[unisog] Re: Nessus Scanning

Lina C Pezzella LINA.PEZZELLA at huskymail.uconn.edu
Tue May 11 03:09:20 GMT 2004


We are also using the same setup at UCONN -- running nessus jobs with cron and using a simple perl script to parse the .nbe files and upload them to a database.  The howto for all of our nessus scans can be found at: http://hogwash.uits.uconn.edu/?page=/nessus.html

Many of the auto-generated reports also found on that page are passworded since they contain vulnerable ip addresses, but the "Progress" reports are open, since they are just statistics.  Feel free to email me if you are interested in any of the web scripts.

Lina Pezzella
University of Connecticut
Network Security

----- Original Message -----
From: Frank Sweetser <fs at wpi.edu>
Date: Monday, May 10, 2004 4:47 pm
Subject: Re: [unisog] Re: Nessus Scanning

> On Tue, May 11, 2004 at 08:28:25AM +1200, Russell Fulton wrote:
> > I'd also be very interested in such a list, particularly if 
> someone was
> > regularly maintaining it.  
> > 
> > Also has anyone written a script to extract out the vital 
> information> from all the fluff that nessus provides.  My guess is 
> that by far the
> > easiest way would be to get nessus to write an xml report and use 
> the> perl nessus modules to parse it. 
> 
> I've actually got a setup doing this right now.  It generates a 
> nessus config
> based on a skeleton, runs it against our list of registered hosts, 
> parses the
> nbe files, and stuffs them into a sql database.  Sho has started 
> work on a
> simple web front end (looks remarkably like placid ;), and I have 
> it emailing
> text summaries out to owner/admins based on IP ranges.  I can clean 
> up and
> post a copy if anyone is interested.
> 
> -- 
> Frank Sweetser fs at wpi.edu
> WPI Network Engineer
> GPG fingerprint = 6174 1257 129E 0D21 D8D4  E8A3 8E39 29E3 E2E8 8CEC
> 
> _______________________________________________
> unisog mailing list
> unisog at lists.sans.org
> http://www.dshield.org/mailman/listinfo/unisog
> 




More information about the unisog mailing list