Kali practice-vulnerability scanning
In the host discovery, port discovery, service scanning to get the target system open port services, service version information, and then you can view the version information and patch list on the official website of the software, while high-risk vulnerabilities can directly control the target system.
On this basis, make a basic judgment on the vulnerabilities and weaknesses of the target system, but there will be a lot of drawbacks. There are a variety of services running on many scanning ports, and you will be busy querying official documents on major websites. Reading a large number of articles makes you very tired, which is relatively expensive and slow.
We can go to various libraries to search for vulnerabilities, and then verify them one by one, this is also a method, but the efficiency is not high, you may not be good at programs written in different languages, so at this time, the requirements for * testers are higher and more difficult, there is an easy way to use vulnerability scanners, these scanners call vulnerabilities to exploit the code for various probes toward your specified target.
Course catalogue:
Brief introduction to vulnerability scanning
Basic concept of vulnerability
NMAP- scan script
Vulnerability Scanner-openvas initialization
Weakness Scanner-openvas (2)
Weakness Scanner-openvas (3)
Vulnerability Scanner-openvas (scan configuration)
Download and install NESSUS-
Basic configuration of NESSUS
NESSUS- scanning (1)
NESSUS scanning (2)
NEXPOSE environment preparation
Detailed explanation of NEXPOSE function (1)
Detailed explanation of NEXPOSE function (2)
Detailed explanation of NEXPOSE function (3)
Curriculum objectives
Master vulnerability scanner invocation vulnerabilities exploit code to make various probes toward your specified target
Online video http://edu.aqniu.com/course/300/lesson/list