20. Vulnerability Scanning and Assessment
Chala mitrano, Chapter 19 madhe aapan target chi yaadi banavli – konte ports ughde, konti service, konta version. Aata pudhcha prashna: ya versions madhe kontya kamjorya (vulnerabilities / असुरक्षितता) aahet? Doctor aadhi report baghto, mag upchar tharavto. Aapan pan aadhi vulnerability shodhu, tyanna gambhirtenusar kramvar lavu, aani mag report karu. Lakshat theva – vulnerability scanner "hack" karat nahi, to fakt sangto kuthe dhoka aahe. Aani punha ekda: sagle labs fakt tumchya host-only lab var (Metasploitable 2 192.168.56.20). Samjla ka? Chala suru karuya!
What you will learn in this chapter
- What a vulnerability is, and the words CVE, CWE and CVSS
- Finding known vulnerabilities manually with searchsploit and the NVD website
- Nmap vulnerability scripts as a quick first check
- OpenVAS / Greenbone: installing and running a full network vulnerability scan
- Nikto for web server scanning
- Reading results, removing false positives and prioritising fixes
- Writing a clear vulnerability report – the real product of an assessment
Lab scope for this whole chapter
Vulnerability scanners send thousands of requests and can crash old services. Run every scan in this chapter only against Metasploitable 2 (192.168.56.20), DVWA or Juice Shop on your host-only network – never against any website or server you do not own.
Concepts in this chapter
- 20.1Vulnerability, CVE, CWE and CVSS
- 20.2Manual Lookup: searchsploit and Exploit-DB
- 20.3Nmap Vulnerability Scripts
- 20.4OpenVAS / Greenbone: Full Vulnerability Scanning
- 20.5Nikto: Web Server Scanning
- 20.6Reading Results: False Positives and Prioritising
- 20.7Writing a Vulnerability Report
- 20.8Red vs Blue, Project and Real Incidents
The chapter recap is at the end of the last concept page.