OpenVAS Terms to Know
OpenVAS Terms to Know Host A Host is a single system that is connected to a computer network and that may be scanned. One or many hosts form the basis of a scan target. A host is also an asset type. Any scanned or discovered host can be recorded in the asset database. Hosts in […]
OpenVAS Authenticated Scan using Local Security Checks
An authenticated scan may provide more vulnerability details on the scanned system. During an authenticated scan the target is both scanned from the outside via the network and from the inside via a valid user login. During an authenticated scan OpenVAS logs in to the target system in order to run local security checks (LSC). […]
How to Reset or Create a Password for OpenVas
The password to access OpenVas vulnerability scanner with username ‘admin’ is created during the initial setup. At times you forget the password or want to reset it. This can be accomplished by resetting the password using the following command: To change admin password: sudo openvasmd -- --user=admin -- --new-password=letmein Then logon using admin for the username […]
A World of Vulnerabilities - InfoSec Institute
Every day, we read about cyber-attacks and data breaches, incidents that represent in many cases a disaster for private companies and governments. Technology plays a significant role in our lives; every component that surrounds us runs a piece of software that could be affected by flaws and exploited by those with ill intentions.
'NetTraveler' Cyberespionage Campaign Uncovered
An intrstuing article from Dark Reading: A less sophisticated but long-running cyberspying program out of China aimed at high-profile targets in government, embassies, oil and gas, military contractors, activists, and universities has infected hundreds of targets across 40 nations. The so-called NetTraveler campaign revealed today by Kaspersky Lab comes from a midsize APT group out […]
3 Lessons From Layered Defense's Missed Attacks
a posting from Dark Reading in there Vulnerability Management section: Layering security measures typically protects systems better: Research) by three University of Michigan graduate students in 2008, for example, found that using multiple antivirus engines result in much better protection than using a single program. Yet, recent analysis by NSS Labs highlights that layering security devices rarely catches all […]
How To Stop Making Excuses For Poor Application Security Testing
An posting from Dark reading about How To Stop Making Excuses For Poor Application Security Testing: just as the old carpenter axiom warns to measure twice and cut once, the effort of putting in effective security testing practices earlier in the application development process saves many more headaches later in the application lifecycle. "We want to […]
Twitter testing a two-step security solution: report
An posting from NBC News in there technology section: On Tuesday, Associated Press became the latest national media outlet to have its Twitter account compromised by hackers, leading security experts to question why the short-messaging service has yet to implement two-factor authentication like that offered by Google, Facebook, Microsoft, and Apple. According to Wired, such a security […]