Learning Nessus for Penetration Testing
暫譯: 學習 Nessus 進行滲透測試

Himanshu Kumar

  • 出版商: Packt Publishing
  • 出版日期: 2013-12-14
  • 售價: $1,530
  • 貴賓價: 9.5$1,454
  • 語言: 英文
  • 頁數: 116
  • 裝訂: Paperback
  • ISBN: 1783550996
  • ISBN-13: 9781783550999
  • 海外代購書籍(需單獨結帳)

商品描述

Master how to perform IT infrastructure security vulnerability assessments using Nessus with tips and insights from real-world challenges faced during vulnerability assessment

Overview

  • Understand the basics of vulnerability assessment and penetration testing as well as the different types of testing
  • Successfully install Nessus and configure scanning options
  • Learn useful tips based on real-world issues faced during scanning
  • Use Nessus for compliance checks

In Detail

IT security is a vast and exciting domain, with vulnerability assessment and penetration testing being the most important and commonly performed security activities across organizations today. The Nessus tool gives the end user the ability to perform these kinds of security tests quickly and effectively.

Nessus is a widely used tool for vulnerability assessment, and Learning Nessus for Penetration Testing gives you a comprehensive insight into the use of this tool. This book is a step-by-step guide that will teach you about the various options available in the Nessus vulnerability scanner tool so you can conduct a vulnerability assessment that helps to identify exposures in IT infrastructure quickly and efficiently. This book will also give you an insight into penetration testing and how to conduct compliance checks using Nessus.

This book starts off with an introduction to vulnerability assessment and penetration testing before moving on to show you the steps needed to install Nessus on Windows and Linux platforms.

Throughout the course of this book, you will learn about the various administrative options available in Nessus such as how to create a new user. You will also learn about important concepts like how to analyze results to remove false positives and criticality. At the end of this book, you will also be introduced to the compliance check feature of Nessus and given an insight into how it is different from regular vulnerability scanning.

Learning Nessus for Penetration Testing teaches you everything you need to know about how to perform VA/PT effectively using Nessus to secure your IT infrastructure and to meet compliance requirements in an effective and efficient manner.

What you will learn from this book

  • Understand the basics of vulnerability assessment and penetration testing
  • Install Nessus on Windows and Linux platforms
  • Set up a scan policy based on the type of infrastructure you are scanning
  • Configure a scan by choosing the right policy and options
  • Understand the difference between credentialed and non-credentialed scans
  • Analyze results from a severity, applicability, and false positive perspective
  • Perform penetration tests using Nessus output
  • Perform compliance checks using Nessus and understand the difference between compliance checks and vulnerability assessment

Approach

This book is a friendly tutorial that uses several examples of real-world scanning and exploitation processes which will help get you on the road to becoming an expert penetration tester.

Who this book is written for

Learning Nessus for Penetration Testing is ideal for security professionals and network administrators who wish to learn how to use Nessus to conduct vulnerability assessments to identify vulnerabilities in IT infrastructure quickly and efficiently.

商品描述(中文翻譯)

掌握如何使用 Nessus 進行 IT 基礎設施安全漏洞評估,並獲取來自實際挑戰的提示和見解。

概述
- 了解漏洞評估和滲透測試的基本概念以及不同類型的測試
- 成功安裝 Nessus 並配置掃描選項
- 根據掃描過程中遇到的實際問題學習有用的提示
- 使用 Nessus 進行合規性檢查

詳細內容
IT 安全是一個廣泛而令人興奮的領域,漏洞評估和滲透測試是當今各組織中最重要和最常執行的安全活動。Nessus 工具使最終用戶能夠快速有效地執行這類安全測試。

Nessus 是一個廣泛使用的漏洞評估工具,《Learning Nessus for Penetration Testing》為您提供了對該工具使用的全面見解。本書是一本逐步指南,將教您有關 Nessus 漏洞掃描器工具中各種可用選項的知識,以便您能夠快速有效地進行漏洞評估,幫助識別 IT 基礎設施中的暴露。本書還將讓您了解滲透測試以及如何使用 Nessus 進行合規性檢查。

本書首先介紹漏洞評估和滲透測試,然後展示在 Windows 和 Linux 平台上安裝 Nessus 所需的步驟。

在本書的過程中,您將學習 Nessus 中可用的各種管理選項,例如如何創建新用戶。您還將了解重要概念,如如何分析結果以消除假陽性和關鍵性。在本書的最後,您還將了解 Nessus 的合規性檢查功能,並了解其與常規漏洞掃描的不同之處。

《Learning Nessus for Penetration Testing》教您如何有效地使用 Nessus 執行漏洞評估和滲透測試,以保護您的 IT 基礎設施並有效滿足合規性要求。

您將從本書中學到的內容
- 了解漏洞評估和滲透測試的基本概念
- 在 Windows 和 Linux 平台上安裝 Nessus
- 根據您掃描的基礎設施類型設置掃描策略
- 通過選擇正確的策略和選項來配置掃描
- 了解有憑證掃描和無憑證掃描之間的區別
- 從嚴重性、適用性和假陽性角度分析結果
- 使用 Nessus 輸出執行滲透測試
- 使用 Nessus 進行合規性檢查,並了解合規性檢查與漏洞評估之間的區別

方法
本書是一個友好的教程,使用多個實際掃描和利用過程的例子,幫助您走上成為專業滲透測試者的道路。

本書的讀者對象
《Learning Nessus for Penetration Testing》非常適合希望學習如何使用 Nessus 進行漏洞評估,以快速有效地識別 IT 基礎設施中的漏洞的安全專業人士和網絡管理員。