EvilZone

Hacking and Security => Hacking and Security => : Nortcele October 22, 2014, 10:26:15 PM

: Vunrability Scanners
: Nortcele October 22, 2014, 10:26:15 PM
So seen as though my Nessus license has ran out,

Anyone know of any good, FREE, Vulnerability scanners to take its place?

Thanks.
: Re: Vunrability Scanners
: Phage October 22, 2014, 10:26:53 PM
Fuck scanners, they make too much noise anyway.
: Re: Vunrability Scanners
: Nortcele October 22, 2014, 10:35:57 PM
I have done all my recon and research and have managed to find an open rtsp port, I need to scan for exploits...
: Re: Vunrability Scanners
: HTH October 22, 2014, 11:02:19 PM
Nessus is still a thing? I thought it died along with my highschool days... but I guess I've never had the urge to spend over a grand to use a piece of software for a year.

Anyway, if you really want to use a scanner,

Nexpose and Metasploit are both owned / distributed by Rapid7, and they both have free versions for single IP users. (with limited functionality in the case of Nexpose)

I think OpenVas is still kicking around, and Qualys also exists. I agree with Phage that these scanners are gonna light up the network like a fucking christmas tree but hey.

Or if paid products are your thing, you could go get Core Impact, sure it's like buying a car, but they did pivot attacks first mang.


: Re: Vunrability Scanners
: Nortcele October 22, 2014, 11:13:29 PM
Using a Metasploit trial now, no worries.
: Re: Vunrability Scanners
: d!amond October 23, 2014, 01:02:22 AM
What about intercepting proxies? So you can find vulnerabilities "on the fly"? I am not a big fan of scanners.. but you could try out:

OWASP ZAP https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project

Vega https://subgraph.com/vega/

w3af http://w3af.org/

Maybe its something for you
: Re: Vunrability Scanners
: Nortcele October 23, 2014, 10:11:31 AM
Im using Metasploit Enterprise and Nexpose, both have done the trick and managed to find 72 Vuns 36 of which were Severe in my last test...
: Re: Vunrability Scanners
: rocketballz November 13, 2014, 02:59:11 PM
Acunetix

~APH ADMIN ~

: Re: Vunrability Scanners
: rocketballz November 13, 2014, 03:02:12 PM
Here is the program http://www.mediafire.com/folder/14ol0977ow5tx

~APH ADMIN ~

: Re: Vunrability Scanners
: chapp November 13, 2014, 09:11:41 PM
I find that scanners are very noisy and the result are too many false-positives, which you spend too much time verifying.

In case of an engagement I'd use scanners as they are "free" in terms of click and run for some hours, while you spend time doing something else and the noise is not a problem if agreed upon. Some engagements requires a more under the radar approach though.
: Re: Vunrability Scanners
: votoco2014 November 18, 2014, 03:13:03 AM
Using a Metasploit 8)
: Re: Vunrability Scanners
: d4rkcat November 18, 2014, 05:11:52 AM
For webapps, I find Arachni (https://github.com/Arachni/arachni) to be the most efficient, most accurate scanner.
: Re: Vunrability Scanners
: ande November 18, 2014, 08:06:38 AM
Try making your own? Its great practice for web application security.
: Re: Vunrability Scanners
: proxx November 18, 2014, 08:56:49 AM
I get thousands of requests like these on the webservers I manage.
You would be amazed how quickly it will ban your ass ;)
: Re: Vunrability Scanners
: d4rkcat November 18, 2014, 09:09:35 AM
I get thousands of requests like these on the webservers I manage.
You would be amazed how quickly it will ban your ass ;)

Bet that ban list is a nice collection of proxies and tor exit nodes.
Really though, who is going to be blackbox scanning a website from their own IP?
: Re: Vunrability Scanners
: proxx November 18, 2014, 09:21:17 AM
Bet that ban list is a nice collection of proxies and tor exit nodes.
Really though, who is going to be blackbox scanning a website from their own IP?
Because it doesn't really matter doing so.
You know , who gives a fuck , if I would have to report every single malicious attempt I would have nothing else to do the entire day.
Since most of it is dynamic anyway it is only relevant for a short period.
Irl it does hardly matter , you end up banned , end of story.
You gotta do some real nasty shit if you want to end up blacklisted ;)


: Re: Vunrability Scanners
: ande November 18, 2014, 10:42:45 AM
Lets try to remember that vulnerability scanners are not malicious by themselves, and are in fact handy tools for those making software and web pages.
: Re: Vunrability Scanners
: anUser190 February 15, 2015, 01:41:06 AM
I find that scanners are very noisy and the result are too many false-positives, which you spend too much time verifying.

In case of an engagement I'd use scanners as they are "free" in terms of click and run for some hours, while you spend time doing something else and the noise is not a problem if agreed upon. Some engagements requires a more under the radar approach though.

What do you do instead of using a scanner? nmap to see what ports are open and then version them one at a time, then look up on websites to see if the versions have vulnerabilities?
: Re: Vunrability Scanners
: Killeramor February 16, 2015, 08:03:37 PM
Yeah he needs to jump off a bridge with that.
: Re: Vunrability Scanners
: GlobalRoot February 17, 2015, 02:28:14 AM
Hello, Offline Nortcele

You can always find cracks for paid ones. You can find cracks at torrenting websites like Kickass.to but most torrents have some sort of malware in it. I reconmend you start learning about web pentesting. You get more out of it. In the long run you will be very happy with it. Manually is a lot better in my opinion.