ThreatProtectionTestingLab3RunningTenableNessusScanAgainstWindows7VM

docx

School

Full Sail University *

*We aren’t endorsed by this school

Course

CYB4381

Subject

Information Systems

Date

Feb 20, 2024

Type

docx

Pages

5

Uploaded by JusticeMink2465

Report
Threat Protection & Testing Lab 3 – Running Tenable Nessus Scan Against Windows 7 VM 1. Login into FullSail lab environment 2. IMPORTANT NOTE: a. Please use https://www.tenable.com/products/nessus/nessus- essentials to activate the Nessus scanner and use the activation code to start/initiate the Nessus service. b. You can get to Nessus by doing the following from Kali... c. Open your Internet browser in Kali and go to https://<your Nessus scanner ip>:8834/#/ and to check the configuration area https://<your Nessus scanner ip>:8000/ d. The Nessus VM will get its IP address from the firewall VM and you should be able to find it in the Proxmox settings in the lab environment when selecting the Nessus VM in the list. 3. Browse to your Kali VM after turning on the Nessus VM a. Open your Internet browser in Kali and go to https://<your Nessus scanner ip>:8834/#/ and to check the configuration area https://<your Nessus scanner ip>:8000/ b. The Nessus VM will get its IP address from the firewall VM and you should be able to find it in the Proxmox settings in the lab environment when selecting the Nessus VM in the list.
c. Obtain the local IP address of the Windows 7 VM 4. Perform a Nessus scan against the Windows 7 VM. a. Click on the “New Scan” button in the top right on the Nessus Essentials console. 5. Choose the “Basic Network Scan” option.
6. In the settings area of the new scan provide a name for your scan and apply the Windows 7 IP to the targets section of the configuration scan window. 7. Next, “Save” the scan configuration.
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
  • Access to all documents
  • Unlimited textbook solutions
  • 24/7 expert homework help
8. Find you newly created scan by looking for the scan title name and then launch the scan. 9. Wait for the Nessus scan to complete and identify the MS17-010 Eternalblue vulnerability. 10. Review the CVEs associated with EternalBlue and provide the following information for each CVE in the detected EternalBlue vulnerability findings.
o Attack Vector o Attack Complexity o Privileges Required o User Interaction o Scope o Confidentiality o Integrity o Availability 11. Provide the CVE information in a Word document and save it with first name_last_name_Threat Protection & Testing_Week 2_Lab3. 12. Upload the document to FSO for a grade.