With the background information on vulnerability scanning complete, let's jump into the heart of vulnerability scanning and start checking some hosts. Like I mentioned earlier, there is a plethora of vulnerability scanning products out there. However, for my lab, I will be utilizing OpenVAS, which is a free, open source tool.
Even through we are using OpenVAS in this lab, don't think this is a required scanner. If you have a subscription to some of the paid scanners, or if you prefer the use of another tool, feel free to use that. The syntax, execution, and process of the scans may be different; however, the overall results should be the same.
OpenVAS was a fork of the Nessus product, so it has a great history. OpenVAS is an extremely powerful scanner, but can be difficult to get the hang of. There is a defined structure to OpenVAS, which is labeled in this...