#nessus — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #nessus, aggregated by home.social.
-
updated CheckNessusAuth — a tool that helps you verify whether Nessus authenticated scans are likely to succeed or not before you start scanning.
GitHub: https://github.com/dietersar/CheckNessusAuthScan
Website: https://secudea.be/tools/nessus-auth-scanning-tool/#Nessus #CyberSecurity #VulnerabilityManagement #AuthenticatedScans #Infosec #SecurityTools #GUI #Automation
-
Heyyyyy #Tenable #Nessus? Can we maybe not run sketchy-looking #PowerShell on my computer? I just happened to catch this in the logs. Kay, thanks.
-
Is there anyone who is proficient with Tenable.sc and managed #Nessus scanners? I'm having a hellova time trying to figure out a glitch with plugins. No matter what I do, my scanner gets only the plugins from 12 May 2025. I've been laser-focused on troubleshooting this and I've run out of ideas. I've even rebuilt the scanner server with no change, leading me to believe it's something with Tenable.sc, and Tenable.sc has the latest plugin set. Help me Obi-won, you're my only hope. #Tenable
-
High-Severity Vulnerabilities Patched in Tenable Nessus Agent – Source: www.securityweek.com https://ciso2ciso.com/high-severity-vulnerabilities-patched-in-tenable-nessus-agent-source-www-securityweek-com/ #securityproductvulnerability #rssfeedpostgeneratorecho #CyberSecurityNews #Endpointsecurity #securityweekcom #securityweek #Tenable #Nessus
-
High-Severity Vulnerabilities Patched in Tenable Nessus Agent https://www.securityweek.com/high-severity-vulnerabilities-patched-in-tenable-nessus-agent/ #securityproductvulnerability #EndpointSecurity #Tenable #Nessus
-
High-Severity Vulnerabilities Patched in Tenable Nessus Agent https://www.securityweek.com/high-severity-vulnerabilities-patched-in-tenable-nessus-agent/ #securityproductvulnerability #EndpointSecurity #Tenable #Nessus
-
Nessus scanner agents went offline due to a faulty plugin update – Source: securityaffairs.com https://ciso2ciso.com/nessus-scanner-agents-went-offline-due-to-a-faulty-plugin-update-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #Security #Tenable #Nessus
-
Tenable Disables Nessus Agents Over Faulty Updates – Source: www.securityweek.com https://ciso2ciso.com/tenable-disables-nessus-agents-over-faulty-updates-source-www-securityweek-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Endpointsecurity #securityweekcom #securityweek #buggyupdate #Tenable #Nessus
-
Tenable Disables Nessus Agents Over Faulty Updates https://www.securityweek.com/tenable-disables-nessus-agents-over-faulty-updates/ #EndpointSecurity #buggyupdate #Tenable #Nessus
-
Tenable Disables Nessus Agents Over Faulty Updates https://www.securityweek.com/tenable-disables-nessus-agents-over-faulty-updates/ #EndpointSecurity #buggyupdate #Tenable #Nessus
-
Bad Tenable plugin updates take down Nessus agents worldwide #vulnerabilityscan #tenable #nessus #networksecurity https://www.bleepingcomputer.com/news/security/bad-tenable-plugin-updates-take-down-nessus-agents-worldwide/?s=09
-
That's a bold statement.
In my experience, #Nessus has at least one false positive in every single scan. There are many plugins that haven't seen a true positive for years.
-
"Note that Nessus has not attempted to exploit the issue but has instead only checked if OpenSSH is running on the remote host."
But how about—as the bare minimum—you check the version or don't fucking report vulnerabilities that have been fixed for 17 years! 🤬
-
Also if you think about it, the majority of #tenable #nessus functionality is based on its ability to log into a remote machine, use the tools on that host (windows: regsitry calls, execute cmd.exe scripts or posh, unix: ssh in run commands built into the host to retrive whatever info it has), and then generate a report. #nmap has the modules
libssh2-utilityto log you in (check outssh-run.nse) and smb capabilities (smb-psexec.nse) that allow you to run services commands and the like on Windows.Why are people paying thousands in subscription fees ???!
#infosec c
-
There's no way that this will help ANYONE, but..
I'm doing an eval of #Nessus (a cybersecurity scanning tool) on our product (#Aarch64 running #Linux (#Debian, to be specific).
And one of the tests would cause my system to kernel panic and reboot.
After a lot of trial and error, I found that some of the tests are trying to use `dmidecode`, which, evidently, is super spicy for us.
I `chmod 000 /usr/sbin/dmidecode` and now everything is happy.
(Again, I know that no one wants to know this)
-
Another #Nessus gem: plugin 58601
This plugin checks for two vulnerabilities from 2008. It's triggered by the header "X-Powered-By : ASP.NET". 🤦
Nessus: "It is not possible to determine the version from the header, so this may be a false positive."
O RLY? In fact, I would say it is almost certainly a false positive. Every single time.
-
One of the most widely used scanners is #Nessus, and many of its plugins have terrible specificity (they are prone to false positives).
One plugin I had to deal with today is plugin 137702. It finds systems vulnerable to #Ripple20, a set of 19 vulnerabilities in the Treck TCP/IP stack discovered in 2020. These vulnerabilities are a serious security risk if present, but should have been fixed in most systems by now.
2/ 🧵
-
Hatte ich schon mal erwähnt dass ich #Nessus für ganz großen Ranz halte?
Weder sind ICMP Timestamp Pakete böse noch ist mein mit Kerberos gesicherter NFS-Server Welt-lesbar und auch ssh 9.2 in Debian stable muss nicht auf 9.3 aktualisiert werden. Die sind doch vollkommen irre. -
Install Nessus for Free and scan for Vulnerabilities (New Way)
YouTube video: https://youtu.be/Gy-aPBb0djk
#kalilinux #linux #cybersecurity #infosec #informationsecurity #scan #nmap #nessus
-
2024 und #nessus ist immer noch nicht klüger geworden.
Ist ja schon gut, dass es sich CVEs/DSAs anschaut und schaut ob die installierten Pakete das Update auch eingespielt haben.
Aber wenn er dann die Source-Paket Version im Binär-Paket erwartet und wenn das nicht stimmt rummotzt, dann hat er halt #Debian nicht verstanden.
-
Abenteuer IT Selbständigkeit
#Wochenbericht (KW45):- Mo: Laptop einrichten, #3CX installieren, #OPNsense Support
- Di: Bürotag und #Tickets erledigen, #Nessus Scan, #Stadtrat am Abend
- Mi: #OPNsense installieren und Netzwerk umbauen. Alten Server abschalten, #TrueNAS übernimmt
- Do: #3CX Besprechung Neukundenaquise
- Fr: #OPNsense Schulung und #3CX installieren, Update von 3 #GroupOffice Instanzen
- Sa: Umzug von #pfSense auf #OPNsense -
I don't want to talk about how #Tenable raised the price of #Nessus Professional from 3k to 4k. Depending on who you ask, it was already too much, or it might still be worth it.
But delivering the news with a (not so subtle) threat is everything that is wrong with the #infosec industry.
Our job is to protect businesses, not scare them into giving up their money. That's the job of the ransomware gangs.