ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    openvas test results

    IT Discussion
    10
    34
    2.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • momurdaM
      momurda
      last edited by momurda

      IIS 8 on Server 2012.
      I suppose it is possible that even at 80% this is a false positive detection.
      Windows update screen
      0_1513881247443_4575deac-8dae-478f-9b77-78590231e488-image.png
      The optional update is for SilverLight

      travisdh1T 1 Reply Last reply Reply Quote 0
      • travisdh1T
        travisdh1 @momurda
        last edited by travisdh1

        @momurda said in openvas test results:

        IIS 8 on Server 2012.
        I suppose it is possible that even at 80% this is a false positive detection.
        Windows update screen
        0_1513881247443_4575deac-8dae-478f-9b77-78590231e488-image.png
        The optional update is for SilverLight

        It could be that Microsoft hasn't released those updates for 2012. Isn't 2012 only covered under extended support now?

        Edit: Answering my own question, normal support for 2012/2012R2 ends in 2018.

        Accordingly, you should be able to apply those updates.

        1 Reply Last reply Reply Quote 1
        • momurdaM
          momurda
          last edited by

          I think they are applied and that openvas is being dumb.

          1 Reply Last reply Reply Quote 1
          • momurdaM
            momurda
            last edited by

            The updates that openvas says are missing are actually installed.
            0_1513959881520_4b4ef504-8599-4e4a-8910-59454a869a4d-image.png
            and
            0_1513959902246_3adff0eb-2190-44f6-84a1-d142bf65e3c2-image.png

            1 Reply Last reply Reply Quote 0
            • ObsolesceO
              Obsolesce
              last edited by

              Does anyone still have an OpenVAS scanner going?

              1 Reply Last reply Reply Quote 0
              • momurdaM
                momurda
                last edited by

                I use mine every couple weeks. It is off right now

                ObsolesceO 1 Reply Last reply Reply Quote 0
                • ObsolesceO
                  Obsolesce @momurda
                  last edited by Obsolesce

                  @momurda said in openvas test results:

                  I use mine every couple weeks. It is off right now

                  I'm asking because I don't have anything set up, and was curious if anyone could do a non-intrusive vunlerability scan against my VPSs, one on GCP and one on turnkeyinternet?

                  I'd like to compare the results...

                  1 Reply Last reply Reply Quote 0
                  • momurdaM
                    momurda
                    last edited by

                    If you give me ip and port i can setup and run a scan. It is incredibly slow here this week. I shouldnt even be in the office.

                    ObsolesceO 1 Reply Last reply Reply Quote 0
                    • ObsolesceO
                      Obsolesce @momurda
                      last edited by

                      @momurda said in openvas test results:

                      If you give me ip and port i can setup and run a scan. It is incredibly slow here this week. I shouldnt even be in the office.

                      tgserv.timothygruber.com

                      mc.timothygruber.com

                      See what comes up just from that info.

                      1 Reply Last reply Reply Quote 0
                      • momurdaM
                        momurda
                        last edited by momurda

                        Ok scanning now
                        edit: openvas tripped the IPS and got banned from all net activity for 20 minutes while scanning these sites, so it was working.

                        ObsolesceO 1 Reply Last reply Reply Quote 0
                        • ObsolesceO
                          Obsolesce @momurda
                          last edited by

                          @momurda said in openvas test results:

                          Ok scanning now
                          edit: openvas tripped the IPS and got banned from all net activity for 20 minutes while scanning these sites, so it was working.

                          Okay, I will see about turning it off later today. I'll let you know. Thanks for trying.

                          momurdaM 1 Reply Last reply Reply Quote 0
                          • momurdaM
                            momurda @Obsolesce
                            last edited by

                            @tim_g I meant my IPS. It has resumed scanning after the 20 minute ban.

                            ObsolesceO 1 Reply Last reply Reply Quote 0
                            • ObsolesceO
                              Obsolesce @momurda
                              last edited by

                              @momurda said in openvas test results:

                              @tim_g I meant my IPS. It has resumed scanning after the 20 minute ban.

                              Ah I see

                              1 Reply Last reply Reply Quote 0
                              • momurdaM
                                momurda
                                last edited by

                                These scans take about 50x as long over the internet as internally, even over a Gb WAN connection.
                                Do you want me to post results here as screenies or do you want a pdf pm to you?

                                IRJI ObsolesceO 2 Replies Last reply Reply Quote 0
                                • IRJI
                                  IRJ @momurda
                                  last edited by

                                  @momurda said in openvas test results:

                                  These scans take about 50x as long over the internet as internally, even over a Gb WAN connection.
                                  Do you want me to post results here as screenies or do you want a pdf pm to you?

                                  Don't publicly post them!

                                  1 Reply Last reply Reply Quote 1
                                  • ObsolesceO
                                    Obsolesce @momurda
                                    last edited by

                                    @momurda said in openvas test results:

                                    These scans take about 50x as long over the internet as internally, even over a Gb WAN connection.
                                    Do you want me to post results here as screenies or do you want a pdf pm to you?

                                    It depends on the results.

                                    If it's just saying "hey these are the open ports", public is fine. I can already tell you SSH, Cockpit, Salt, and MC ports are open on the one VPS... as they should be.

                                    If it gets deep into things that are a real vulnerability, that are fixable, then I'd rather keep private until I can fix them... then I or you can post them publicly.

                                    1 Reply Last reply Reply Quote 0
                                    • momurdaM
                                      momurda
                                      last edited by

                                      Ok you can decide, ill send them when done. One is at 98%, the other 16%.
                                      So far i have had to lower QoD to 0 and include Log and FP to get anything to show on results page.

                                      1 Reply Last reply Reply Quote 0
                                      • 1
                                      • 2
                                      • 2 / 2
                                      • First post
                                        Last post