Showing posts with label openvas. Show all posts
Showing posts with label openvas. Show all posts

Wednesday, October 20, 2010

What I've been up to...

In case you didn't know, Ubuntu 10.10 was released on 10.10.10. I've not upgraded my systems as I am quite happy with 10.04 and the promise of it's LTS (Long Term Support). That said, I'll pick one of my machines and see how good 10.10 is and post my findings at a later date.

What have I been up to lately? My friend (droll) introduced me to a nifty little device called the Nokia N900 which is based of Maemo which is derived from Debian Linux.

I've gotten a nifty overclocking which allows my to underclock the device at 125MHz all the way to 1.15GHz (the stock speeds at 250MHz till 600MHz). I've also gotten kismet and nmap installed on this device so wireless testing is now simply putting my phone in my pocket and walking around. I will soon be trying to get install OpenVAS which should make for a rather complete basic pentesting setup, all on my phone. I may even try Ubuntu 9.04 which somebody ported over to the N900 (it's ARM based).

Though this site is called "Life with Ubuntu", I guess I'll be including some Maemo/MeeGo blogs in the future.

Sunday, April 11, 2010

Installing OpenVAS 3.0.x on Ubuntu Linux...

This is a follow-up to my earlier article on Installing OpenVAS 2.0.x on Ubuntu Linux...

Updating your Ubuntu Setup

Before we begin, it is best that we update our Ubuntu libraries and applications to the latest versions by typing the following in a terminal:

sudo apt-get update
sudo apt-get upgrade


Installing the libraries that OpenVAS uses

Once you have updated your machine, we will need to install the following libraries and applications to compile and install OpenVAS. Again, in the terminal:

sudo apt-get install cmake build-essential libgtk2.0-dev libglib2.0-dev libssl-dev htmldoc libgnutls-dev libpcap0.8-dev bison libgpgme11-dev libsmbclient-dev snmp pnscan


Downloading the source code and compiling them

Now that the machine is ready to work with the OpenVAS sources, you then need to download the following source codes from the OpenVAS website. You can find the sources at URL http://wald.intevation.org/frs/?group_id=29

Download the latest version of the following:

openvas-libraries (latest v3.0.x, I used 3.0.4)
openvas-scanner (latest v3.0.x, I used 3.0.2)
openvas-client (latest v3.0.x, I used 3.0.0)

You will need to install OpenVAS in the above listed order. To install each component, you will need to do the following:

tar -zxvf [filename of .tar.gz file]
cd [sub-folder of same name as .tar.gz file]
./configure
make
sudo make install
cd ..

If you are using the 64-bit version of Ubuntu, you may get an error message ("/usr/bin/ld: cannot find -lcrypto") when you 'make' the openvas-client. You can fix this by typing:

sudo ln -s /usr/lib/libcrypto.so.0.9.8 /usr/lib/libcrypto.so

Once all three components are compiled and installed, you will then need to let Ubuntu know about the new libraries you have just compiled before the can be used by typing in:

sudo ldconfig -v


First time OpenVAS users

For the first time use of OpenVAS, you will need to create a new cert and add in the first user that can login into the OpenVAS server by running both:

sudo openvas-mkcert
sudo openvas-adduser


Updating the latest plug-ins

Periodically (I usually run it once every day, or just before I am about to use OpenVAS), you will need to update the plugins that OpenVAS uses to detect newer vulnerabilities which are found everyday. You can do that by typing:

sudo openvas-nvt-sync

Note: There is a bug in the update script and you will get an error message (as of today, 11-Apr-2010). A quick look at the OpenVAS forums showed a typo made by one of the developers and the way to fix this is do the following (in a terminal):

gksu gedit /usr/local/sbin/openvas-nvt-sync

Search for the string (my script had it on line 63):

SYNC_TMP_DIR='mktemp -d openvas-nvt-sync'

and change it to:

SYNC_TMP_DIR='mktemp -d openvas-nvt-sync.XXXXXXXXXX -t'

To start the OpenVAS server, activate the server by typing in:

sudo openvassd

And running the OpenVAS client by typing:

sudo OpenVAS-Client

If you want to learn or know more about OpenVAS, visit them at http://www.openvas.org/

Note: Tested on Ubuntu 9.10, and I assume you are doing all this with user access (that is why, some root only commands have the "sudo" command in front of them) and am running the kernel in i386 (32-bit) mode. Also, as I did not test this on a 64-bit system, the 64-bit only error/solution mentioned in my article comes from the forums and I have not tested them myself.

Wednesday, November 18, 2009

Installing OpenVAS 2.0.x on Ubuntu Linux...

This is a follow-up to my earlier article on Installing OpenVAS 1.0.x

OpenVAS has started releasing betas of v3.0.x, so I thought I'd write a tutorial on how to install the latest stable version of OpenVAS (v2.0.x).

Before we begin, it is best that we update our Ubuntu libraries and applications to the latest versions by typing the following in a terminal:

sudo apt-get update
sudo apt-get upgrade

Once you have updated your machine, we will need to install the following libraries and applications to compile and install OpenVAS. Again, in the terminal:

sudo apt-get install build-essential libgnutls-dev libpcap0.8-dev bison
sudo apt-get install libgtk2.0-dev libglib2.0-dev libgpgme11-dev libssl-dev htmldoc

Now that the machine is ready to work with the OpenVAS sources, you then need to download the following source codes from the OpenVAS website. You can find the sources at URL http://wald.intevation.org/frs/?group_id=29

Download the latest version of the following:

openvas-libraries (latest v2.0.x)
openvas-libnasl (latest v2.0.x)
openvas-server (latest v2.0.x)
openvas-plugins (latest v1.0.x)
openvas-client (latest v2.0.x)

You will need to install OpenVAS in the above listed order. To install each component, you will need to do the following:

tar zxvf [filename of .tar.gz file]
cd [sub-folder of same name as .tar.gz file]
./configure
make
sudo make install
cd ..

Once all five components are compiled and installed, you will then need to let Ubuntu know about the new libraries you have just compiled before the can be used by typing in:

sudo ldconfig -v


For the first time use of OpenVAS, you will need to create a new cert and add in the first user that can login into the OpenVAS server by running both:

sudo openvas-mkcert
sudo openvas-adduser


Periodically (I usually run it once every day, or just before I am about to use OpenVAS), you will need to update the plugins that OpenVAS uses to detect newer vulnerabilities which are found everyday. You can do that by typing:

sudo openvas-nvt-sync


To start the OpenVAS server, activate the server by typing in:

sudo openvasd -D

And running the OpenVAS client by typing:

sudo OpenVAS-Client

If you want to learn or know more about OpenVAS, visit them at http://www.openvas.org/

Note: Tested on Ubuntu 9.10, and I assume you are doing all this with user access (that is why, some root only commands have the "sudo" command in front of them) and am running the kernel in i386 (32-bit) mode.

Sunday, February 8, 2009

Installing OpenVAS 1.0.x on Ubuntu Linux...

OpenVAS (URL http://www.openvas.org) is an open source and fully GPL'ed fork of the now closed source Nessus security scanner. I will not go into the history of Nessus and why OpenVAS is a fork of that source code but will focus more on how I installed OpenVAS on my favorite Linux distro Ubuntu.

If you go to the OpenVAS site, they only have .rpm (aka RedHat) packages and can't be used on a Debian based distro like Ubuntu. Also, as a side note, if you want to do something else with OpenVAS which I am not covering, remember that you should best follow only the Ubuntu specific instructions and when that is not possible, for the Debian Etch instructions as Ubuntu uses the "Etch" branch of Debian.

The instructions below are for use with OpenVAS v1.x and not the new beta 2.0 (will write another article later when it gets out of beta).

Firstly, you will need to add the following repositories into aptitude by editing /etc/apt/sources.list and adding the following line into the sources.list file:

deb http://apt.intevation.de/ etch openvas

You then update your Ubuntu repositories by issuing the "apt-get update" command.

You then need to download the following source codes from the OpenVAS website. Which you can find at URL http://wald.intevation.org/frs/?group_id=29

They are:

openvas-libraries 1.0.2 (not needed, a .deb installer is available in the repository)
openvas-libnasl 1.0.1
openvas-server 1.0.2
openvas-plugins 1.0.4 (if there is a newer version > 1.0.4, download that instead)

Create a sub-directory in your home directory called "~/openvas1" and move all the .tar.gz source code files into this folder.

Then, you need to install certain libraries which OpenVAS uses prior to compiling the source codes you've downloaded by issuing the command:

apt-get install openvas-client libopenvas1 libopenvas1-dev libgpgme11 libgpgme11-dev bison build-essential

!
! in Ubuntu 8.10, prior to issuing the above command, you will need to install
! some libraries which are missing in Ubuntu 8.10.
!
! Download the following .deb (libgnutls13 and libopencdk10) files from the
! hardy packages (they'll work in Ubuntu 8.10)
!
! http://packages.ubuntu.com/hardy-updates/i386/libgnutls13/download
! http://packages.ubuntu.com/hardy/i386/libopencdk10/download
!
! You can install the two .deb files by issuing the command:
!
! dpkg -i libgnutls13_2.0.4-1ubuntu2.1_i386.deb
! dpkg -i libopencdk10_0.6.6-1ubuntu1_i386.deb
!

You will then need to open the three source code files, untar them and compile them. You can do this for all three packages by typing in:

tar zxvf [filename of .tar.gz file]
cd [sub-folder of same name as .tar.gz file]
./configure
make
make install
cd ..

You will need to do the above with all three files, mainly:

openvas-libnasl-1.0.1.tar.gz
openvas-server-1.0.2.tar.gz
openvas-plugins-1.0.4.tar.gz

in the above order.

You will then need to let your linux system know about the new libraries you have just compiled before the can be used by typing in:

ldconfig -v

You then need to copy the file openvas-services from the server source code folder into the /var/lib/openvas directory by issuing the following command in a bash shell:

mkdir /var/lib/openvas
cp ~/openvas1/openvas-server-1.0.2/openvas-services /var/lib/openvas/

For the first time use of OpenVAS, you will need to create a new cert and add in the first user that can login into the OpenVAS server by running both:

openvas-mkcert
openvas-adduser

To start OpenVAS, activate the server by typing in:

openvasd -D &

And running the OpenVAS client by typing:

openvas-client

If all works well, when you run openvasd, you will see it attempt to load in all the plug-ins and in the openvas-client, connect to the openvas server.

Feel free to comment!

Note: Tested on Ubuntu 7.10, 8.04 and 8.10, and I assume you are doing all this with root access and am running the kernel in i386 (32-bit) mode.