Vulnerability Scanning 461
Be patient with Shadow Security Scanner, first-time users tend to think the
process is finished prior to the audit testing completing, Shadow is not complete
until you see the Scan complete (100%) message in the status bar.
462 Practical Hacking Techniques and Countermeasures
By clicking on one of the vulnerabilities found by Shadow, you display
the details of the vulnerability in the lower section of the application, among
them:
The description
The risk level
The solution
The community name (if applicable)
Description of the target system
Target hostname
Amount of RAM on the target
IP address
Once the scan has completed, click the Report button.
Vulnerability Scanning 463
As this is the first report run, click the Add report button.
Enter a Name for the report and select the report style. Click OK.
464 Practical Hacking Techniques and Countermeasures
Accept the default Selections to view the entire report. Click OK.
The last step to creating the report is to give the report a filename. Once
you have provided a filename, click Save. (Be sure you know where you are
saving the file.)
Vulnerability Scanning 465
Locate the saved report file and double-click to open it.
The report will open in a Web browser. The initial glance displays a
Confidential Information warning.
466 Practical Hacking Techniques and Countermeasures
Continue to scroll down the report to view the Executive Summary
portion of the report.
Pages:
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169