By scrolling further down the report, the details of the scan will be revealed,
along with the details of how to correct the vulnerabilities.
Vulnerability Scanning 467
At the end of the report a Glossary is conveniently available for review.
*Note: Shadow Security Scanner is an excellent vulnerability scanner, which is comparable
to the more expensive scanners like Retina. At the time of this writing
the cost for the full version of Shadow is $372.70.
468 Practical Hacking Techniques and Countermeasures
Lab 71: Internet Vulnerability Scanner
Assessment of Target Security: Cerberus
Prerequisites: None
Countermeasures: ACLs, Bastion Computer, host-based firewalls
Description: Cerberus is an Internet scanner that looks for vulnerabilities
in Web, FTP, SMTP, POP3, NT, NetBIOS, MS SQL, and others. The
scanner runs about 300 scans and generates HTML reports.
Procedure: Start, define the parameters, select the target, and initiate the
scan.
Double-click on the cis icon to start the Cerberus scanner.
The Cerberus scanner starts.
Vulnerability Scanning 469
Click the button on the toolbar. The Select Scan Modules screen will
appear.
In this example, All was selected. Click OK.
M
470 Practical Hacking Techniques and Countermeasures
Click on the house icon on the toolbar. The Choose host to scan
screen will appear.
Enter the IP address of the target. Click Select.
Vulnerability Scanning 471
Click on the button on the toolbar.
Pages:
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170