Re: [Openvas-discuss] Openvas 7 on Centos7

2014-10-16 Thread Dustin Demuth
Am 16.10.2014 um 03:06 schrieb Sec DevOps: Hi Has anyone been able to get Openvas7 running on Centos7? Yes, everything but the PDF-Generation worked out of the box on my CentOS 7 machine, If I understood it right, the Administrator was merged into the manager. This might explain why Step 3

Re: [Openvas-discuss] Openvas 7 on Centos7

2014-10-16 Thread Barkley, Joey
Try running the check tool with the --v7 option and it should remove that failure as it won’t check for the Administrator. Joey On Oct 16, 2014, at 7:29 AM, Dustin Demuth m...@demuth.mobimailto:m...@demuth.mobi wrote: Am 16.10.2014 um 03:06 schrieb Sec DevOps: Hi Has anyone been able to get

Re: [Openvas-discuss] Observers and Overrides

2014-10-16 Thread Helmut Koers
I am trying with OpenVAS-7 now, but a user that has been set up as observer, does not see any notes or overrides that have been created. In addition to that I can not add or remove any users as observer to tasks like I was able to in OpenVAS-6. Did that change somehow?

Re: [Openvas-discuss] Observers and Overrides

2014-10-16 Thread Jack Harvey
In my not huge amount of v7 experience, observers have to be added to tasks via omp/api (apologizies if not said correctly). I did it like this...but observers are limited in what they can do... omp -iX modify_task task_id='task-id-is-in-these-single-quotes'

Re: [Openvas-discuss] Scanning target behind firewall

2014-10-16 Thread Mauro Risonho de Paula Assumpção
Hi. OpenVAS use nmap starting scannings. Clone/Fork plugins nmap - firewall bypass Reference NMAP: http://nmap.org/nsedoc/scripts/firewall-bypass.html http://pentestlab.wordpress.com/2012/04/02/nmap-techniques-for-avoiding-firewalls/

[Openvas-discuss] Poodle - SSL version check

2014-10-16 Thread clems
Hello, I would like to create a scan for all my server (4000 servers) to check only port 443 and check the SSL version and Cipher version. The goal is to ensure that all servers (new and old) have the correct SSL version and Cipher version. What kind of scan configuration should i use?

Re: [Openvas-discuss] Poodle - SSL version check

2014-10-16 Thread Chris
Hi, there is currently no NVT available so the only possibility i'm seeing is to scan all systems with the Check SSL Weak Ciphers and Supported Ciphers from the General family and check the output of this plugin if the systems are supporting SSLv3 ciphers.

Re: [Openvas-discuss] Scanning target behind firewall

2014-10-16 Thread Chris
Hi, as an alternative you could use a tool like sshuttle over an SSH jumphost on your OpenVAS system to make the internal network available to this system. ___ Openvas-discuss mailing list Openvas-discuss@wald.intevation.org

Re: [Openvas-discuss] Poodle - SSL version check

2014-10-16 Thread clems
Thanks Chris, So if I understand I must use nmap NVT to check if port 443 is open and use the Check SSL Weak Ciphers and Supported Ciphers Is it correct? Regards, On Thu, Oct 16, 2014 at 5:46 PM, Chris fisch@gmx.de wrote: Hi, there is currently no NVT available so the only possibility

Re: [Openvas-discuss] Scanning target behind firewall

2014-10-16 Thread Eero Volotinen
2014-10-16 18:14 GMT+03:00 Nick darknovan...@gmail.com: Hello, I am a new user of OpenVAS. So far I have successfully used it to do an external vulnerability test of my server. However, our firewall blocks many of the ports (as it should). How about using IPSec ? -- Eero

Re: [Openvas-discuss] Scanning target behind firewall

2014-10-16 Thread Brandon Perry
Or OpenVPN On Thu, Oct 16, 2014 at 1:21 PM, Eero Volotinen eero.voloti...@iki.fi wrote: 2014-10-16 18:14 GMT+03:00 Nick darknovan...@gmail.com: Hello, I am a new user of OpenVAS. So far I have successfully used it to do an external vulnerability test of my server. However, our firewall

Re: [Openvas-discuss] Credentialed Scans - Not Working

2014-10-16 Thread Jan-Oliver Wagner
Am Montag, 6. Oktober 2014, 16:56:27 schrieb Turner, Jonas: Well, it appears to be working now. I haven't done anything different except to lower the amount of IP's I scanned. I am getting the SMB log in now and can now see Adobe and Java vulnerabilities and windows. I can not imagine any

Re: [Openvas-discuss] Credentialed Scans - Not Working

2014-10-16 Thread Turner, Jonas
I, believe, it's working now. Don't ask me why it started to work. Will keep everyone updated. -Original Message- From: Openvas-discuss [mailto:openvas-discuss-boun...@wald.intevation.org] On Behalf Of Jan-Oliver Wagner Sent: Thursday, October 16, 2014 4:20 PM To:

Re: [Openvas-discuss] arachni, etc.

2014-10-16 Thread Jan-Oliver Wagner
Am Mittwoch, 1. Oktober 2014, 15:51:43 schrieb Geoff Galitz: FWIW, openvas as a wrapper around other established tools/projects is half the point of openvas (to me anyways). It would be great if the project somehow identifies what needs to be done to get these to work again. There's no real

Re: [Openvas-discuss] Openvas 7 on Centos7

2014-10-16 Thread Sec DevOps
Hi Joey, Thank you for taking the time to respond. Your suggestion to run the check tool with the --v7 flag is exactly what I did, that's what was so weird about it.: [root@Neb ~]# /usr/bin/openvas-check-setup --v7 openvas-check-setup 2.2.1 Test completeness and readiness of OpenVAS-7 Step

[Openvas-discuss] Fwd: Openvas 7 on Centos7

2014-10-16 Thread Sec DevOps
Thank you Dustin - have you been able to update your NVT and SCAP feeds successfully? I also noticed the absence of PDF reports and was wondering if it wasn't a symptom of a broken installation. What's really odd is that scans I'm running against servers with known security issues are