Current Issue


Table of contents

CD-ROM

Sys Admin and The Perl Journal CD-ROM version 12.0

Version 12.0 delivers every issue of Sys Admin from 1992 through 2006 and every
issue of The Perl Journal from 1996-2002 in one convenient CD-ROM!

Order now!

Sys Admin Magazine > Archives > 2001 > April 2001

Using Freeware Vulnerability Scanners

Gary Bahadur and Yen-ming Chen

Vulnerabilty scanners are all the rage in the security industry. Some scan externally for weaknesses, and others perform host-based scanning and everything in between. If you have ever used Cybercop (http://www.nai.com) or ISS Safesuite (http://www.iss.net), you know these products can be expensive. There are alternatives that do not cost a lot of money, but how do you know which ones are best and how do you find them?

In this article, we will briefly describe the methodology of using vulnerability scanners and give some freeware options for the security-minded administrator. There are a number of pros and cons to using freeware versus commercial products, and the validity of even performing security testing. The three products discussed in this article are Nessus (http://www.nessus.org), Narrow Security Scanner (http://www.packetstorm.securify.com/UNIX/scanners/nss/), and SAINT (http://www.wwdsi.com/saint/). The usage of these products is placed in the context of performing a security review and these are just a sample of available products.

To secure a site, a logical progression must be followed. Downloading a scanner and executing it against your network is only part of the solution. For a comprehensive security review, the following steps must be taken:

  1. Footprint Analysis — Scan the environment for operating systems, applications, and services running.
  2. Vulnerability Analysis — Determine potential vulnerabilities in services, applications, and operating systems.



MarketPlace

Build IT Knowledge with Current & Trusted Content
Helps Employees Develop & Hone New Technical Programming Skills. Sign Up & Get Full Access.

Villanova University Six Sigma & IT Certificate Programs
100% Online programs in Six Sigma, IS Security, CISSP Prep, Business Analysis, Proj. Mgmt. and more!

Learn Embedded Linux, $349
Hands-on kit teaches fundamentals of embedded Linux development on real target hardware. ARM9 SBC.

Workflow Enabled Help Desk & IT Service Management
Automate service desk activities and integrate processes across IT. Learn more here.

Wanna see your ad here?