data:image/s3,"s3://crabby-images/da466/da466bfda52cccf5b018995c1cdcb625b6459d92" alt="Metasploit Penetration Testing Cookbook(Third Edition)"
上QQ阅读APP看书,第一时间看更新
How to do it...
- To install OpenVAS on Kali Linux use the apt install openvas command:
root@kali:~# apt-get install openvas
- Then use the openvas-setup command to set up OpenVAS, download the latest rules, create an admin user, and start up the various services:
root@kali:~# openvas-setup
- When the setup is finished, the OpenVAS manager, scanner, and GSAD services should be listening. To start OpenVAS, use the openvas-start command:
root@kali:~# openvas-start
Starting OpenVas Services
root@kali:~#
- Before we can use OpenVAS inside msfconsole, we need to load the OpenVAS plugin using the load command:
msf > load openvas
[*] Welcome to OpenVAS integration by kost and averagesecurityguy.
[*]
[*] OpenVAS integration requires a database connection. Once the
[*] database is ready, connect to the OpenVAS server using openvas_connect.
[*] For additional commands use openvas_help.
[*]
[*] Successfully loaded plugin: OpenVAS
msf >
- We can use the help command to display all the available OpenVAS commands we can use inside msfconsole:
msf > help openvas
OpenVAS Commands
================
Command Description
------- -----------
openvas_config_list Quickly display list of configs
openvas_connect Connect to an OpenVAS manager using OMP
...
openvas_task_start Start task by ID
openvas_task_stop Stop task by ID
openvas_version Display the version of the OpenVAS server
msf >
- To connect to the OpenVAS manager using OMP, we use the openvas_connect followed by the OpenVAS username, password, and the OpenVAS server IP address and port:
msf > openvas_connect admin 596230dc-cfe0-4322-a7b7-025d11a28141 127.0.0.1 9390
[*] Connecting to OpenVAS instance at 127.0.0.1:9390 with username admin...
/usr/share/metasploit-framework/vendor/bundle/ruby/2.3.0/gems/openvas-omp-0.0.4/lib/openvas-omp.rb:201:in `sendrecv': Object#timeout is deprecated, use Timeout.timeout instead.
[+] OpenVAS connection successful
msf >
- After connecting to the OpenVAS server, we need to specify our target using the openvas_target_create command followed by the name we want to give to our target, the IP address of the target, and a description or comment about the target:
msf > openvas_target_create "Metasploitable3" 192.168.216.10 "Windows Target"
[+] OpenVAS list of targets
ID Name Hosts Max Hosts In Use Comment
-- ---- ----- --------- ------ -------
83d3d851-150a-4d1b-80e3-04bb90d034cb Metasploitable3 192.168.216.10 1 0 Windows Target
msf >
- The openvas_config_list displays the list of configurations we can use to scan the target:
msf > openvas_config_list
[+] OpenVAS list of configs
ID Name
-- ----
085569ce-73ed-11df-83c3-002264764cea empty
2d3f051c-55ba-11e3-bf43-406186ea4fc5 Host Discovery
698f691e-7489-11df-9d8c-002264764cea Full and fast ultimate
708f25c4-7489-11df-8094-002264764cea Full and very deep
...
msf >
- Now, we need to create a task using the openvas_task_create followed by the task name, comment, the config ID, and target ID:
data:image/s3,"s3://crabby-images/318f2/318f21df2586aa71402f78c3891e53fcc14144c9" alt=""
- To start the task, we will use the openvas_task_start followed by the task ID:
data:image/s3,"s3://crabby-images/22ada/22ada2f947ff97b61956be6f632dad49528a9e06" alt=""
- To monitor the progress, we use the openvas_task_list command:
data:image/s3,"s3://crabby-images/4ab76/4ab76b895fecca8bf303ed3eee0c36e553e39837" alt=""
- The openvas_format_list will display the list of report formats supported by OpenVAS:
data:image/s3,"s3://crabby-images/1f140/1f1407b9dfe36c2df2021d04a5b49389d9e09a1e" alt=""
- To see if the task has completed, use the openvas_task_list command:
data:image/s3,"s3://crabby-images/1660f/1660f3ab1089694cdf2937510cd4c02d5e4af906" alt=""
- When the scan is finished, we can use the openvas_report_list command to list the available reports:
data:image/s3,"s3://crabby-images/173bd/173bd9cd2ef872a1c22c0b1a009b649786195a0d" alt=""
- And use the openvas_report_import command to import the report into Metasploit. Only the NBE (legacy OpenVAS report) and XML formats are supported for importing:
data:image/s3,"s3://crabby-images/e4f62/e4f62bf96280c52815d7e2dd7151865214ab4f9c" alt=""
- After importing the report into Metasploit, we can use the msfconsole database vulns command to list the vulnerabilities found:
data:image/s3,"s3://crabby-images/af552/af55204c994c9a71adf55cb67057d3cdfcbc2d5f" alt=""