Re: [Openvas-discuss] OpenVAS Metasploit

2014-06-21 Thread Brandon Perry
must use the console. On Fri, Jun 20, 2014 at 2:29 PM, W Scott Lockwood III sc...@guppylog.com wrote: Awesome! Is that included in the commercial version as well? On Fri, 2014-06-20 at 14:25 -0500, Brandon Perry wrote: There is an openvas plugin. In msfconsole, type

Re: [Openvas-discuss] OpenVAS v7 Not Working

2014-07-09 Thread Brandon Perry
And you clearly ran it, my bad. :) Maybe run --update after ensuring all of the openvas processes are stopped. And then --migrate for thoroughness. Sent from a computer On Jul 9, 2014, at 9:44 AM, Robert Debs rdeb...@gmail.com wrote: We are a networking company that uses OpenVAS to

Re: [Openvas-discuss] updating via yum...

2014-07-09 Thread Brandon Perry
Hmm, any reason you are on i686? Maybe the build of the lib you need isn't available for i686. On Wed, Jul 9, 2014 at 1:10 PM, Jack Harvey ja...@synnex.com wrote: From the Quick-Setup and Quick-Start page, following the steps for CentOS 6 install, after adding the Atomicorp repository when

Re: [Openvas-discuss] next steps for development in OpenVAS

2014-07-21 Thread Brandon Perry
I would grok the following: http://www.openvas.org/protocol-doc.html The OMP protocol will be what you use for the most part, I think, for instrumentation and automation. On Mon, Jul 21, 2014 at 1:12 PM, Pham, Tam T tam.t.p...@hp.com wrote: Everyone: I have done some digging into Openvas

Re: [Openvas-discuss] OpenVas7 Manager to Scanner error

2014-07-22 Thread Brandon Perry
What happens when you try to start a scan with raw OMP? start_task / iirc On Tue, Jul 22, 2014 at 4:54 PM, Brian Diehl bdi...@christensenfarms.com wrote: Hello, I just completed an upgrade of OpenVas from version 6 to version 7. I am running 64bit Ubuntu 13.10 (Saucy). GSAD works great.

Re: [Openvas-discuss] OpenVas7 Manager to Scanner error

2014-07-22 Thread Brandon Perry
*From:* Brandon Perry [mailto:bperry.volat...@gmail.com] *Sent:* Tuesday, July 22, 2014 5:06 PM *To:* Brian Diehl *Cc:* openvas-discuss@wald.intevation.org *Subject:* Re: [Openvas-discuss] OpenVas7 Manager to Scanner error What happens when you try to start a scan with raw OMP? start_task

Re: [Openvas-discuss] Manager error

2014-07-23 Thread Brandon Perry
If authentication were an issue, then the previous omp command you ran wouldn't have worked. I don't recall you posting the result of listing the current tasks via omp after attempting to start a task. Did this not work? On Wed, Jul 23, 2014 at 10:33 AM, Brian Diehl bdi...@christensenfarms.com

Re: [Openvas-discuss] Manager error

2014-07-23 Thread Brandon Perry
I think you can also pass -vvv to omp to get super verbose output. On Wed, Jul 23, 2014 at 10:49 AM, Brandon Perry bperry.volat...@gmail.com wrote: If authentication were an issue, then the previous omp command you ran wouldn't have worked. I don't recall you posting the result of listing

Re: [Openvas-discuss] SMTP problems not discovered

2014-07-25 Thread Brandon Perry
Does it respond to ICMP pings? OpenVAS may be skipping it due to no response from a ping. On Fri, Jul 25, 2014 at 10:35 AM, deepak deepak...@gmail.com wrote: Hi, I have a target host that runs an SMTP server on port 25. I have the target configured with All IANA assigned TCP and UDP

Re: [Openvas-discuss] SMTP problems not discovered

2014-07-25 Thread Brandon Perry
it was left with the default Scan Config Default. Thanks, Deepak On Fri, Jul 25, 2014 at 10:39 AM, Brandon Perry bperry.volat...@gmail.com wrote: Does it respond to ICMP pings? OpenVAS may be skipping it due to no response from a ping. On Fri, Jul 25, 2014 at 10:35 AM, deepak deepak

Re: [Openvas-discuss] high load in master-slave mode

2014-07-28 Thread Brandon Perry
Is there another process, such as nmap, or dirb running as well? Maybe it is hung up on a NASL script that hadn't finished... On Mon, Jul 28, 2014 at 5:59 AM, red0queen red0qu...@red-net.info wrote: Hello, I was trying the master slave mode and I have a strange behavior : when the scan

Re: [Openvas-discuss] don't ping...

2014-07-29 Thread Brandon Perry
Not sure exactly how you are configuring the scan config, but someone recently had this same issue: https://www.mail-archive.com/openvas-discuss@wald.intevation.org/msg06133.html On Tue, Jul 29, 2014 at 11:55 AM, Jack Harvey ja...@synnex.com wrote: By way of further explanation of my issue:

Re: [Openvas-discuss] don't ping...

2014-07-29 Thread Brandon Perry
” parameter for the host? Jack Harvey CISSP Synnex Corporation 864-349-4939 *From:* Brandon Perry [mailto:bperry.volat...@gmail.com] *Sent:* Tuesday, July 29, 2014 1:00 PM *To:* Jack Harvey *Cc:* openvas-discuss@wald.intevation.org *Subject:* Re: [Openvas-discuss] don't ping

Re: [Openvas-discuss] Time Zone

2014-07-29 Thread Brandon Perry
I thought it used the system time, but I am willing to eat my words on this. Setting the system time correctly still yields an incorrect time in openvas reports/schedules? On Tue, Jul 29, 2014 at 12:10 PM, luciano fain lucianof...@hotmail.com wrote: Hi all, where can i change the openvas time

Re: [Openvas-discuss] GSAD on Openvas 7 doesn't take credentials, hosts or tasks

2014-08-13 Thread Brandon Perry
Can you create targets with raw OMP? On Wed, Aug 13, 2014 at 2:45 PM, Tom Powers t...@sound-solutions.biz wrote: Sound Solutions, Inc. 8400 Highland Dr. Wausau, WI 54401 Tel: 715-842-7665 Fax: 715-842-7620 Hello Openvas.. I have a fresh build of Open Vas 7 running on Ubuntu

Re: [Openvas-discuss] GSAD on Openvas 7 doesn't take credentials, hosts or tasks

2014-08-13 Thread Brandon Perry
Highland Dr. Wausau, WI 54401 Tel: 715-842-7665 Fax: 715-842-7620 Not sure…how does one try that in the OpenVas 7? I made the jump from 3 to 7 here…so I’m sure I’ve missed some of the commands along the way All insight is appreciated Thanks TP *From:* Brandon Perry

Re: [Openvas-discuss] 7 task in paralell

2014-08-13 Thread Brandon Perry
TBH it would actually be awesome if SQLite were supported out of the box, but you could configure OpenVAS to use PostgreSQL. Would resolve this issue, and would allow you to reduce IO during scans on the engine, and put it on a dedicated database. On Wed, Aug 13, 2014 at 6:26 PM, luciano fain

Re: [Openvas-discuss] GSAD on Openvas 7 doesn't take credentials, hosts or tasks

2014-08-14 Thread Brandon Perry
@BFN-Securscan7:~# *From:* Brandon Perry [mailto:bperry.volat...@gmail.com] *Sent:* Wednesday, August 13, 2014 3:05 PM *To:* Tom Powers *Cc:* openvas-discuss@wald.intevation.org *Subject:* Re: [Openvas-discuss] GSAD on Openvas 7 doesn't take credentials, hosts or tasks You can use

Re: [Openvas-discuss] GSAD on Openvas 7 doesn't take credentials, hosts or tasks

2014-08-14 Thread Brandon Perry
This will basically tell you whether the manager or GSA is the issue. On Wed, Aug 13, 2014 at 3:26 PM, Brandon Perry bperry.volat...@gmail.com wrote: Yep, you will need to build a small XML snippet to create a target, then you can use --get-targets to ensure it was created: omp --xml

Re: [Openvas-discuss] GSAD on Openvas 7 doesn't take credentials, hosts or tasks

2014-08-14 Thread Brandon Perry
the only one I have setup) and it said : Failed to Acquire socket. *From:* Brandon Perry [mailto:bperry.volat...@gmail.com] *Sent:* Wednesday, August 13, 2014 3:27 PM *To:* Tom Powers *Cc:* openvas-discuss@wald.intevation.org *Subject:* Re: [Openvas-discuss] GSAD on Openvas 7 doesn't take

Re: [Openvas-discuss] GSAD on Openvas 7 doesn't take credentials, hosts or tasks

2014-08-14 Thread Brandon Perry
have been the OMP commands because I restarted this thing a truck load of times trying to see if it clears up. Thanks for all your help TP *From:* Brandon Perry [mailto:bperry.volat...@gmail.com] *Sent:* Wednesday, August 13, 2014 3:41 PM *To:* Tom Powers *Cc:* openvas-discuss

Re: [Openvas-discuss] GSAD on Openvas 7 doesn't take credentials, hosts or tasks

2014-08-14 Thread Brandon Perry
as you asked that. They all came back up fine…and it now says “Failed to authenticate” Do I need a username and password in this XML string to correctly Identify myself? TP *From:* Brandon Perry [mailto:bperry.volat...@gmail.com] *Sent:* Wednesday, August 13, 2014 3:36 PM *To:* Tom

Re: [Openvas-discuss] GSAD on Openvas 7 doesn't take credentials, hosts or tasks

2014-08-15 Thread Brandon Perry
can create targets just fine…but Credentials…are a no go….it sits and hangs on the credentials Would I use the create_lsc_credentials manually in omp to check this? TP *From:* Brandon Perry [mailto:bperry.volat...@gmail.com] *Sent:* Wednesday, August 13, 2014 3:48 PM *To:* Tom Powers

Re: [Openvas-discuss] GSAD on Openvas 7 doesn't take credentials, hosts or tasks

2014-08-15 Thread Brandon Perry
there. And yes…right now the admin user is admin with a password of password. The Credential I am trying to make is an smb login to a windows domain Ideas? TP *From:* Brandon Perry [mailto:bperry.volat...@gmail.com] *Sent:* Thursday, August 14, 2014 1:34 PM *To:* Tom Powers *Cc:* openvas

Re: [Openvas-discuss] 7 task in paralell

2014-08-15 Thread Brandon Perry
Yes, I didn't mean it SQLite wasn't supported out of the box, I meant it would be awesome if it were supported out of the box, with an option to use pgsql. :) On Fri, Aug 15, 2014 at 2:17 AM, Jan-Oliver Wagner jan-oliver.wag...@greenbone.net wrote: On Donnerstag, 14. August 2014, Brandon

Re: [Openvas-discuss] Openvas metasploit msfconsole

2014-08-23 Thread Brandon Perry
You should open up a bug with this on the metasploit-framework github issue tracker. You can also cc @brandonprry on it. On Fri, Aug 22, 2014 at 6:13 AM, Jack Daniels jackdaniels7...@googlemail.com wrote: Hello all. This might be a silly mistake, but I am stuck, please help me out. I am

Re: [Openvas-discuss] Credentialed Scans - Not Working

2014-09-09 Thread Brandon Perry
Did you install openvas from the Atomic repos? What version of openvas are you using? Do credentialed scans for SSH on linux boxen work? Is it just SMB that is not behaving as you expect? On Tue, Sep 9, 2014 at 10:13 AM, Turner, Jonas jotur...@hcr-manorcare.com wrote: I have tried it several

Re: [Openvas-discuss] arachni, etc.

2014-09-30 Thread Brandon Perry
believe this is not currently the case with them. Jack Harvey RHCE CISSP Synnex Corporation 864-349-4939 *From:* Brandon Perry [mailto:bperry.volat...@gmail.com] *Sent:* Tuesday, September 30, 2014 3:59 PM *To:* Jack Harvey *Cc:* Reindl Harald; openvas-discuss@wald.intevation.org

Re: [Openvas-discuss] arachni, etc.

2014-10-01 Thread Brandon Perry
I agree that utilities like dirb and nikto are useful as plugins for OpenVAS since these are generally applicable to any web server. Arachni and wapiti require such application specific configurations that I wouldn't want to give people using OpenVAS the idea that running arachni through OpenVAS

Re: [Openvas-discuss] arachni, etc.

2014-10-01 Thread Brandon Perry
I will also admit however that I do not use OpenVAS as a pen-tester, as others might. My use cases could obviously differ from those of another OpenVAS user. :) On Wed, Oct 1, 2014 at 9:52 AM, Brandon Perry bperry.volat...@gmail.com wrote: I agree that utilities like dirb and nikto are useful

Re: [Openvas-discuss] arachni, etc.

2014-10-01 Thread Brandon Perry
01.10.2014 um 16:52 schrieb Brandon Perry: I agree that utilities like dirb and nikto are useful as plugins for OpenVAS since these are generally applicable to any web server. Arachni and wapiti require such application specific configurations that I wouldn't want to give people using

Re: [Openvas-discuss] Parsing OpenVAS XML from Dradis

2014-10-06 Thread Brandon Perry
TBH there should be a published XSD of the XML report so that programs can validate the reports they are getting against them, and so that multiple versions of the reports can be supported. On Mon, Oct 6, 2014 at 4:31 AM, Matthew Mundell matthew.mund...@greenbone.net wrote: I don't think I

Re: [Openvas-discuss] OpenVAS OMP CLI Examples :Comprehensive Configuration Guide/Tutorial?

2014-10-13 Thread Brandon Perry
All of the omp protocol documentation lives here; http://www.openvas.org/protocol-doc.html On Mon, Oct 13, 2014 at 11:37 AM, Traiano Welcome traiano.welc...@alshaya.com wrote: Hi Is there a through guide or tutorial on how to configure and use OMP via the cli ? The scattered

Re: [Openvas-discuss] Scanning target behind firewall

2014-10-16 Thread Brandon Perry
Or OpenVPN On Thu, Oct 16, 2014 at 1:21 PM, Eero Volotinen eero.voloti...@iki.fi wrote: 2014-10-16 18:14 GMT+03:00 Nick darknovan...@gmail.com: Hello, I am a new user of OpenVAS. So far I have successfully used it to do an external vulnerability test of my server. However, our firewall

Re: [Openvas-discuss] OpenVas Disk Requirements

2014-10-28 Thread Brandon Perry
Technically /32 is 'subnet'... How large are your subnets? /16? /22? /24? On Tue, Oct 28, 2014 at 8:42 AM, Turner, Jonas jotur...@hcr-manorcare.com wrote: I am looking to scan over 650 subnets. How much disk space do you recommend? I am not sure on the data retention at this time, but I

Re: [Openvas-discuss] OpenVas Disk Requirements

2014-10-28 Thread Brandon Perry
I think 250gb for 30 days of data retention is just fine. You might use half of it to be honest. On Tue, Oct 28, 2014 at 11:38 AM, William Scott Lockwood III sc...@guppylog.com wrote: On Tue, Oct 28, 2014 at 10:26 AM, Turner, Jonas jotur...@hcr-manorcare.com wrote: Correct. My bad. /24. I

Re: [Openvas-discuss] nmap custom folder

2014-11-08 Thread Brandon Perry
Just add your custom folder to the beginning of your PATH On Sat, Nov 8, 2014 at 10:21 AM, paky...@libero.it paky...@libero.it wrote: Hi, i have installed openvas and it work properly. I want to install nmap on my machine, in this way when i start the scan, openvas invoke also nmap. I have

Re: [Openvas-discuss] web vulnerability detection

2014-11-18 Thread Brandon Perry
What's wrong with the apache license? Arachni is awesome. It is modular, flexible, and incredibly automatable. You can also perform distributed scans with specific nodes running specific subsets of tests. On Tue, Nov 18, 2014 at 8:24 AM, Winfried Neessen nees...@cleverbridge.com wrote: Hi,

Re: [Openvas-discuss] RSYNC Alternative for scapdata-sync

2015-02-19 Thread Brandon Perry
You could set up a local rsync server and mirror the scap data internally, updating the SCAP mirror over HTTP. On Thu, Feb 19, 2015 at 9:10 AM, Alter Ego alterego...@gmail.com wrote: I am wondering if there is any option or solution to being able to do a SYNC of scapdata without the use of

Re: [Openvas-discuss] RSYNC Alternative for scapdata-sync

2015-02-19 Thread Brandon Perry
While slightly off topic, it may not be his need in and of itself that is increasing risk. The problem could very well be, if you open this thing for this user, while legitimate, now you have other users saying Well you opened this up for him! Why not open this up for me?. It is easier for the

Re: [Openvas-discuss] Handling CentOS False Positives

2015-02-05 Thread Brandon Perry
Are these authenticated or unauthenticated scans? On Thu, Feb 5, 2015 at 12:22 PM, Kevin T. Neely ktne...@astroturfgarden.com wrote: Michael, Pretty much any check that uses presented banner information on RedHat or CentOS will trigger this. The one I was specifically looking at yesterday

Re: [Openvas-discuss] Handling CentOS False Positives

2015-02-05 Thread Brandon Perry
, 2015 at 10:24 AM, Brandon Perry bperry.volat...@gmail.com wrote: Are these authenticated or unauthenticated scans? On Thu, Feb 5, 2015 at 12:22 PM, Kevin T. Neely ktne...@astroturfgarden.com wrote: Michael, Pretty much any check that uses presented banner information on RedHat or CentOS

Re: [Openvas-discuss] W3af with OpenVAS 8 beta version

2015-01-05 Thread Brandon Perry
Ah, my mistake. Will need to play with this, didn't realize there were new mechanisms for this. Sent from a phone On Jan 5, 2015, at 09:49, Michael Meyer michael.me...@greenbone.net wrote: *** Brandon Perry wrote: Really shouldn't be doing w3af/arachni/etc scans through OpenVAS to begin

Re: [Openvas-discuss] OpenVAS NVT feed syncing, but new plugins not loading

2015-03-20 Thread Brandon Perry
Have you rebuilt and restarted openvas manager? On Fri, Mar 20, 2015 at 5:29 PM, Russell Jones russell-l...@jonesmail.me wrote: Hi all, I was checking to see if OpenVAS had a FREAK test yet and I see that it does (http://plugins.openvas.org/nasl.php?oid=805142). When I check my NVT feed I

Re: [Openvas-discuss] installing openvas 8 from source on CentOS 7

2015-04-27 Thread Brandon Perry
Within the error message printed is: ERROR: No users found. You need to create at least one user to log in. It is recommended to have at least one user with role Admin. FIX: create a user by running 'openvasmd --create-user=name --role=Admin openvasmd --user=name

Re: [Openvas-discuss] Install from Binary Packages on CentOS

2015-05-11 Thread Brandon Perry
That should be OpenVAS 8. Glad to see this thread, have been having the same issue. We may want to add these details to the openvas install binary packages page. EPEL7 isn't there by default. On Mon, May 11, 2015 at 7:56 AM, Brian Chabot bcha...@millennialmedia.com wrote: Yup. I got it working

Re: [Openvas-discuss] Broken WMI dep for OpenVAS from Atomic repo?

2015-05-05 Thread Brandon Perry
error messages to mailinglist? Crystalball is broken.. 5.5.2015 7.24 ip. Brandon Perry bperry.volat...@gmail.com kirjoitti: Hey guys, Attempting to do a fresh install of some openvas servers last night, I am getting a broken dep on wmi from the atomic repos. Anyone else seeing an issue

[Openvas-discuss] Broken WMI dep for OpenVAS from Atomic repo?

2015-05-05 Thread Brandon Perry
Hey guys, Attempting to do a fresh install of some openvas servers last night, I am getting a broken dep on wmi from the atomic repos. Anyone else seeing an issue or would it just be me? Have freshened up my repo defs and caches. Thanks! -- http://volatile-minds.blogspot.com -- blog

Re: [Openvas-discuss] Broken WMI dep for OpenVAS from Atomic repo?

2015-05-05 Thread Brandon Perry
Thanks, just joined, will wait to see if there was a bad push or something. On Tue, May 5, 2015 at 12:18 PM, Michael Meyer michael.me...@greenbone.net wrote: *** Brandon Perry wrote: Attempting to do a fresh install of some openvas servers last night, I am getting a broken dep on wmi from

Re: [Openvas-discuss] Broken WMI dep for OpenVAS from Atomic repo?

2015-05-10 Thread Brandon Perry
Meyer michael.me...@greenbone.net wrote: *** Brandon Perry wrote: Attempting to do a fresh install of some openvas servers last night, I am getting a broken dep on wmi from the atomic repos. If you have this kind of trouble with OpenVAS from atomic repo, an easy way to get help is to just

Re: [Openvas-discuss] Install from Binary Packages on CentOS

2015-05-12 Thread Brandon Perry
and are NOT in the documentation and the last one could be substituted with opening port 9392. I'll have other, more technical questions later... Thank you all for the help so far. Brian On Mon, May 11, 2015 at 11:00 AM, Brandon Perry bperry.volat...@gmail.com wrote: That should

Re: [Openvas-discuss] Install from Binary Packages on CentOS

2015-05-12 Thread Brandon Perry
supposedly not play well with and what are the side-effects/symptoms? On Tue, May 12, 2015 at 8:07 AM, Reindl Harald h.rei...@thelounge.net wrote: Am 12.05.2015 um 15:05 schrieb Brandon Perry: Why should he do that? That seems a bit overkill? because OpenVAS should *always* run on a dedicated

Re: [Openvas-discuss] Install from Binary Packages on CentOS

2015-05-12 Thread Brandon Perry
On Tue, May 12, 2015 at 8:24 AM, Eero Volotinen eero.voloti...@iki.fi wrote: OpenVAS will not work with selinux correctly. I want to know what this means. I have run hundreds of OpenVAS instances, never disabled SELinux, and never had any issues. I get that we think it won't work correctly,

Re: [Openvas-discuss] Delete Reports

2015-04-14 Thread Brandon Perry
You could easily modify that script to delete them: http://www.openvas.org/omp-5-0.html#command_delete_report On Tue, Apr 14, 2015 at 12:45 PM, Turner,Jonas jotur...@hcr-manorcare.com wrote: Does anyone have a script that can delete all the reports that were generated by scans? Eero was

Re: [Openvas-discuss] OpenVAS 8 virtual appliance

2015-06-23 Thread Brandon Perry
I checked on this, cookie are enable in my web browser and the time is correctly synced on the virtual appliance. Still get the Cookie bad or missing. Please try again. error. Authing with the manager over OMP still works though. On Mon, Jun 22, 2015 at 8:15 AM, Brandon Perry bperry.volat

[Openvas-discuss] OpenVAS 8 virtual appliance

2015-06-21 Thread Brandon Perry
Hello, I am unable to login with admin/admin into GSA, but over OMP I am able to auth as admin. Am just playing around with the virtual appliance, so not a big deal. The error on screen after trying to auth via GSA is Cookie missing or bad. Please login again.

Re: [Openvas-discuss] OpenVAS 8 virtual appliance

2015-06-22 Thread Brandon Perry
Cookies are definitely enabled on the client (web browser) and time is correct on the client, not sure about the time on the OpenVAS VM. I can check this later today. On Mon, Jun 22, 2015 at 2:17 AM, Michael Meyer michael.me...@greenbone.net wrote: *** Brandon Perry wrote: The error

Re: [Openvas-discuss] Syn cert data without using rsync?

2015-05-29 Thread Brandon Perry
You could create an internal mirror and rsync internally, create the mirror with HTTP or whatnot. On Fri, May 29, 2015 at 10:43 AM, Emily Crowe emilyvcr...@gmail.com wrote: Hi all, I'm trying to set up OpenVAS, but I keep getting stuck when openvas-setup attempts to rsync. The default

Re: [Openvas-discuss] local account used for scans

2015-07-01 Thread Brandon Perry
I actually don't recommend running scans as root if you can get away with it. I use local accounts, can you SSH into the machine yourself? What happens when you run rpm -qa/dpkg -l if you can SSH into the box? On Wed, Jul 1, 2015 at 9:02 AM, Brian Thompson bthomp...@wyetechllc.com wrote:

Re: [Openvas-discuss] local account used for scans

2015-07-01 Thread Brandon Perry
password: password entered [openvas @ localhost ~]$ rpm -qa yum-utils-1.1.30-14.el6.noarch 100's more rpm's reported [openvas @ localhost ~]$ On July 1, 2015 at 10:05 AM Brandon Perry bperry.volat...@gmail.com wrote: I actually don't recommend running scans as root if you can get

Re: [Openvas-discuss] local account used for scans

2015-07-01 Thread Brandon Perry
, root, adm, sys, etc)? On July 1, 2015 at 10:17 AM Brandon Perry bperry.volat...@gmail.com wrote: Ah, I misread your original post. Not sure then. :/ On Wed, Jul 1, 2015 at 9:15 AM, Brian Thompson bthomp...@wyetechllc.com wrote: I'm not running the scans as root, I created a user (openvas

Re: [Openvas-discuss] `openvasmd --progress --verbose --rebuild` hangs forever

2015-07-30 Thread Brandon Perry
How long is forever? On Thu, Jul 30, 2015 at 9:04 AM, Arthur calvin...@gmail.com wrote: Hello, As my title say, my problem today is that the command `openvasmd --progress --verbose --rebuild` never returns and hangs forever, locking the sqlite database and preventing any other action

Re: [Openvas-discuss] `openvasmd --progress --verbose --rebuild` hangs forever

2015-07-30 Thread Brandon Perry
Also, not sure what the specs on your box is. You should have at least 4gb RAM and a nice proc to nicely run OpenVAS. On Thu, Jul 30, 2015 at 9:16 AM, Brandon Perry bperry.volat...@gmail.com wrote: Yes, while 30 mins is a bit long, let it sit a bit longer. I don't have much experience

Re: [Openvas-discuss] `openvasmd --progress --verbose --rebuild` hangs forever

2015-07-30 Thread Brandon Perry
Yes, while 30 mins is a bit long, let it sit a bit longer. I don't have much experience with the Ubuntu packages however. Also, don't stop them halfway through with Ctrl+c, I am not sure what kind of state that leaves openvasmd in. If you have done that, probably should reinstall and try again.

Re: [Openvas-discuss] Arachni and Nikto plugin support OpenVas 8

2015-07-31 Thread Brandon Perry
I am not sure if the arachni plugin was updated after arachni released a major update a while back changing many of the command line arguments. Sent from a phone On Jul 31, 2015, at 3:32 PM, Himanshu Kesar hke...@good.com wrote: Hi everyone, I am trying to setup Arachni and Nikto

Re: [Openvas-discuss] non Default scans

2015-08-04 Thread Brandon Perry
Wouldn't it be nmap that is being slow in the first 1%? On Tue, Aug 4, 2015 at 2:57 PM, Eero Volotinen eero.voloti...@iki.fi wrote: What is output of ps aux | grep openvas during scan? Eero 3.8.2015 8.01 ip. Dury, John C. jd...@duqlight.com kirjoitti: I have built both OpenVAS 8 and

Re: [Openvas-discuss] Severity in error, access denied when scanning any remote hosts

2015-08-14 Thread Brandon Perry
Do you have redis installed? On Fri, Aug 14, 2015 at 10:08 AM, Jeremy MJ jsk...@gmail.com wrote: I'm attempting to try out OpenVAS in ArchLinux. Everything is setup and running, but when I go to scan a host outside of my OpenVAS host, it fails, complaining about access being denied to a

[Openvas-discuss] Streaming XML parser and low-memory systems

2015-08-10 Thread Brandon Perry
While scanning with low memory systems is still an issue, it seems like the largest issue with OpenVAS running on low memory systems is actually parsing large XML files. I see a recent feature was added that splits large XML files for parsing. Would it be worthwhile to look into using a

Re: [Openvas-discuss] OpenVAS built from source on Ubuntu 14.04 but scans seem to hang

2015-07-27 Thread Brandon Perry
Using CentOS and the Atomic repos. On Mon, Jul 27, 2015 at 12:29 PM, Dury, John C. jd...@duqlight.com wrote: I installed a fresh copy of Ubuntu 14.04 and then installed and configured OpenVAS 8 from the latest non-beta sources via the instructions on this page

Re: [Openvas-discuss] Long delay when adding first credential

2015-07-16 Thread Brandon Perry
If there isn't a lot of entropy during key generation on the system, it can take a long time to create strong RSA keys for encrypting the credentials on the system. On Thu, Jul 16, 2015 at 10:41 AM, Wesley Botham wes...@semcat.net wrote: I just set up OpenVAS 8 in an Ubuntu 14.04 VM. I ran

Re: [Openvas-discuss] Nessus comparison

2015-10-20 Thread Brandon Perry
Reported vulnerability count is not a useful measurement for comparing two vulnerability scanners. One vulnerability scanner may report all missing patches, including ones that are superseded by others in the same report, while another does not. For instance, OpenVAS is far more useful to me

Re: [Openvas-discuss] OpenVAS 8 openvas-check-setup

2015-07-10 Thread Brandon Perry
Let's keep it civil please. This has gotten off track. On Fri, Jul 10, 2015 at 9:46 AM, Reindl Harald h.rei...@thelounge.net wrote: Am 10.07.2015 um 16:39 schrieb Eero Volotinen: disabling selinux required reboot, logging permissive mode is possible without rebooting. you can use

Re: [Openvas-discuss] debian 8 and openvas pdf generation?

2015-09-21 Thread Brandon Perry
While I can’t say the exact libs that are required, here is the dpkg -l printout of the openvas debian appliance (v8). I expect the poppler and ghostscript libs are what are used. Desired=Unknown/Install/Remove/Purge/Hold |

Re: [Openvas-discuss] Openvas Agent

2016-02-25 Thread Brandon Perry
> On Feb 25, 2016, at 10:41 AM, Eero Volotinen wrote: > > Agent? There is no agents on openvas, only slaves. > There are agents. http://www.openvas.org/omp-6-0.html#command_create_agent But there isn’t an

Re: [Openvas-discuss] Admin Role (restrictions) & Privileges

2016-05-14 Thread Brandon Perry
id that in the future, > if possible. Thanks, T If you are trying to completely separate admin users (if you can’t trust them, why are they admins?), you are looking for multi-tenancy. Best way to ensure it doesn’t happen again is give them two systems, not a shared one. > > On 14 Ma

Re: [Openvas-discuss] Admin Role (restrictions) & Privileges

2016-05-14 Thread Brandon Perry
> On May 14, 2016, at 12:03 PM, TN TN wrote: > > Hi all, when I create two users and assign them an Admin role, lets name them > admin1 and admin2 they can see each others username under Administration -> > Users (in GSA). What privileges can I set to avoid having the

Re: [Openvas-discuss] PHP not detected

2016-09-07 Thread Brandon Perry
You should be performing authenticated scans to detect these things, not unauthenticated external scans based on HTTP headers. > On Sep 7, 2016, at 8:42 AM, Jiri K. wrote: > > Hello everyone, > > I did a Full & Fast scan of our server which is running Apache and PHP >

Re: [Openvas-discuss] Problem getting tasks to run - old and new

2016-09-14 Thread Brandon Perry
Please run openvasmd --rebuild and restart the manager (latter probably not needed). > On Sep 14, 2016, at 2:41 PM, Allyn Baskerville wrote: > > The scans were running fine for a few weeks, but they stopped a couple days > ago. OpenVAS 8 is running on CentOS 7. I created a

Re: [Openvas-discuss] Problem getting tasks to run - old and new

2016-09-14 Thread Brandon Perry
ebuild immediately upon receipt of your email, and 40 minutes > later it is still rebuilding. > > From: Brandon Perry [mailto:bperry.volat...@gmail.com] > Sent: Wednesday, September 14, 2016 2:50 PM > To: Allyn Baskerville > Cc: openvas-discuss@wald.intevation.org > Subject

Re: [Openvas-discuss] experience with hackertarget.com or similar services

2017-04-28 Thread Brandon Perry
> On Apr 28, 2017, at 6:21 AM, Niklas Klein wrote: > > Hello, > > Does anyone have experience with hackertarget.com or similar services? In > short: Hackertarget offers to make vulnaribility scans against an ip given to > them. That would be interesting for us since

Re: [Openvas-discuss] sql errors

2017-06-12 Thread Brandon Perry
> On Jun 12, 2017, at 8:33 AM, Thijs Stuurman > wrote: > > No, never. These are also the kind of errors I never ever wish to see! > > If your data is still there, scan tasks .. history etc’ I strongly urge you > to make a backup and repeat making backups

Re: [Openvas-discuss] problem after compiling omp: libopenvas_omp.so.8

2017-05-23 Thread Brandon Perry
> On May 23, 2017, at 9:04 AM, Dehm, Jochen wrote: > > I want to use a 2nd server to control my OpenVAS server via omp. > > After building openvas-libraries and openvas-cli from the source, I get the > following error: > > root@sv-idoit ~ # omp > omp: error while

Re: [Openvas-discuss] problem after compiling omp: libopenvas_omp.so.8

2017-05-23 Thread Brandon Perry
> On May 23, 2017, at 9:17 AM, Reindl Harald <h.rei...@thelounge.net> wrote: > > > > Am 23.05.2017 um 16:10 schrieb Brandon Perry: >>> On May 23, 2017, at 9:04 AM, Dehm, Jochen <jochen.d...@freenet.de> wrote: >>> >>> I want to

Re: [Openvas-discuss] openvasmd don't start after upgrade

2017-10-30 Thread Brandon Perry
> On Oct 30, 2017, at 8:18 AM, Reindl Harald wrote: > > > > Am 30.10.2017 um 14:03 schrieb Reindl Harald: >> openvas-libraries-9.0.1-1.fc26.x86_64 >> openvas-manager-7.0.2-1.fc26.x86_64 >> openvas-cli-1.4.5-3.fc26.x86_64 >> openvas-gsa-7.0.2-2.fc26.x86_64 >>

Re: [Openvas-discuss] Empty vulnerabilities in report

2018-06-26 Thread Brandon Perry
Sent from my iPhone > On Jun 25, 2018, at 10:01 PM, Daryn Utesbayev wrote: > > Hi, > We deployed OpenVas in our organization for monitoring vulnerabilities. After > that we checked many targets host to get reports of vulnerabilities. Further > OpenVAS scans produce reports displaying

Re: [Openvas-discuss] stupid question

2017-10-27 Thread Brandon Perry
> On Oct 25, 2017, at 2:10 PM, AP - Alan Jackson > wrote: > > I am brand new to the discussion list. Is there a way to search through the > archive of all the past threads? I don’t want to post a question that has > already been answered, and I would rather not

Re: [Openvas-discuss] distribute the load for a single task amongst a list of scanners?

2018-08-07 Thread Brandon Perry
> On Aug 7, 2018, at 7:34 AM, Fichter, Frédéric > wrote: > > Hello all, > > Is there a way to distribute the load for a single task amongst a list of > scanners? You should instead split the size of the task up and schedule smaller network blocks, rather than trying to run the single

Re: [Openvas-discuss] Scanning for vulnerabilities in Oracle Database

2018-04-07 Thread Brandon Perry
> On Apr 7, 2018, at 10:56 AM, Anantha Raghava > wrote: > > Hi, > > I have been using OpenVas vulnerability scanning for sometime now. > > I am trying to scan for Oracle Database on Windows to start with for > vulnerabilities. When I select Full & Fast scan

<    1   2