SARA is built to support the
large-scale enterprise model that contains more than 25,000 nodes and
is approved for operation in the SANS Top 10 and Top 20 environments.
Remember that all commands in Linux are case sensitive.
Procedure: Compile, install, execute against target, and review the results.
From the directory containing the compressed files, type tar ??“zxvf sara-
6.0.7b.tgz.
The files will uncompress into a new directory named sara-6.0.7b.
Change to the new directory by typing cd sara-6.0.7b and pressing Enter.
The SARA application must be configured for the specific machine it is on.
This is done by typing ./configure.
Vulnerability Scanning 403
SARA will now configure to the specific machine it is on.
The next step is to create the SARA file by typing:
./make
404 Practical Hacking Techniques and Countermeasures
The SARA application will now be created.
To execute the SARA application type:
./sara
Vulnerability Scanning 405
The SARA application will start in Mozilla.
On the left side of the screen click on Target selection.
406 Practical Hacking Techniques and Countermeasures
For the Primary Target Selection enter the target hostname or IP address.
In this example the target IP address is 172.16.1.46.
For the Scanning level selection, select Extreme. Click the Start the scan
button.
SARA will initialize the scan against the target.
Start the scan
Vulnerability Scanning 407
In the status bar on the lower left of the screen you may receive a Stalled
warning.
Pages:
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155