©¶´É¨Ãè¾ÍÊǶԼÆËã»úϵͳ»òÕ߯äËüÍøÂçÉ豸½øÐа²È«Ïà¹ØµÄ¼ì²â£¬ÒÔÕÒ³ö°²È«Òþ»¼ºÍ¿É±»ºÚ¿ÍÀûÓõÄ©¶´¡£ÏÔÈ»£¬Â©¶´É¨ÃèÈí¼þÊǰÑË«Èн££¬ºÚ¿ÍÀûÓÃËüÈëÇÖϵͳ£¬¶øÏµÍ³¹ÜÀíÔ±ÕÆÎÕËüÒÔºóÓÖ¿ÉÒÔÓÐЧµÄ·À·¶ºÚ¿ÍÈëÇÖ¡£Òò´Ë£¬Â©¶´É¨ÃèÊDZ£Ö¤ÏµÍ³ºÍÍøÂ簲ȫ±Ø²»¿ÉÉÙµÄÊֶΣ¬±ØÐë×ÐϸÑо¿ÀûÓá£
©¶´É¨Ãèͨ³£²ÉÓÃÁ½ÖÖ²ßÂÔ£¬µÚÒ»ÖÖÊDZ»¶¯Ê½²ßÂÔ£¬µÚ¶þÖÖÊÇÖ÷¶¯Ê½²ßÂÔ¡£Ëùν±»¶¯Ê½²ßÂÔ¾ÍÊÇ»ùÓÚÖ÷»úÖ®ÉÏ£¬¶ÔϵͳÖв»ºÏÊʵÄÉèÖ㬴àÈõµÄ¿ÚÁîÒÔ¼°ÆäËûͬ°²È«¹æÔòµÖ´¥µÄ¶ÔÏó½øÐмì²é£»¶øÖ÷¶¯Ê½²ßÂÔÊÇ»ùÓÚÍøÂçµÄ£¬Ëüͨ¹ýÖ´ÐÐһЩ½Å±¾ÎļþÄ£Äâ¶Ôϵͳ½øÐй¥»÷µÄÐÐΪ²¢¼Ç¼ϵͳµÄ·´Ó¦£¬´Ó¶ø·¢ÏÖÆäÖеÄ©¶´¡£ÀûÓñ»¶¯Ê½²ßÂÔɨÃè³ÆÎªÏµÍ³°²È«É¨Ã裬ÀûÓÃÖ÷¶¯Ê½²ßÂÔɨÃè³ÆÎªÍøÂ簲ȫɨÃè¡£
¿ìËÙ°²×°Nessus
NessusÊÇÒ»¸ö¹¦ÄÜÇ¿´ó¶øÓÖÒ×ÓÚʹÓõÄÔ¶³Ì°²È«É¨ÃèÆ÷¡£°²È«É¨ÃèÆ÷µÄ¹¦ÄÜÊǶÔÖ¸¶¨ÍøÂç½øÐа²È«¼ì²é£¬ÕÒ³ö¸ÃÍøÂçÊÇ·ñ´æÔÚÓе¼Ö¶ÔÊÖ¹¥»÷µÄ°²È«Â©¶´¡£¸Ãϵͳ±»Éè¼ÆÎªclient/severģʽ£¬·þÎñÆ÷¶Ë¸ºÔð½øÐа²È«¼ì²é£¬¿Í»§¶ËÓÃÀ´ÅäÖùÜÀí·þÎñÆ÷¶Ë¡£ÔÚ·þÎñ¶Ë»¹²ÉÓÃÁËplug-inµÄÌåϵ£¬ÔÊÐíÓû§¼ÓÈëÖ´ÐÐÌØ¶¨¹¦ÄܵIJå¼þ£¬Õâ²å¼þ¿ÉÒÔ½øÐиü¿ìËٺ͸ü¸´Ôӵݲȫ¼ì²é¡£ÔÚNessusÖл¹²ÉÓÃÁËÒ»¸ö¹²ÏíµÄÐÅÏ¢½Ó¿Ú£¬³ÆÖ®ÖªÊ¶¿â£¬ÆäÖб£´æÁËÇ°Ãæ½øÐмì²éµÄ½á¹û¡£¼ì²éµÄ½á¹û¿ÉÒÔHTML¡¢´¿Îı¾¡¢LaTeX£¨Ò»ÖÖÎı¾Îļþ¸ñʽ£©µÈ¼¸ÖÖ¸ñʽ±£´æ¡£
NessusµÄÓŵãÔÚÓÚ£º
1. Æä²ÉÓÃÁË»ùÓÚ¶àÖÖ°²È«Â©¶´µÄɨÃ裬±ÜÃâÁËɨÃè²»ÍêÕûµÄÇé¿ö¡£
2. ËüÊÇÃâ·ÑµÄ£¬±ÈÆðÉÌÒµµÄ°²È«É¨Ã蹤¾ßÈçISS¾ßÓм۸ñÓÅÊÆ¡£
£¨1£©°²×°ºÍÆô¶¯Nessus·þÎñÆ÷¶Ë
ÒÔNessus-4.2.0-es5.i386.rpmNessusʹÓÃΪÀý£¬Ê¹ÓÃÈçϵÄÃüÁî¶ÔÆä½øÐа²×°¼´¿É£º
[root@localhost tmp]# rpm -ivh Nessus-4.2.0-es5.i386.rpm
°²×°³É¹¦ºó£¬»¹ÐèÒªÌí¼ÓÓû§À´¶ÔÆä½øÐвÙ×÷£¬²½ÖèÈçÏÂËùʾ£º
[root@localhost tmp]# /opt/nessus//sbin/nessus-adduser
//Ìí¼ÓÓû§
Login : root
//ÉèÖÃÃÜÂë
Login password :
Login password (again) :
Æô¶¯nessus·Ç³£¼òµ¥£¬Ê¹ÓÃÈçÏÂÃüÁî¼´¿É£º
#/sbin/service nessusd start
£¨2£©°²×°Nessus¿Í»§¶Ë
nessusµÄ¿Í»§¶ËÓÐÁ½¸ö°æ±¾£¬JAVA°æ±¾¼°C°æ±¾£¬JAVA°æ±¾µÄ¿ÉÒÔÔÚ¶à¸öƽ̨ÖÐÔËÐУ¬C°æ±¾µÄÖ§³ÖWindows£¬ÓÐÁËÕâÁ½¸ö¿Í»§¶ËµÄ°æ±¾¾Í¿ÉÒÔÔÚ¾ÖÓòÍøµÄÈκεÄһ̨»úÆ÷ÉϽøÐа²È«¼ì²éÁË¡£ÎªÁËʹÓõļòµ¥Æð¼û£¬ÎÒÃÇÑ¡ÔñÁËÒ»¿îWindowsϵͳϵÄNessus
4¿Í»§¶Ë°æ±¾½øÐа²×°ºÍʹÓã¬Ò²¾ÍÊÇʹÓÃWindows¿Í»§¶ËÀ´¿ØÖÆÔËÐÐÓÚLinuxϵÄNessus·þÎñÆ÷¶ËÀ´¶Ô¾ÖÓòÍøÀïÃæµÄ»úÆ÷½øÐЩ¶´É¨Ã裬ÕâÒ²ÊÇĿǰNessusʹÓõķdz£Á÷ÐеÄÒ»ÖÖ·½Ê½¡£¾ßÌåµÄ°²×°ÈçͬWindowsÏÂÈκÎÒ»¿îÓ¦ÓÃÈí¼þµÄ°²×°·½Ê½Ïàͬ£¬·Ç³£¼òµ¥£¬ÕâÀï²»ÔÙ׸Êö¡£
3¡¢Îå²½Íê³ÉNessusɨÃè
ÏÂÃæÀ´¿´¿´Ê¹ÓÃnessus½øÐÐɨÃèµÄ²½ÖèÒÔ¼°Ð§¹û£¬Ò»°ãÀ´Ëµ£¬Ê¹ÓÃNessus½øÐÐɨÃèÐèÒªÓÐÈçÏÂ5¸ö²½Ö裺
£¨1£©ÉèÖ÷þÎñÆ÷Á¬½Ó£ºÈçͼ1Ëùʾ£¬Ê×ÏÈÐèÒªÉèÖÃNessus¿Í»§¶ËÀ´Á¬½ÓNessus·þÎñÆ÷£¬ÔÚͼ1ÖУ¬ÅäÖúÃÏàÓ¦µÄÖ÷»úÃûºÍ¶Ë¿Ú£¬ÒÔ¼°µÇ½ËùÐèҪʹÓõÄÓû§ÃûºÍÃÜÂë¡£

ͼ1 ÉèÖ÷þÎñÆ÷Á¬½Ó
£¨2£©ÉèÖÃIP·¶Î§£ºÈçͼ2Ëùʾ£¬ÉèÖÃΪIP Range¡£µ±È»£¬ÕâÀﻹÓÐÆäËûµÄÑ¡Ïî¿ÉÌṩѡÔñ£¬°üÀ¨Í¼ÖÐËùʾµÄSingle
Host¡¢SubnetµÈ£¬¿ÉÒÔ¸ù¾Ýʵ¼ÊÇé¿öÀ´Ñ¡Ôñ¡£

ͼ2 ÉèÖÃɨÃèµÄIP·¶Î§
£¨3£©µã»÷scan now£¬¿ªÊ¼¶ÔÉ趨·¶Î§½øÐÐɨÃ裺Èçͼ5Ëùʾ¡£

ͼ3 ¿ªÊ¼É¨Ãè
£¨4£©É¨ÃèµÄÕûÌåЧ¹û£ºÈçͼ4Ëùʾ£¬É¨Ãè¸ø³öÁ˶Ô172.31.12.188Õą̂Ö÷»ú£¨Linux²Ù×÷ϵͳ£¬RHEL
5.0°æ±¾£©µÄɨÃè½á¹û£¬¿ÉÒÔºÜÇåÎú¿´³ö²Ù×÷ϵͳµÄ°æ±¾ÒÔ¼°¿ª·ÅµÄ¶Ë¿Ú£¬Í¬Ê±£¬Ò²Äܹ»½«¿ª·ÅµÄ¶Ë¿ÚÏêϸÐÅÏ¢ÁгöÀ´¡£

ͼ4 ɨÃèµÄÕûÌå½á¹û
£¨5£©²é¿´¾ßÌåµÄ©¶´ÐÅÏ¢£ºÈçͼ5Ëùʾ£¬Èç¹ûÏë²é¿´¾ßÌåµÄ©¶´ÐÅÏ¢±¨¸æÒÔ¼°Â©¶´µÈ¼¶µÈÏêϸÐÅϢʱ£¬¿ÉÒԵ㿪ͼÖÐËùʾµÄ¶ÔÓ¦¿ª·Å¶Ë¿ÚÐÅÏ¢£¬²¢Õë¶Ô¾ßÌåÐÅÏ¢²ÉÈ¡ÏàÓ¦µÄ´ëÊ©À´¶Ô¸Ã©¶´½øÐÐÐÞ²¹µÈ²Ù×÷¡£

ͼ5 ¾ßÌåµÄ©¶´ÐÅÏ¢ |