1
00:00:00,270 --> 00:00:01,230
In this lesson,

2
00:00:01,230 --> 00:00:03,690
I'm going to show you how to assess scan outputs.

3
00:00:03,690 --> 00:00:05,490
And so instead of using Nessus,

4
00:00:05,490 --> 00:00:07,170
we're going to go ahead and use OpenVAS

5
00:00:07,170 --> 00:00:09,000
to see how that one looks a little bit different.

6
00:00:09,000 --> 00:00:10,860
Now, in this one I'm going to go a little bit more in depth

7
00:00:10,860 --> 00:00:11,820
than I did last time,

8
00:00:11,820 --> 00:00:13,290
because I'm going to show you everything

9
00:00:13,290 --> 00:00:14,850
from creating the scan account,

10
00:00:14,850 --> 00:00:17,490
configuring its permissions, setting up OpenVAS,

11
00:00:17,490 --> 00:00:20,220
and then looking at the results that come from that scan.

12
00:00:20,220 --> 00:00:22,530
Let's jump into the environment and get started.

13
00:00:22,530 --> 00:00:25,830
First, we need to go ahead and configure our scan accounts.

14
00:00:25,830 --> 00:00:27,870
so I'm going to open up DC1

15
00:00:27,870 --> 00:00:31,350
and then use my Active Directory users and computers area.

16
00:00:31,350 --> 00:00:33,420
And from here I'm going to right-click on Users

17
00:00:33,420 --> 00:00:35,880
and select New and then Group.

18
00:00:35,880 --> 00:00:38,040
When I do this, I'm going to enter my name from my group.

19
00:00:38,040 --> 00:00:41,760
I'm going to call it sec-glo-scan.

20
00:00:41,760 --> 00:00:43,800
And this is the group name we're going to use for our auditors

21
00:00:43,800 --> 00:00:45,720
who are going to perform our scans.

22
00:00:45,720 --> 00:00:47,190
Now, when we look at the scope of this,

23
00:00:47,190 --> 00:00:48,420
it should be global

24
00:00:48,420 --> 00:00:50,850
and the type should be selected as Security.

25
00:00:50,850 --> 00:00:53,460
Once that's done, go ahead and hit OK.

26
00:00:53,460 --> 00:00:55,140
Next, we're going to right-click on Users

27
00:00:55,140 --> 00:00:57,630
and select New, and then User.

28
00:00:57,630 --> 00:00:59,370
Here we're going to enter in the full name

29
00:00:59,370 --> 00:01:01,740
and username as scan.

30
00:01:01,740 --> 00:01:05,160
Then I'm going to click Next and I'm going to enter a password.

31
00:01:05,160 --> 00:01:07,800
Now, I'm going to uncheck the user must change password

32
00:01:07,800 --> 00:01:09,690
and check the password never expires,

33
00:01:09,690 --> 00:01:12,090
and then click None and then Finish.

34
00:01:12,090 --> 00:01:13,200
This is a common setting when

35
00:01:13,200 --> 00:01:15,000
you're setting up a scan account.

36
00:01:15,000 --> 00:01:16,320
Now, when you do this,

37
00:01:16,320 --> 00:01:18,600
make sure you're using a good, strong password

38
00:01:18,600 --> 00:01:20,400
because again, we're not requiring people

39
00:01:20,400 --> 00:01:21,570
to change their password here

40
00:01:21,570 --> 00:01:23,280
and the password will never expire.

41
00:01:23,280 --> 00:01:24,750
Something long and strong

42
00:01:24,750 --> 00:01:27,780
and complicated would be a great use case here.

43
00:01:27,780 --> 00:01:29,850
Next, we're going to right-click the scan object

44
00:01:29,850 --> 00:01:31,380
that we just created, that user,

45
00:01:31,380 --> 00:01:32,335
and we're going to select add to group.

46
00:01:32,335 --> 00:01:36,930
Here we're going to type in sec-glo-scan,

47
00:01:36,930 --> 00:01:38,430
and then click Check Name.

48
00:01:38,430 --> 00:01:40,380
Once that's underlined, click OK,

49
00:01:40,380 --> 00:01:42,540
and then we'll be able to hit OK again.

50
00:01:42,540 --> 00:01:44,190
Now, we can close the active directory

51
00:01:44,190 --> 00:01:46,200
users and computers console.

52
00:01:46,200 --> 00:01:48,180
Next, we're going to go into the server manager

53
00:01:48,180 --> 00:01:50,880
and select Tools, Group Policy Management.

54
00:01:50,880 --> 00:01:53,670
This will allow us to go and manage our group policies.

55
00:01:53,670 --> 00:01:54,630
Once we're in here,

56
00:01:54,630 --> 00:01:56,490
then right-click the ComputersOU container

57
00:01:56,490 --> 00:02:00,060
and select "Create a GPO in this domain, and Link it here...".

58
00:02:00,060 --> 00:02:00,990
When we get to the box,

59
00:02:00,990 --> 00:02:02,940
we're going to go ahead and call it something,

60
00:02:02,940 --> 00:02:06,180
in this case, "515support Scanning Policy".

61
00:02:06,180 --> 00:02:08,340
If you remember, 515Support is going to be

62
00:02:08,340 --> 00:02:09,240
our fictional company

63
00:02:09,240 --> 00:02:11,700
that we're using in most of our examples here.

64
00:02:11,700 --> 00:02:14,130
Now, we're going to expand the Computer Configuration

65
00:02:14,130 --> 00:02:15,390
and then Policies,

66
00:02:15,390 --> 00:02:18,150
and then Window Settings, then Security Settings,

67
00:02:18,150 --> 00:02:21,360
then Local Policies, and then User Rights Assignment.

68
00:02:21,360 --> 00:02:25,110
Once you do that, double click the deny log on locally.

69
00:02:25,110 --> 00:02:28,321
This is going to make sure that we're not going to allow people

70
00:02:28,321 --> 00:02:30,300
to log on the local machines as an administrator.

71
00:02:30,300 --> 00:02:33,840
We can only do it remotely by using our scanning engine.

72
00:02:33,840 --> 00:02:36,210
We're going to check the define these policy settings box,

73
00:02:36,210 --> 00:02:38,610
and then click Add Users or Groups.

74
00:02:38,610 --> 00:02:40,230
Again, we're going to type in our group,

75
00:02:40,230 --> 00:02:43,980
which is "sec-glo-scan", and click OK,

76
00:02:43,980 --> 00:02:46,650
and then OK to confirm the main dialogue.

77
00:02:46,650 --> 00:02:48,780
At this point, we can double click the deny log

78
00:02:48,780 --> 00:02:50,610
on through remote desktop services

79
00:02:50,610 --> 00:02:52,410
because again, we don't want people logging

80
00:02:52,410 --> 00:02:53,850
onto these machines,

81
00:02:53,850 --> 00:02:55,230
and we're going to check the define

82
00:02:55,230 --> 00:02:58,860
these policy settings box and click Add User or Group.

83
00:02:58,860 --> 00:03:02,760
Again, we're going to put in our group, sec-glo-scan,

84
00:03:02,760 --> 00:03:05,490
and click OK, and then, OK, once more.

85
00:03:05,490 --> 00:03:06,660
Under Security Settings,

86
00:03:06,660 --> 00:03:08,550
we're going to select the Registry Node.

87
00:03:08,550 --> 00:03:10,200
We're going to right-click in the empty pane

88
00:03:10,200 --> 00:03:12,150
and select Add Key.

89
00:03:12,150 --> 00:03:15,420
From here, we're going to select Users and click OK.

90
00:03:15,420 --> 00:03:18,060
Then we'll click Advanced and click Add.

91
00:03:18,060 --> 00:03:20,430
Then we can select a principle.

92
00:03:20,430 --> 00:03:25,430
Again, we're going to type in sec-glo-scan, and click OK.

93
00:03:25,710 --> 00:03:28,530
From the type box, we're going to select Deny,

94
00:03:28,530 --> 00:03:30,150
from the applies to this box,

95
00:03:30,150 --> 00:03:33,990
we're going to ensure this object and child object is selected.

96
00:03:33,990 --> 00:03:35,070
Now at this point,

97
00:03:35,070 --> 00:03:37,680
we can select the show advanced permissions,

98
00:03:37,680 --> 00:03:40,950
and we're going to check the following boxes, set value,

99
00:03:40,950 --> 00:03:44,460
create sub key, create link, delete, change permissions,

100
00:03:44,460 --> 00:03:45,690
and take ownership,

101
00:03:45,690 --> 00:03:48,150
and then we'll confirm all the dialogue boxes.

102
00:03:48,150 --> 00:03:50,400
This allows us to create those keys that we need

103
00:03:50,400 --> 00:03:52,260
inside the registry to give us the right

104
00:03:52,260 --> 00:03:53,940
permissions for our scanner.

105
00:03:53,940 --> 00:03:55,950
Next, we're going to right-click in the empty pane

106
00:03:55,950 --> 00:03:58,080
and again, select Add Key.

107
00:03:58,080 --> 00:04:01,320
From here, we're going to select Machine and click OK.

108
00:04:01,320 --> 00:04:04,830
Then click Advanced and Add and select a principle.

109
00:04:04,830 --> 00:04:09,210
Once more, we're going to type in sec-glo-scan, and click OK.

110
00:04:09,210 --> 00:04:11,520
From the type box, we're going to select Deny,

111
00:04:11,520 --> 00:04:13,170
and for the applies to list box,

112
00:04:13,170 --> 00:04:16,260
we're going to select this object and child objects.

113
00:04:16,260 --> 00:04:18,600
Then we're going to click the Show Advance Permission

114
00:04:18,600 --> 00:04:20,940
and make sure we check the following boxes,

115
00:04:20,940 --> 00:04:24,600
"Set Value", "Create Subkey", "Create Link", "Delete",

116
00:04:24,600 --> 00:04:26,580
"Change", and "Take ownership".

117
00:04:26,580 --> 00:04:29,250
Once more, confirm all the dialogue boxes,

118
00:04:29,250 --> 00:04:31,650
and now we have set the right permissions.

119
00:04:31,650 --> 00:04:33,640
So at this point we have now created a user

120
00:04:33,640 --> 00:04:36,180
and a group with the right permissions that we can use

121
00:04:36,180 --> 00:04:37,260
for our scanners.

122
00:04:37,260 --> 00:04:39,300
Anytime we want do credentialed scans now,

123
00:04:39,300 --> 00:04:43,440
we're going to use the user account, sec-glo-scan

124
00:04:43,440 --> 00:04:46,320
inside the group sec-glo-scan

125
00:04:46,320 --> 00:04:47,820
because that is our scanning account,

126
00:04:47,820 --> 00:04:50,040
so any host in the network will allow us to connect

127
00:04:50,040 --> 00:04:51,600
using administrative credentials

128
00:04:51,600 --> 00:04:53,160
when we're using the scan account,

129
00:04:53,160 --> 00:04:54,810
and it gives us local administrative rights

130
00:04:54,810 --> 00:04:55,743
to the registry,

131
00:04:56,815 --> 00:04:58,380
across all the computers in this domain.

132
00:04:58,380 --> 00:05:00,480
Now that we've finished creating the scan account,

133
00:05:00,480 --> 00:05:03,120
we need to go into OpenVAS and start using it.

134
00:05:03,120 --> 00:05:05,250
So we're going to go over to my OpenVAS scanning machine,

135
00:05:05,250 --> 00:05:09,060
and we're going to go to the webpage 10.1.0.43,

136
00:05:09,060 --> 00:05:10,740
which is my local account.

137
00:05:10,740 --> 00:05:12,420
When you're using OpenVAS, you're going to do it

138
00:05:12,420 --> 00:05:14,880
through a webpage that then interacts with the server

139
00:05:14,880 --> 00:05:17,100
and the program on that local machine.

140
00:05:17,100 --> 00:05:18,270
Once we're there, I'm going to log in

141
00:05:18,270 --> 00:05:20,760
with my admin user and my password.

142
00:05:20,760 --> 00:05:23,250
Now, once I'm in the system, you can see the dashboard

143
00:05:23,250 --> 00:05:24,690
and there isn't much information here

144
00:05:24,690 --> 00:05:26,760
because they haven't done any scans yet.

145
00:05:26,760 --> 00:05:29,280
First, I want to go to configuration under the menu

146
00:05:29,280 --> 00:05:31,260
and then select credentials.

147
00:05:31,260 --> 00:05:33,630
From here, I want to select New credential,

148
00:05:33,630 --> 00:05:36,111
and then in that dialogue box I'm going to add a new account

149
00:05:36,111 --> 00:05:39,810
known as sec-glo-scan,

150
00:05:39,810 --> 00:05:41,970
that user account we just created.

151
00:05:41,970 --> 00:05:44,160
Now, from the allow insecure use options,

152
00:05:44,160 --> 00:05:45,270
I'm going to select Yes

153
00:05:45,270 --> 00:05:47,820
because I want to find every vulnerability in my systems,

154
00:05:47,820 --> 00:05:50,250
not just the ones that might not cause problems.

155
00:05:50,250 --> 00:05:53,190
Then in the username box, I'm going to type 515Support,

156
00:05:53,190 --> 00:05:57,060
which is my domain \scan, and in the password box,

157
00:05:57,060 --> 00:05:58,830
I'm going to type my password.

158
00:05:58,830 --> 00:06:02,040
Now, notice the slash scan is that user account we created.

159
00:06:02,040 --> 00:06:03,723
After we do this, click Save.

160
00:06:04,650 --> 00:06:06,330
Now, that we have our credentials saved,

161
00:06:06,330 --> 00:06:10,020
we can now go and configure a scan scope and sensitivity.

162
00:06:10,020 --> 00:06:12,120
When we do this, we're going to decide what group

163
00:06:12,120 --> 00:06:13,560
of targets we want to go after

164
00:06:13,560 --> 00:06:15,420
with our vulnerability scanning,

165
00:06:15,420 --> 00:06:17,040
so we're going to click on configuration

166
00:06:17,040 --> 00:06:18,540
and then select targets.

167
00:06:18,540 --> 00:06:20,880
Here, I'm going to click New Target.

168
00:06:20,880 --> 00:06:22,410
Then in that web dialogue,

169
00:06:22,410 --> 00:06:26,700
I'm going to type in the name, 515support-Hosts-Windows

170
00:06:26,700 --> 00:06:28,860
because I'm going to do a scan across all my hosts

171
00:06:28,860 --> 00:06:31,410
inside my network that are Windows-based.

172
00:06:31,410 --> 00:06:33,300
Next to the host, I'm going to select manual

173
00:06:33,300 --> 00:06:35,730
and type in the IP address that I want to scan.

174
00:06:35,730 --> 00:06:39,774
In this case 10.1.0.0-24, which is my subnet

175
00:06:39,774 --> 00:06:42,570
that contains all my Windows hosts.

176
00:06:42,570 --> 00:06:44,670
Next, I can click to exclude some hosts,

177
00:06:44,670 --> 00:06:46,410
so I'm going to select manual

178
00:06:46,410 --> 00:06:51,410
and type in 10.1.0.254, 10.1.0.243.

179
00:06:52,680 --> 00:06:56,130
Now, the .243 machine is the box I'm actually scanning with,

180
00:06:56,130 --> 00:06:58,680
so I don't want to actually scan this as part of my host

181
00:06:58,680 --> 00:07:00,240
because it's actually an excluded area.

182
00:07:00,240 --> 00:07:02,280
It is my vulnerability scanner.

183
00:07:02,280 --> 00:07:03,420
Then under credentials,

184
00:07:03,420 --> 00:07:06,570
I'm going to select sec-glo-scan

185
00:07:06,570 --> 00:07:08,700
because that is one that we have authorized

186
00:07:08,700 --> 00:07:10,770
as that administrative scanning account,

187
00:07:10,770 --> 00:07:13,260
and then I'm going to click on Save.

188
00:07:13,260 --> 00:07:15,690
Now, next I'm going to go into the configuration menu

189
00:07:15,690 --> 00:07:17,790
and click Scan Configs.

190
00:07:17,790 --> 00:07:19,200
Here, we're going to take a few minutes

191
00:07:19,200 --> 00:07:21,990
to just browse the default scan configurations,

192
00:07:21,990 --> 00:07:24,450
but we're not going to make any changes here.

193
00:07:24,450 --> 00:07:26,850
From the scans, I can select Tasks

194
00:07:26,850 --> 00:07:28,110
and from the tasks there's going to be

195
00:07:28,110 --> 00:07:29,640
a wizard prompt that appears.

196
00:07:29,640 --> 00:07:31,680
If it does, just close it.

197
00:07:31,680 --> 00:07:34,237
Next, click on new task and then select New Task.

198
00:07:34,237 --> 00:07:37,770
In the new task dialogue box, we're going to type in the name

199
00:07:37,770 --> 00:07:38,700
that we want to call this,

200
00:07:38,700 --> 00:07:43,700
in this case, 515support-Hosts-Windows-Full.

201
00:07:43,800 --> 00:07:45,510
Then from the scan targets box,

202
00:07:45,510 --> 00:07:47,700
we're going to select the group we've just set up,

203
00:07:47,700 --> 00:07:50,700
515support-Hosts-Windows.

204
00:07:50,700 --> 00:07:52,260
From the scan configuration box,

205
00:07:52,260 --> 00:07:54,090
We're going to ensure that we select full

206
00:07:54,090 --> 00:07:55,720
and fast, which is the type

207
00:07:56,689 --> 00:07:57,522
of vulnerability scan we want to conduct,

208
00:07:57,522 --> 00:07:59,040
and then we'll click Save,

209
00:07:59,040 --> 00:08:02,430
and finally we'll click Play, which will start our scan.

210
00:08:02,430 --> 00:08:04,590
Now, because I'm using the community edition here,

211
00:08:04,590 --> 00:08:06,870
I don't have the ability to schedule tasks,

212
00:08:06,870 --> 00:08:09,540
that's a feature of the pro version of this tool.

213
00:08:09,540 --> 00:08:11,700
So if you're going to be using this on your own home network,

214
00:08:11,700 --> 00:08:13,110
you're going to have to actually remember

215
00:08:13,110 --> 00:08:15,690
to start up the scan yourself at designated intervals,

216
00:08:15,690 --> 00:08:17,790
instead of having it do it for you automatically.

217
00:08:17,790 --> 00:08:19,650
Now, it'll usually take a couple of minutes

218
00:08:19,650 --> 00:08:21,630
or even longer to perform these scans

219
00:08:21,630 --> 00:08:24,630
because it's connecting to each machine inside my scope

220
00:08:24,630 --> 00:08:26,700
and being able to test them for those vulnerabilities.

221
00:08:26,700 --> 00:08:27,960
So I'm going to speed this up here

222
00:08:27,960 --> 00:08:29,550
so you don't have to wait as long.

223
00:08:29,550 --> 00:08:32,010
Once you're done, you're going to get back the results

224
00:08:32,010 --> 00:08:34,500
by going ahead and looking at the scan report,

225
00:08:34,500 --> 00:08:36,990
click on scan, and then results.

226
00:08:36,990 --> 00:08:38,460
Once you do that, you'll see a dashboard

227
00:08:38,460 --> 00:08:39,960
with four key areas.

228
00:08:39,960 --> 00:08:42,960
The top left is all the results by severity class.

229
00:08:42,960 --> 00:08:44,190
So in this case, you could see I had

230
00:08:44,190 --> 00:08:46,410
163 total vulnerabilities.

231
00:08:46,410 --> 00:08:48,926
I had 7 High, 26 Medium, 5 Low,

232
00:08:48,926 --> 00:08:52,440
and the rest of these were log or informational content.

233
00:08:52,440 --> 00:08:54,420
Then in the middle we have a word cluster.

234
00:08:54,420 --> 00:08:55,440
These are words that are coming

235
00:08:55,440 --> 00:08:58,170
to us based on all those vulnerabilities that were found,

236
00:08:58,170 --> 00:09:00,690
and so I could see for instance, that Windows occurred a lot

237
00:09:00,690 --> 00:09:02,070
because these were Windows scans,

238
00:09:02,070 --> 00:09:03,630
so that was a very large word.

239
00:09:03,630 --> 00:09:05,220
So it's a very quick visual way to say,

240
00:09:05,220 --> 00:09:07,590
oh, I have an issue with SSLTLS,

241
00:09:07,590 --> 00:09:09,540
or I have an issue with SSH,

242
00:09:09,540 --> 00:09:11,010
or whatever that vulnerability is

243
00:09:11,010 --> 00:09:12,720
that's really taking up most of your cluster there

244
00:09:12,720 --> 00:09:13,890
inside the words.

245
00:09:13,890 --> 00:09:15,420
Then on the top right side,

246
00:09:15,420 --> 00:09:17,940
you have the results shown based on the severity

247
00:09:17,940 --> 00:09:21,630
inside of CVSS, so it goes from non applicable, low

248
00:09:21,630 --> 00:09:23,010
and then 1 through 10,

249
00:09:23,010 --> 00:09:24,180
and so you could see very quickly

250
00:09:24,180 --> 00:09:26,130
how dangerous things are in your network.

251
00:09:26,130 --> 00:09:28,710
Now, what I really find useful is that bottom part.

252
00:09:28,710 --> 00:09:30,690
Now, in the bottom part, we're seeing the results

253
00:09:30,690 --> 00:09:31,860
10 at a time,

254
00:09:31,860 --> 00:09:34,320
and in those results we are going to see in this case,

255
00:09:34,320 --> 00:09:36,600
10 out of 163.

256
00:09:36,600 --> 00:09:38,430
You'll have the name of the vulnerability.

257
00:09:38,430 --> 00:09:39,930
You'll have the severity.

258
00:09:39,930 --> 00:09:41,670
You'll have the quality of detection.

259
00:09:41,670 --> 00:09:43,740
You'll have the host IP, the name,

260
00:09:43,740 --> 00:09:45,810
which is the DNS name of your server,

261
00:09:45,810 --> 00:09:48,780
and then the location and when that was created.

262
00:09:48,780 --> 00:09:51,270
This is information again at the top level,

263
00:09:51,270 --> 00:09:53,160
but you can drill down and see additional detail

264
00:09:53,160 --> 00:09:55,590
by clicking on the names of those vulnerabilities.

265
00:09:55,590 --> 00:09:57,840
So now that we've done a quick look at our results,

266
00:09:57,840 --> 00:10:00,600
let's go ahead and take a look by filtering

267
00:10:00,600 --> 00:10:03,510
to find out anything associated with a particular host.

268
00:10:03,510 --> 00:10:05,970
For example, if I wanted to find all the vulnerabilities

269
00:10:05,970 --> 00:10:08,790
for the host at 10.1.0.1,

270
00:10:08,790 --> 00:10:10,260
I could go into the filter box,

271
00:10:10,260 --> 00:10:14,730
type host equals 10.1.0.1, and click Update Filter.

272
00:10:14,730 --> 00:10:16,650
This is all the vulnerabilities associated

273
00:10:16,650 --> 00:10:18,000
with my domain controller.

274
00:10:18,000 --> 00:10:19,470
Now, you'll see there's not many here.

275
00:10:19,470 --> 00:10:20,460
Why is that?

276
00:10:20,460 --> 00:10:23,040
Well, because we really only did an uncredentialed scan

277
00:10:23,040 --> 00:10:24,570
against the domain controller.

278
00:10:24,570 --> 00:10:25,830
We gave ourself permissions

279
00:10:25,830 --> 00:10:28,718
with that scan account to have administrative rights

280
00:10:28,718 --> 00:10:31,170
on everything in the network except the domain controller.

281
00:10:31,170 --> 00:10:34,020
So the domain controller is getting an uncredentialed scan,

282
00:10:34,020 --> 00:10:36,750
while everything else is getting a credentialed scan.

283
00:10:36,750 --> 00:10:38,100
Now, let's take a look for instance,

284
00:10:38,100 --> 00:10:40,230
at the null session vulnerability.

285
00:10:40,230 --> 00:10:42,240
When we click on that, we can see that

286
00:10:42,240 --> 00:10:43,890
because the guest account is enabled,

287
00:10:43,890 --> 00:10:45,930
there is a serious configuration here,

288
00:10:45,930 --> 00:10:47,550
and because this is a domain controller,

289
00:10:47,550 --> 00:10:48,900
this is quite alarming.

290
00:10:48,900 --> 00:10:51,150
This is something that definitely should not be there

291
00:10:51,150 --> 00:10:53,700
on a domain controller, which is why there's a high severity

292
00:10:53,700 --> 00:10:55,740
and it's something we should fix quite quickly.

293
00:10:55,740 --> 00:10:58,572
Now, the next thing we want to do is we want to filter out

294
00:10:58,572 --> 00:10:59,405
and adjust our string here.

295
00:10:59,405 --> 00:11:02,370
So instead of looking at the domain controller at 10.1.0.1,

296
00:11:02,370 --> 00:11:05,310
let's go ahead and make that 10.1.0.2.

297
00:11:05,310 --> 00:11:08,790
When we do that, you're going to see a lot more severe results.

298
00:11:08,790 --> 00:11:10,860
This is because we had administrative credentials

299
00:11:10,860 --> 00:11:12,690
and we did a credentialed scan.

300
00:11:12,690 --> 00:11:14,190
Now, when we did this on a host,

301
00:11:14,190 --> 00:11:15,960
we're going to see a lot more vulnerabilities

302
00:11:15,960 --> 00:11:17,850
because we have administrative rights.

303
00:11:17,850 --> 00:11:19,530
In this case, we see a lot of them

304
00:11:19,530 --> 00:11:20,940
that have high severity,

305
00:11:20,940 --> 00:11:23,280
in the 10 range or the nine range.

306
00:11:23,280 --> 00:11:24,240
Now, we can go in

307
00:11:24,240 --> 00:11:26,850
and look at these by clicking on those reports,

308
00:11:26,850 --> 00:11:29,280
and if you have Internet access connected to this,

309
00:11:29,280 --> 00:11:31,590
you can actually go and research those different

310
00:11:31,590 --> 00:11:33,930
CVEs to figure out what you should do.

311
00:11:33,930 --> 00:11:36,600
For example, if we look at the vulnerability in the filter

312
00:11:36,600 --> 00:11:38,160
and we want to find everything that's affected

313
00:11:38,160 --> 00:11:39,840
by a particular vulnerability,

314
00:11:39,840 --> 00:11:41,370
instead of looking at it by host,

315
00:11:41,370 --> 00:11:43,377
we can type in vulnerability~"

316
00:11:44,550 --> 00:11:46,080
and then the name of the vulnerability.

317
00:11:46,080 --> 00:11:51,060
In my case, I'm going to use 4013389, and then end quote.

318
00:11:51,060 --> 00:11:53,610
Once I do that, I click the update filter button

319
00:11:53,610 --> 00:11:55,770
and you'll see that I have a hit for PC2,

320
00:11:55,770 --> 00:11:57,300
which is running Windows 7.

321
00:11:57,300 --> 00:11:59,610
And this is bad news because this is the same vulnerability

322
00:11:59,610 --> 00:12:02,940
that was used by WannaCry, which is known as EternalBlue.

323
00:12:02,940 --> 00:12:04,770
This is a big, bad vulnerability

324
00:12:04,770 --> 00:12:07,350
that allows remote code execution on a system.

325
00:12:07,350 --> 00:12:09,150
So this is one that if you finding your network,

326
00:12:09,150 --> 00:12:11,730
you want to make sure you get it patched up pretty quickly.

327
00:12:11,730 --> 00:12:14,670
Now, additionally, we can look at the same results by,

328
00:12:14,670 --> 00:12:16,770
instead of looking at the vulnerability number,

329
00:12:16,770 --> 00:12:19,140
based on the knowledge base that Microsoft uses,

330
00:12:19,140 --> 00:12:21,570
we can instead look at it based on a CVE.

331
00:12:21,570 --> 00:12:22,560
For example,

332
00:12:22,560 --> 00:12:26,427
I know that the WannaCry vulnerability is CVE-2017-0144,

333
00:12:28,350 --> 00:12:30,649
so I can go into the filter box type

334
00:12:30,649 --> 00:12:35,649
~"CVE-2017-0144" and hit update filter.

335
00:12:38,100 --> 00:12:42,150
Now, I'm going to find any machines that match that CVE.

336
00:12:42,150 --> 00:12:43,110
This is really useful

337
00:12:43,110 --> 00:12:45,960
if there's some new big, bad vulnerability that comes out

338
00:12:45,960 --> 00:12:47,340
and you want to test all your systems

339
00:12:47,340 --> 00:12:49,620
for that particular vulnerability.

340
00:12:49,620 --> 00:12:52,350
For example, I was working in a large organization

341
00:12:52,350 --> 00:12:53,880
when the Apache Struts vulnerability

342
00:12:53,880 --> 00:12:55,530
came out a couple of years ago.

343
00:12:55,530 --> 00:12:58,500
We wanted to identify across our millions of endpoints

344
00:12:58,500 --> 00:13:00,510
which ones were vulnerable to this attack.

345
00:13:00,510 --> 00:13:04,500
So we were able to do a search looking just for that one CVE

346
00:13:04,500 --> 00:13:06,450
as we looked across our network and scanned,

347
00:13:06,450 --> 00:13:09,090
and that way we can find those and patch those quickly.

348
00:13:09,090 --> 00:13:11,460
So hopefully you've enjoyed this short lesson on learning

349
00:13:11,460 --> 00:13:12,750
how to configure your scanner

350
00:13:12,750 --> 00:13:15,120
and use a scanner using OpenVAS

351
00:13:15,120 --> 00:13:17,043
and the Greenbone Community Edition.

