:22,590
Our Kali machine is actually a very secure machine as well,

633
00:22:22,590 --> 00:22:24,570
having 57 informational items

634
00:22:24,570 --> 00:22:27,900
and only one low item here as a vulnerability.

635
00:22:27,900 --> 00:22:29,970
This scan actually took 16 minutes to complete

636
00:22:29,970 --> 00:22:31,320
on this single machine,

637
00:22:31,320 --> 00:22:34,500
and we look at the vulnerabilities we have 44 of them total.

638
00:22:34,500 --> 00:22:35,610
Now the reason there's 44 is

639
00:22:35,610 --> 00:22:38,190
because there's lots of them that have multiple issues

640
00:22:38,190 --> 00:22:41,730
such as HTTP has three, SSH has four,

641
00:22:41,730 --> 00:22:44,340
SSL has five, and things like that.

642
00:22:44,340 --> 00:22:46,890
When we look at the SSL one, you can see it says mixed,

643
00:22:46,890 --> 00:22:48,480
and the reason for that is when I click on this,

644
00:22:48,480 --> 00:22:49,860
it works almost like a folder.

645
00:22:49,860 --> 00:22:51,450
You could see there was four informational

646
00:22:51,450 --> 00:22:53,580
and one medium vulnerability.

647
00:22:53,580 --> 00:22:55,770
This is our first vulnerability that actually has a number

648
00:22:55,770 --> 00:22:57,230
or score associated with it.

649
00:22:57,230 --> 00:23:01,260
In this case, that's 6.5, giving us a medium classification.

650
00:23:01,260 --> 00:23:03,810
If I click on that, we could see the additional information.

651
00:23:03,810 --> 00:23:05,820
And in this case it says the SSL certificate

652
00:23:05,820 --> 00:23:07,110
cannot be trusted.

653
00:23:07,110 --> 00:23:09,030
And the reason for this as we look at the output

654
00:23:09,030 --> 00:23:10,410
below from the scanner is

655
00:23:10,410 --> 00:23:12,840
that we got information from the system we were scanning,

656
00:23:12,840 --> 00:23:14,580
in this case, our Kali Linux machine,

657
00:23:14,580 --> 00:23:16,320
and it did have information about the subject

658
00:23:16,320 --> 00:23:18,180
and issuer of that digital certificate,

659
00:23:18,180 --> 00:23:20,760
but it was a self-signed certificate

660
00:23:20,760 --> 00:23:22,740
and therefore it's being registered as signed

661
00:23:22,740 --> 00:23:24,570
by an unknown certificate authority.

662
00:23:24,570 --> 00:23:27,330
And that is why this is considered a vulnerability.

663
00:23:27,330 --> 00:23:29,490
Now, in my case, because I'm in a lab environment,

664
00:23:29,490 --> 00:23:31,260
this isn't really a big vulnerability

665
00:23:31,260 --> 00:23:33,240
and again, it's only a medium level vulnerability,

666
00:23:33,240 --> 00:23:35,760
but it is the only vulnerability we have on the system,

667
00:23:35,760 --> 00:23:38,460
and that tells me this Kali machine is rather secure.

668
00:23:38,460 --> 00:23:40,020
If I wanted to solve this problem,

669
00:23:40,020 --> 00:23:41,880
I could then go through and figure out why

670
00:23:41,880 --> 00:23:43,500
is this using a self-signed certificate

671
00:23:43,500 --> 00:23:45,570
and how can I get it its own certificate?

672
00:23:45,570 --> 00:23:47,730
In this case, it tells me my solution is to purchase

673
00:23:47,730 --> 00:23:50,490
or generate a proper SSL certificate for this service,

674
00:23:50,490 --> 00:23:52,260
and I can actually go look at those two links

675
00:23:52,260 --> 00:23:54,150
to see how to do that or get more information

676
00:23:54,150 --> 00:23:56,340
about this particular vulnerability.

677
00:23:56,340 --> 00:23:58,380
Let's go ahead and go back to our scans,

678
00:23:58,380 --> 00:24:00,780
and from here we're going to go and look at our Mac machine.

679
00:24:00,780 --> 00:24:03,420
Now, the Mac machine is a machine I use on a daily basis,

680
00:24:03,420 --> 00:24:06,420
and here you can see I have 33 informational

681
00:24:06,420 --> 00:24:08,910
and one that is a medium vulnerability.

682
00:24:08,910 --> 00:24:10,320
Let's see what that one is.

683
00:24:10,320 --> 00:24:12,090
As I click on the vulnerabilities tab,

684
00:24:12,090 --> 00:24:13,890
I see there are multiple SSL issues

685
00:24:13,890 --> 00:24:16,800
and it's the exact same issue we had on Kali.

686
00:24:16,800 --> 00:24:17,820
Now, why is this?

687
00:24:17,820 --> 00:24:19,290
Well, on my Mac system,

688
00:24:19,290 --> 00:24:21,030
I also have Nessus there

689
00:24:21,030 --> 00:24:24,270
and Nessus using that same self-signed certificate again

690
00:24:24,270 --> 00:24:26,970
inside of that installation on my Mac machine,

691
00:24:26,970 --> 00:24:28,740
and therefore we're getting the same vulnerability.

692
00:24:28,740 --> 00:24:30,120
So I would want to go ahead

693
00:24:30,120 --> 00:24:31,710
and install a real certificate

694
00:24:31,710 --> 00:24:33,930
instead of using the self-signed one from Nessus

695
00:24:33,930 --> 00:24:35,940
to avoid this vulnerability.

696
00:24:35,940 --> 00:24:37,710
Next, let's go back to my scans,

697
00:24:37,710 --> 00:24:39,510
and from here we're going to look at Ubuntu.

698
00:24:39,510 --> 00:24:40,800
Now, this Ubuntu one is one

699
00:24:40,800 --> 00:24:43,380
that I just installed straight off the CD

700
00:24:43,380 --> 00:24:45,990
and all I did was create a user account and then scan it.

701
00:24:45,990 --> 00:24:48,000
So there is no patches that have been done,

702
00:24:48,000 --> 00:24:50,280
but you can see that Ubuntu is pretty secure

703
00:24:50,280 --> 00:24:52,080
straight from its installation.

704
00:24:52,080 --> 00:24:54,120
This is because as part of the installation process,

705
00:24:54,120 --> 00:24:56,280
Ubuntu usually will download any new patches

706
00:24:56,280 --> 00:24:58,020
and vulnerability updates that it has

707
00:24:58,020 --> 00:24:59,760
before finishing the installation,

708
00:24:59,760 --> 00:25:00,780
and that's why we're seeing that this is

709
00:25:00,780 --> 00:25:02,430
a pretty secure machine.

710
00:25:02,430 --> 00:25:03,870
If we look at these vulnerabilities,

711
00:25:03,870 --> 00:25:05,490
they're all informational again,

712
00:25:05,490 --> 00:25:07,590
and from here you can see it's most of the same stuff.

713
00:25:07,590 --> 00:25:09,450
We're getting information about the system

714
00:25:09,450 --> 00:25:12,360
such as its Mac address, its IP protocols being scanned,

715
00:25:12,360 --> 00:25:13,860
and things like that.

716
00:25:13,860 --> 00:25:15,900
Let's go back to our scans one more time,

717
00:25:15,900 --> 00:25:17,820
and from here you can see that my other two scans

718
00:25:17,820 --> 00:25:18,840
are still running.

719
00:25:18,840 --> 00:25:20,487
The basic scan of my entire network

720
00:25:20,487 --> 00:25:22,440
and the Metasploitable 2 one.

721
00:25:22,440 --> 00:25:24,480
Let me go ahead and look at Metasploitable 2 first

722
00:25:24,480 --> 00:25:27,030
because this one has a lot of vulnerabilities.

723
00:25:27,030 --> 00:25:29,790
Now, you'll notice here that I can't export this as a report

724
00:25:29,790 --> 00:25:32,820
yet, and the reason is it's still running this scan.

725
00:25:32,820 --> 00:25:34,950
I started this scan over an hour ago

726
00:25:34,950 --> 00:25:36,690
and we're still at only 99%,

727
00:25:36,690 --> 00:25:38,970
but we found a lot of vulnerabilities.

728
00:25:38,970 --> 00:25:43,950
Here even at 99%, we can see 171 informational, 8 lows,

729
00:25:43,950 --> 00:25:47,490
44 mediums, 13 highs, and 15 criticals.

730
00:25:47,490 --> 00:25:49,260
This is a really vulnerable system,

731
00:25:49,260 --> 00:25:51,000
and if this was on your production network,

732
00:25:51,000 --> 00:25:52,530
you would definitely want to start remediating

733
00:25:52,530 --> 00:25:53,790
all these issues.

734
00:25:53,790 --> 00:25:55,200
So what are some of these issues?

735
00:25:55,200 --> 00:25:57,090
Well, let's go ahead and click on our vulnerabilities

736
00:25:57,090 --> 00:25:58,800
and we'll look at the first one we have,

737
00:25:58,800 --> 00:26:01,980
which is NFS Exported Share Information Disclosure,

738
00:26:01,980 --> 00:26:04,800
and this is a 10.0, which is critical.

739
00:26:04,800 --> 00:26:06,360
You could see it's under the RPC

740
00:26:06,360 --> 00:26:08,640
or remote procedure call family of plugins,

741
00:26:08,640 --> 00:26:10,890
and it happened one time on the system.

742
00:26:10,890 --> 00:26:13,530
If I click on it, I can get more information about it.

743
00:26:13,530 --> 00:26:16,110
Going down the left, I'll see the description, the solution,

744
00:26:16,110 --> 00:26:17,850
and the output we got from the scanner,

745
00:26:17,850 --> 00:26:20,040
and on the right we'll see information about the plugin

746
00:26:20,040 --> 00:26:22,950
such as its ID, the severity, the version,

747
00:26:22,950 --> 00:26:25,320
the type, the family, when it was published,

748
00:26:25,320 --> 00:26:27,060
and when it was last modified.

749
00:26:27,060 --> 00:26:28,920
As you can see, this is a really well-known

750
00:26:28,920 --> 00:26:32,160
and old vulnerability from all the way back in 2003,

751
00:26:32,160 --> 00:26:33,780
over 20 years ago.

752
00:26:33,780 --> 00:26:35,700
In addition to that, we could see risk information

753
00:26:35,700 --> 00:26:38,310
such as what the risk factor is, in this case critical,

754
00:26:38,310 --> 00:26:40,770
and the score that is associated with it, in this case,

755
00:26:40,770 --> 00:26:44,910
a 10.0 critical under the CVSS version two standard.

756
00:26:44,910 --> 00:26:48,630
Now, why isn't CVSS version three or version 3.1 here?

757
00:26:48,630 --> 00:26:50,940
Well, because this is a really old vulnerability

758
00:26:50,940 --> 00:26:52,920
from 20 years ago and they haven't updated it

759
00:26:52,920 --> 00:26:54,150
to the latest scoring system,

760
00:26:54,150 --> 00:26:56,700
but we still know it's very vulnerable.

761
00:26:56,700 --> 00:26:59,040
Then we could see vulnerability information on the right

762
00:26:59,040 --> 00:27:01,230
that says things like, is there an exploit available?

763
00:27:01,230 --> 00:27:02,550
True, yes, there is.

764
00:27:02,550 --> 00:27:04,230
That again, makes it even more serious for us

765
00:27:04,230 --> 00:27:05,460
to patch this vulnerability

766
00:27:05,460 --> 00:27:07,080
because not only are we vulnerable,

767
00:27:07,080 --> 00:27:09,330
but attackers also know how to exploit it.

768
00:27:09,330 --> 00:27:11,490
In addition to that, we can see the ease of that exploit

769
00:27:11,490 --> 00:27:13,500
is that exploits are publicly available

770
00:27:13,500 --> 00:27:15,690
and the vulnerability was first known

771
00:27:15,690 --> 00:27:18,300
back on January 1st, 1985,

772
00:27:18,300 --> 00:27:21,120
so it's really, really old vulnerability here.

773
00:27:21,120 --> 00:27:22,500
You can see what you can exploit it with.

774
00:27:22,500 --> 00:27:24,540
In this case, you can use Metasploit,

775
00:27:24,540 --> 00:27:27,270
and we can see reference information including the CVEs

776
00:27:27,270 --> 00:27:30,767
associated with it, which were all written back in 1999,

777
00:27:30,767 --> 00:27:33,840
and you can see that because it says CVE dash 1999 dash,

778
00:27:33,840 --> 00:27:35,850
and then the number for the three CVEs

779
00:27:35,850 --> 00:27:37,770
associated with this vulnerability.

780
00:27:37,770 --> 00:27:39,720
Let's go back to our vulnerabilities again.

781
00:27:39,720 --> 00:27:40,740
We'll click on the next one,

782
00:27:40,740 --> 00:27:44,640
which is the "rexecd Service Detection".

783
00:27:44,640 --> 00:27:46,830
Here we see that that service is running on the host

784
00:27:46,830 --> 00:27:48,480
and it's designed to allow users of the network

785
00:27:48,480 --> 00:27:51,060
to execute commands remotely, which could be a bad thing

786
00:27:51,060 --> 00:27:53,130
for us as cybersecurity professionals.

787
00:27:53,130 --> 00:27:55,290
So to fix it, you would comment out the 'exec' line

788
00:27:55,290 --> 00:27:59,400
inside the /etc/inetd/.conf file,

789
00:27:59,400 --> 00:28:02,070
and then restart the inetd process.

790
00:28:02,070 --> 00:28:03,870
So this one's a pretty easy one to fix,

791
00:28:03,870 --> 00:28:06,090
and so we can go in comment at that line,

792
00:28:06,090 --> 00:28:07,770
and then we would be able to restart the process,

793
00:28:07,770 --> 00:28:09,210
re-scan our system and verify

794
00:28:09,210 --> 00:28:12,090
that this critical vulnerability is no longer there.

795
00:28:12,090 --> 00:28:13,950
Let's go ahead and look at our vulnerabilities again.

796
00:28:13,950 --> 00:28:15,480
Let's scroll down here and take a look at

797
00:28:15,480 --> 00:28:17,700
our Bind Shell Backdoor Detection.

798
00:28:17,700 --> 00:28:19,620
This one has a 9.8 rating,

799
00:28:19,620 --> 00:28:20,453
and again, you can see

800
00:28:20,453 --> 00:28:22,890
that this is a shell listening on a remote port

801
00:28:22,890 --> 00:28:24,930
without any authentication being required,

802
00:28:24,930 --> 00:28:26,220
and this would be a really bad thing

803
00:28:26,220 --> 00:28:27,690
because the attacker can use it to connect

804
00:28:27,690 --> 00:28:29,250
to the remote port and send commands

805
00:28:29,250 --> 00:28:30,630
directly to that system.

806
00:28:30,630 --> 00:28:31,590
How do we solve this?

807
00:28:31,590 --> 00:28:33,390
Well, we want to verify if the remote host

808
00:28:33,390 --> 00:28:34,350
has been compromised

809
00:28:34,350 --> 00:28:36,390
and then reinstall the system if necessary.

810
00:28:36,390 --> 00:28:38,370
Essentially, we think this is a backdoor

811
00:28:38,370 --> 00:28:39,969
or a root kit of some kind,

812
00:28:39,969 --> 00:28:41,190
and this would be a really bad thing,

813
00:28:41,190 --> 00:28:43,050
so we would want to be able to fix that.

814
00:28:43,050 --> 00:28:44,700
And again, you can see all the details there,

815
00:28:44,700 --> 00:28:48,120
including the CVSS scores over on the right hand side.

816
00:28:48,120 --> 00:28:49,680
If we go back to our vulnerabilities,

817
00:28:49,680 --> 00:28:51,750
we can look at some other ones such as our highs,

818
00:28:51,750 --> 00:28:54,300
our mediums, or our lows by clicking through all of these.

819
00:28:54,300 --> 00:28:56,190
But because there are so many here,

820
00:28:56,190 --> 00:28:59,640
what I would probably do is instead I would run my report,

821
00:28:59,640 --> 00:29:02,400
export that as a PDF, showing me all the vulnerabilities,

822
00:29:02,400 --> 00:29:04,950
including all of the solutions for those vulnerabilities,

823
00:29:04,950 --> 00:29:06,120
and then we can pass that over

824
00:29:06,120 --> 00:29:08,430
to our system administrators in a prioritized manner,

825
00:29:08,430 --> 00:29:10,380
which shows them which things we want them to fix first,

826
00:29:10,380 --> 00:29:12,180
and then once they tell us they've done that,

827
00:29:12,180 --> 00:29:13,440
we would re-scan the system

828
00:29:13,440 --> 00:29:16,600
to see if our 95 vulnerabilities now went down to 50 or 40

829
00:29:17,491 --> 00:29:19,950
or 20 or 10 or maybe even 0.

830
00:29:19,950 --> 00:29:22,140
But that's probably not going to happen because as you saw,

831
00:29:22,140 --> 00:29:25,380
even really secure hosts still have 5 or 10 or 15

832
00:29:25,380 --> 00:29:27,030
of these informational things.

833
00:29:27,030 --> 00:29:29,190
And on this system, we have quite a few informational

834
00:29:29,190 --> 00:29:32,640
as well, with 57% of our findings being informational.

835
00:29:32,640 --> 00:29:34,860
But again, what I'm really worried about is these criticals,

836
00:29:34,860 --> 00:29:36,900
these highs, and then even the mediums.

837
00:29:36,900 --> 00:29:38,850
The lows don't usually worry me as much,

838
00:29:38,850 --> 00:29:40,440
and then the informational don't usually worry me

839
00:29:40,440 --> 00:29:41,520
as much either.

840
00:29:41,520 --> 00:29:42,870
These are the kind of things you need to look at

841
00:29:42,870 --> 00:29:45,090
as you're going through a tool like Nessus.

842
00:29:45,090 --> 00:29:46,770
The last one we have is our basic scan

843
00:29:46,770 --> 00:29:48,240
of the entire network.

844
00:29:48,240 --> 00:29:50,190
Now here you can see that I had four machines

845
00:29:50,190 --> 00:29:52,440
inside of the scope of this particular scan,

846
00:29:52,440 --> 00:29:54,270
and the one that isn't there is Metasploitable

847
00:29:54,270 --> 00:29:57,060
because I added that in after this scan started.

848
00:29:57,060 --> 00:29:59,940
Now because of that, you can see which machines we have.

849
00:29:59,940 --> 00:30:03,480
In this case the .136 is my Kali Linux machine.

850
00:30:03,480 --> 00:30:05,880
The .116 is my MAC system.

851
00:30:05,880 --> 00:30:08,520
The .138 is my Windows 11 system,

852
00:30:08,520 --> 00:30:11,190
and my .137 is my Ubuntu system.

853
00:30:11,190 --> 00:30:12,990
As you can see here, this is what you want

854
00:30:12,990 --> 00:30:14,160
your network to look like.

855
00:30:14,160 --> 00:30:15,900
This is a nice clean scan.

856
00:30:15,900 --> 00:30:17,760
We only have two low vulnerabilities,

857
00:30:17,760 --> 00:30:19,200
and those low vulnerabilities

858
00:30:19,200 --> 00:30:20,850
were basically self-signed certificates

859
00:30:20,850 --> 00:30:23,880
for the SSL being run on the Nessus scanner itself.

860
00:30:23,880 --> 00:30:26,100
So that tells me these systems aren't that vulnerable

861
00:30:26,100 --> 00:30:28,230
to attack and they're in a pretty good shape.

862
00:30:28,230 --> 00:30:29,880
This is what you want your systems to look like

863
00:30:29,880 --> 00:30:32,220
by the time you're done doing all your remediation.

864
00:30:32,220 --> 00:30:34,650
Unfortunately though, in most production networks,

865
00:30:34,650 --> 00:30:37,020
your scans are going to look a lot more like this

866
00:30:37,020 --> 00:30:38,850
than they are the one that I just showed you.

867
00:30:38,850 --> 00:30:41,250
And the reason for that is sometimes systems are offline

868
00:30:41,250 --> 00:30:42,540
when people push patches,

869
00:30:42,540 --> 00:30:44,580
sometimes the systems don't take the patches.

870
00:30:44,580 --> 00:30:46,110
Sometimes people say, remind me later,

871
00:30:46,110 --> 00:30:48,060
instead of installing those security patches.

872
00:30:48,060 --> 00:30:49,200
And for all those reasons,

873
00:30:49,200 --> 00:30:51,420
you start getting vulnerabilities in your system.

874
00:30:51,420 --> 00:30:53,670
The nice thing about using a tool like Nessus though

875
00:30:53,670 --> 00:30:56,430
is by going through these and scanning an entire network,

876
00:30:56,430 --> 00:30:58,500
you're going to be able to see very quickly which machines

877
00:30:58,500 --> 00:31:00,060
you need to focus your efforts on.

878
00:31:00,060 --> 00:31:02,940
So if I saw these four plus the Metasploitable 2 VM

879
00:31:02,940 --> 00:31:05,040
on the screen, I would know immediately

880
00:31:05,040 --> 00:31:06,900
that the Metasploitable 2 VM is the one

881
00:31:06,900 --> 00:31:07,890
I need to worry about

882
00:31:07,890 --> 00:31:10,110
because it already had so much other things

883
00:31:10,110 --> 00:31:12,390
that were critical, high, medium, and low,

884
00:31:12,390 --> 00:31:13,890
in addition to the informational.

885
00:31:13,890 --> 00:31:15,960
And so that's where my attention would go.

886
00:31:15,960 --> 00:31:17,610
That's the idea of using one of these tools

887
00:31:17,610 --> 00:31:19,260
to identify what things are on your network

888
00:31:19,260 --> 00:31:21,360
that are vulnerable and what things you can do to fix

889
00:31:21,360 --> 00:31:22,460
those vulnerabilities.

