4 ms·
Yes it’s unfortunately standard for expensive scanners too. Our goal was to make something easy to run and deploy with similar results to something like openva
by ejcx 7y ago
Yes it’s unfortunately standard for expensive scanners too.
Our goal was to make something easy to run and deploy with similar results to something like openvas or Nessus.
I personally think accuracy issues are because security vendors don’t want to show that their expensive software found nothing, so they dial down the accuracy. This works using the same methods as a Nessus, banner grabbing and indexing issues.
We are going to keep working on this and look for ways to make it more accurate, but I’d say our results with this versus our expensive scanners was pretty much the same.
- thaumaturgy 7y agoYeah. FWIW those openvas reports really satisfied the C-level itch to have some kind of work product in the form of an official-looking report, and your looks identical. Overall you seem to have built an awesome toolkit to start with. Greenbone is a total pain to get working initially and openvas updates are broken out-of-the-box. If I were still doing this kind of stuff I'd be immediately trying out Flan Scan.
- jascii 7y ago"I personally think accuracy issues are because security vendors don’t want to show that their expensive software found nothing" That might be a bit cynical, not sure I'd call openvas expensive.. I think it comes down to the fact that the damage of a single false negative can far outweigh the cost of the false positives. In the end, these scanners are mostly a tool to help document your security efforts, often for compliance reasons, making you think about and document the choices you make from a security perspective.
- ejcx 7y agoDefinitely a little cynical =]. I think the same thing about a lot of 3rd party security consulting. OpenVAS is free, but the big issue we've had with it is the complexity of setting it up and maintaining it. We are a security team, and would rather not spend our time managing servers, especially since we aren't the best people to do that at Cloudflare.
- bostik 7y agoYeah, OpenVAS is a nasty piece of work to set up and operate reliably. Especially headless. Shameless plug: I got it to work. Will be doing a talk about the experience at week's DC4420 meeting.
- papower 7y agoAre you in a position to share that session online or perhaps a blog post on your experience and approach ? I've looked at it (openvas), got something working, but was never happy with it and ended up returning to a simpler/proven nmap base that I could manage better and add complexity if/when needed.
- bostik 7y agoI was planning to do a blog post in about a month's time. The DC4420 meetings and/or talks are not recorded (luckily!), but I intend to polish the talk up for a future re-run. On the other hand.. I do have something that might be enough to get you going. The setup we built is open: https://github.com/smarkets/vuln-scanner https://github.com/smarkets/vuln-scanner - go have a look. The glue code has comments on some of the stranger bugs I had to work around. So does the readme. If something isn't clear, feel free to ask.
- papower 7y agoThanks, looks promising. One of my challanges was understanding the the zoo of tests OpenVAS would run and trying to reliably select which ones to apply. Did you, or anyone here, ever spot a way of outputting all the tests (nmap scripts etc.) that a particular run would trigger (but without actually running them)
- bostik 7y agoSadly no. We tried to figure out a way to reliably and permanently disable a whole suit of test scripts, but that got surprisingly fiddly. I think there might be a way to choose categories to include/exclude but haven't had the time to actually investigate.
- brightball 7y agoThis is accurate. Various types of scanners and sensors are standard requirements for even the most basic SOC2.