﻿{"id":182,"date":"2020-06-08T08:27:44","date_gmt":"2020-06-08T00:27:44","guid":{"rendered":"https:\/\/byy3.com\/?p=182"},"modified":"2020-06-09T05:28:38","modified_gmt":"2020-06-08T21:28:38","slug":"rpnessus","status":"publish","type":"post","link":"https:\/\/byy3.com\/?p=182","title":{"rendered":"RP:Nessus"},"content":{"rendered":"\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/849\/1*PzZ0nn4cc8Sz8kCXaiMxmw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe\" alt=\"RP:Nessus\u63d2\u56fe\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>[Task 1] Deploy!<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>[Task 2] Installation<br><\/strong>After installation, open nessus<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">sudo \/etc\/init.d\/nessusd start<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/949\/1*VM2eYBnSZhaNS5zqkgA0ag.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe1\" alt=\"RP:Nessus\u63d2\u56fe1\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Open browser and type<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/localhost:8834\/\" target=\"_blank\" rel=\"noreferrer noopener\" rel=\"nofollow\" >https:\/\/localhost:8834\/<\/a><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Select Nessus Essentials and click continue<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/939\/1*78aSQSF5cfQdl-doHQnUZw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe2\" alt=\"RP:Nessus\u63d2\u56fe2\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Input activation code<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/470\/1*6jbxHByGzkq6YjEDlFqgMQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe3\" alt=\"RP:Nessus\u63d2\u56fe3\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Create user account<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/518\/1*0MHfJ5zm47_a1_maCVv3yg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe4\" alt=\"RP:Nessus\u63d2\u56fe4\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">After finish installation, login with credential<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/516\/1*e5Y_84FWFlE2-yPOl0BCBw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe5\" alt=\"RP:Nessus\u63d2\u56fe5\" \/><\/figure>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>[Task 3] Nessus Quiz<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>As we log into Nessus, we are greeted with a button to launch a scan, what is the name of this button?<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1613\/1*ih0kieAKHagAqNVC9TYqnw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe6\" alt=\"RP:Nessus\u63d2\u56fe6\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>New Scan<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">2. Nessus allows us to create custom templates that can be used during the scan selection as additional scan types, what is the name of the menu where we can set these?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1260\/1*Xbilpd5hWMbzdYP4CLXWFg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe7\" alt=\"RP:Nessus\u63d2\u56fe7\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Policies<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">3. Nessus also allows us to change plugin properties such as hiding them or changing their severity, what menu allows us to change this?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1226\/1*9Rl5lp76YHrBEYAXYJEyEA.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe8\" alt=\"RP:Nessus\u63d2\u56fe8\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Plugin Rules<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">4. Nessus can also be run through multiple \u2018Scanners\u2019 where multiple installations can work together to complete scans or run scans on remote networks, what menu allows us to see all of these installations?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1531\/1*ypA_YHrMmP4gtFLEciU1hA.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe9\" alt=\"RP:Nessus\u63d2\u56fe9\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scanners<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">5. Let\u2019s move onto the scan types, what scan allows us to see simply what hosts are \u2018alive\u2019?<br>Click New Scan<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1588\/1*Gljd_RfDnx48nQBJzU1LnQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe10\" alt=\"RP:Nessus\u63d2\u56fe10\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1108\/1*GnjW7mP-6HPwa9h8YpKIkw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe11\" alt=\"RP:Nessus\u63d2\u56fe11\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Host Discovery<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">6. One of the most useful scan types, which is considered to be \u2018suitable for any host\u2019?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/665\/1*xCS28YXnC4sg2oSpWbuudw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe12\" alt=\"RP:Nessus\u63d2\u56fe12\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Basic Network Scan<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">7. Following a few basic scans, it\u2019s often useful to run a scan wherein the scanner can authenticate to systems and evaluate their patching level. What scan allows you to do this?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/881\/1*jVFYTnCG23TQMfElP4lbSg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe13\" alt=\"RP:Nessus\u63d2\u56fe13\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Credential Patch Audit<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">8. When performing Web App tests it\u2019s often useful to run which scan? This can be incredibly useful when also using nitko, zap, and burp to gain a full picture of an application.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/893\/1*IkkAeN4C6gYc0y53Ctxzow.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe14\" alt=\"RP:Nessus\u63d2\u56fe14\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Web Application Tests<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>[Task 4] Scanning!<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Deploy the machine and connect to the network<\/li><li>Create a new \u2018Basic Network Scan\u2019 targeting the deployed VM. What option can we set under \u2018BASIC\u2019 to set a time for this scan to run? This can be very useful when network congestion is an issue.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Click Basic Network Scan, and type the name and target<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1159\/1*fK5oYPnWRcT4NhtsN82Dmg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe15\" alt=\"RP:Nessus\u63d2\u56fe15\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Click Schedule and Enabled<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1281\/1*Xgqc_bp14jpmSw54C1bYFA.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe16\" alt=\"RP:Nessus\u63d2\u56fe16\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Schedule<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">3. Under discovery set the scan to cover ports 1\u201365535. What is this type called?<br>Click Discovery and select scan type<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1099\/1*OhnKLSizot75utVIpxr66A.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe17\" alt=\"RP:Nessus\u63d2\u56fe17\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Port Scan\uff08all ports\uff09<\/strong> ***attention ()<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">4. As we are connected to the network via a VPN, it may be to our benefit to \u2018tone down\u2019 the scan a bit. What scan type can we change to under \u2018ADVANCED\u2019 for this lower bandwidth connection?<br>Click ADVANCED, select scan type<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/955\/1*HSasiECZbrX090D4JuycNQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe18\" alt=\"RP:Nessus\u63d2\u56fe18\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>scan low bandwidth links<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">5. With these options set (other than the time to run) save and launch the scan.<br>Launch the scan<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1416\/1*Gw9lTPPVch10Hm7PZ0Ns7g.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe19\" alt=\"RP:Nessus\u63d2\u56fe19\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1348\/1*PjM18PExnosCZxTY0Hb31w.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe20\" alt=\"RP:Nessus\u63d2\u56fe20\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Wait the for scan to finish<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">6. After the scan completes, which \u2018Vulnerability\u2019 can we view the details of to see the open ports on this host?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/921\/1*8YeK3CNOcOmPBKFLRd0-RA.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe21\" alt=\"RP:Nessus\u63d2\u56fe21\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/528\/1*tuh_pCvAt91F1NqGXtwSXw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe22\" alt=\"RP:Nessus\u63d2\u56fe22\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Nessus SYN scanner<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">7. There seems to be a chat server running on this machine, what port is it on?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/958\/1*zYgip9xoFDmgejWxcuZUPA.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe23\" alt=\"RP:Nessus\u63d2\u56fe23\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/886\/1*Y8620KGS7iwzSlzPqN0h9A.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe24\" alt=\"RP:Nessus\u63d2\u56fe24\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>6667<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">8. Looks like we have a medium level vulnerability relating to SSH, what is this vulnerability named?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/905\/1*2MxOWlneB2dCWs266AILog.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe25\" alt=\"RP:Nessus\u63d2\u56fe25\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/909\/1*7kgwdOorM5dN8izXX1qlBQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe26\" alt=\"RP:Nessus\u63d2\u56fe26\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/926\/1*08ah-FhXAYukjhmEf_20mg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe27\" alt=\"RP:Nessus\u63d2\u56fe27\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>SSH Weak Algorithms Supported<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">9. What web server type and version is reported by Nessus?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/889\/1*t9K4ijOKbXj3BBgyiDVvVg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe28\" alt=\"RP:Nessus\u63d2\u56fe28\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/910\/1*SMbOPTOrQscBpWJyOeYnQQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe29\" alt=\"RP:Nessus\u63d2\u56fe29\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/928\/1*ceV8i6qdRFdwGDmSZ-bkdQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe30\" alt=\"RP:Nessus\u63d2\u56fe30\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Apache\/2.4.99<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>[Task 5] Wait, there\u2019s mail?<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>An optional but awesome additional step, link your Nessus box up to an SMTP server via the Settings panel. Google provides this for free if you already have a Gmail account. Adding 2-factor authentication on your account and create an app password, then link Nessus to the Gmail SMTP server via these following settings:&nbsp;<a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.siteground.com\/kb\/google_free_smtp_server\/\" target=\"_blank\" rel=\"noreferrer noopener\" rel=\"nofollow\" >https:\/\/www.siteground.com\/kb\/google_free_smtp_server\/<\/a><\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Skipped<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>[Task 6] So you\u2019re telling me that\u2019s how you set up a web app\u2026<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Run a web application scan against this new box.<br>Click new scan<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/796\/1*1RQT9YK7IBgbG9ZxfVK2jQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe31\" alt=\"RP:Nessus\u63d2\u56fe31\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Click Web Application Tests, set up scan settings, and start<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/749\/1*-EE1F_QY_sHy3a1Tal7ORg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe32\" alt=\"RP:Nessus\u63d2\u56fe32\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">2. What is the plugin id of the plugin that determines the HTTP server type and version?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/854\/1*YlKLoFe5yhkx-dfWflKiAw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe33\" alt=\"RP:Nessus\u63d2\u56fe33\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1311\/1*3FUFQrdHcuWhtUxOnkxz0A.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe34\" alt=\"RP:Nessus\u63d2\u56fe34\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>10107<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">3. What authentication page is discovered by the scanner that transmits credentials in cleartext?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/871\/1*O5bj762Ar2lnvZOUmXsSzQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe35\" alt=\"RP:Nessus\u63d2\u56fe35\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/868\/1*qTUHZ2-K2dZiKs-UzfTUrQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe36\" alt=\"RP:Nessus\u63d2\u56fe36\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/916\/1*J9-kQGj-a38d1GMMiyTr-A.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe37\" alt=\"RP:Nessus\u63d2\u56fe37\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>login.php<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">4. What is the file extension of the config backup?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/899\/1*itZmhh9Cvu-_jh0kTKlKfA.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe38\" alt=\"RP:Nessus\u63d2\u56fe38\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/681\/1*iaDKEd7B80jT5TlSzMq63w.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe39\" alt=\"RP:Nessus\u63d2\u56fe39\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/478\/1*umQH0qzrilCfCmRmccF8jw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe40\" alt=\"RP:Nessus\u63d2\u56fe40\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Follow the path<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/620\/1*N9OMW0PdedY4vOBQ52MBVg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe41\" alt=\"RP:Nessus\u63d2\u56fe41\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>.bak<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">5. Which directory contains example documents? (This will be in a php directory)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Follow the path<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1040\/1*ltKp_iW-hWT0EmtBGxSF1Q.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe42\" alt=\"RP:Nessus\u63d2\u56fe42\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\/external\/phpids\/0.6\/docs\/examples\/<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">6. What vulnerability is this application susceptible to that is associated with X-Frame-Options?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/895\/1*Al9hreywtFUJ-eADRzfwSQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe43\" alt=\"RP:Nessus\u63d2\u56fe43\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/959\/1*9GYE0ujLE28b5EMtu8E4Dg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe44\" alt=\"RP:Nessus\u63d2\u56fe44\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>clickjacking<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">7. What version of php is the server using?<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/874\/1*8_11w1U4crRlr55QyV3CrQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe45\" alt=\"RP:Nessus\u63d2\u56fe45\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/888\/1*uNWeuXgr6jCY9ADYRcN3kQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe46\" alt=\"RP:Nessus\u63d2\u56fe46\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/771\/1*WR8Kf-y24ckomrEPn56uLw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"RP:Nessus\u63d2\u56fe47\" alt=\"RP:Nessus\u63d2\u56fe47\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5.5.9\u20131ubuntu4.26<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[Task 1] Deploy! [Task 2] InstallationAfter installatio [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-182","post","type-post","status-publish","format-standard","hentry","category-net-security"],"_links":{"self":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/182","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=182"}],"version-history":[{"count":0,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/182\/revisions"}],"wp:attachment":[{"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=182"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=182"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=182"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}