45 Scanning and Enumeration – Vulnerability Scanning
45 Scanning and Enumeration – Vulnerability Scanning
Mathew J. Heath Van Horn, PhD
This lab helps students become familiar with the Nessus vulnerability scanner and how it can be used to find vulnerabilities to exploit on a network. Nessus by Tenable has been used in the industry for over 25 years. It is updated weekly with new exploits by the Common Vulnerabilities and Exposures (CVE) database.
Learning Objectives
- Perform a vulnerability scan of a vulnerable target using Nessus
- Read and investigate ways to take advantage of detected vulnerabilities
- Exploit a critical vulnerability using Metasploit
Prerequisites
Deliverables
- 4 Screenshots are required
- Nmap scan of the target network that identifies the target machine
- Results of a completed Nessus advanced scan of the target machine
- A Nessus report of the critical vulnerability
- Metasploitable report of the module that can be used against the vulnerability
Resources
Contributors and Testers
- An idea proposed by Raechel Ferguson
- Dante Rocca, Cybersecurity Student, ERAU-Prescott
Phase I – Install Nessus
Nessus has continuous updates. If you skipped the Nessus installation from Chapter 12, you will need to do this now. If you haven’t updated Nessus recently, you must complete the following steps. These steps are based on your prior knowledge from completing Section 1 of this book.
- Open the virtual box manager and select the Kali VM
- Click on settings, click on network, and make sure it is attached to NAT
- Press OK and start the Kali VM
- From the command line, start Nessus with the following command
> systemctl start nessusd.service
- Open the Nessus user interface by opening Firefox and going to this URL. It may say it is insecure but click advanced and accept the risk to continue
https://kali:8834/
- Click on About –> Software Update –> Manual Software Update
- Click on Update all components then continue
- Let the software update. This could take a while depending on the last time your Kali VM had access to the Internet
- Once the update has been completed, power off the Kali VM
- Return back to the Oracle VM manager and on the Kali VM switch the network card back to the generic adapter
Phase II – Running a Nessus Scan Against Metasploitable
Nessus is a popular vulnerability scanner that can detect vulnerabilities running on devices. This is useful for defensive purposes to detect areas of weakness but can be used by attackers to find holes in the network.
- Open GNS3 workspace and wait for the green lights
- Start the following machines:
- DHCP Server
- Router
- Kali VM
- Metasploitable3-Linux
- Once all machines are running, find the IP address of the Metasploitable3-Linux box by running a Nmap scan on the <IP_ADDRESS>/24 network from the Kali VM. In this example, the target has an IP address of <IP_ADDRESS>
> sudo nmap -O <IP_ADDRESS>/24
- Once you have the IP, start Nessus with the following command
> systemctl start nessusd.service
- Open the interface by opening Firefox