老熟女激烈的高潮_日韩一级黄色录像_亚洲1区2区3区视频_精品少妇一区二区三区在线播放_国产欧美日产久久_午夜福利精品导航凹凸

重慶分公司,新征程啟航

為企業提供網站建設、域名注冊、服務器等服務

ubuntu14.04編譯安裝openvas8

去年在centos 6.4上面yum裝了openvas,結果掃描的時候,客戶端經常掛掉,囧。openvas對centos的支持很不好,在centos 6.4重新yum又安裝不上了,編譯也是各種依賴需要export。終于還是放棄了centos 6.4,在ubuntu上編譯安裝。

創新互聯公司專注為客戶提供全方位的互聯網綜合服務,包含不限于成都網站建設、網站設計、八宿網絡推廣、成都微信小程序、八宿網絡營銷、八宿企業策劃、八宿品牌公關、搜索引擎seo、人物專訪、企業宣傳片、企業代運營等,從售前售中售后,我們都將竭誠為您服務,您的肯定,是我們最大的嘉獎;創新互聯公司為所有大學生創業者提供八宿建站搭建服務,24小時服務熱線:18980820575,官方網址:www.cdcxhl.com

一、準備工作

1. 系統環境

root@bob-Openvas:~# lsb_release -a

Ubuntu 14.04.4 LTS

2.安裝依賴包

root@bob-Openvas:~# apt-get update

root@bob-Openvas:~# apt-get install openssh-server

root@bob-Openvas:~# apt-get install lrzsz

root@bob-Openvas:~# apt-get install build-essential bison flex cmake pkg-config libglib2.0-0 libglib2.0-dev

root@bob-Openvas:~# apt-get install libgnutls-dev

root@bob-Openvas:~# apt-get install libgnutls28-dev

root@bob-Openvas:~# apt-get install libpcap0.8 libpcap0.8-dev libgpgme11 libgpgme11-dev doxygen libuuid1 uuid-dev sqlfairy xmltoman sqlite3

root@bob-Openvas:~# apt-get install libxml2-dev libxslt1.1 libxslt1-dev xsltproc libmicrohttpd-dev libsqlite3-dev rsync libldap2-dev libhiredis-dev

root@bob-Openvas:~# apt-get install libgcrypt-dev zlib1g-dev libssh-dev

3.openvas包下載

http://www.openvas.org/install-source.html

(1)libraries:openvas庫文件

openvas-libraries-8.0.7.tar.gz

(2)scanner:掃描器 負責調用各種漏洞檢測插件,完成實際的掃描操作。

openvas-scanner-5.0.5.tar.gz

(3)manager:管理器 負責分配掃描任務,并根據掃描結果生產評估報告。

openvas-manager-6.0.8.tar.gz

(4)gsa:前端web ui 負責提供訪問openvas服務層的web接口,便于通過瀏覽器來執行掃描任務,是使用最簡便的客戶層組件。

greenbone-security-assistant-6.0.10.tar.gz

(5)openvas-cli(命令行接口):負責提供從命令行訪問OpenVAS服務層程序。

openvas-cli-1.4.4.tar.gz

二、編譯安裝

1.安裝libraries

root@bob-Openvas:~# tar -xf openvas-libraries-8.0.7.tar.gz

root@bob-Openvas:~# cd openvas-libraries-8.0.7/

root@bob-Openvas:~/openvas/openvas-libraries-8.0.7# mkdir build

root@bob-Openvas:~/openvas/openvas-libraries-8.0.7# cd build/

root@bob-Openvas:~/openvas/openvas-libraries-8.0.7/build# cmake ..

root@bob-Openvas:~/openvas/openvas-libraries-8.0.7/build# make

root@bob-Openvas:~/openvas/openvas-libraries-8.0.7/build# make doc-full

root@bob-Openvas:~/openvas/openvas-libraries-8.0.7/build# make install

root@bob-Openvas:~/openvas/openvas-libraries-8.0.7/build# cd ../../

2.安裝scanner方法同上,后面安裝方法都一樣

openvas-scanner-5.0.5.tar.gz

3.創建cert

root@bob-Openvas:~# openvas-mkcert

cert存放位置

/usr/local/var/lib/openvas/private/CA

/usr/local/var/lib/openvas/CA

4.重載libraries,重載的是libopenvas_nasl.so.8

root@bob-Openvas:~# ldconfig

5.同步nvt,nvt插件目錄。NVT collection in /usr/local/var/lib/openvas/plugins contains 38966 NVTs.

root@bob-Openvas:~# openvas-nvt-sync   

...

...

zone_alarm_local_dos.nasl

zone_alarm_local_dos.nasl.asc

[i] Download complete

[i] Checking dir: ok

[i] Checking MD5 checksum: ok

6.安裝redis-2.8.4,scanner啟動前還需要運行一個redis服務,用于緩沖

root@bob-Openvas:~# apt-get install redis-server

root@bob-Openvas:~# netstat -lanpt |grep 6379

tcp        0      0 127.0.0.1:6379          0.0.0.0:*               LISTEN      3602/redis-server 1

root@bob-Openvas:~# cp /etc/redis/redis.conf{,.bak}

root@bob-Openvas:~# /etc/init.d/redis-server stop

Stopping redis-server: redis-server.

添加下面2行,不添加后面會報錯

root@bob-Openvas:~# vim /etc/redis/redis.conf

unixsocket /tmp/redis.sock

unixsocketperm 700

root@bob-Openvas:~# /etc/init.d/redis-server start

root@bob-Openvas:~# netstat -lanpt |grep 6379

tcp        0      0 127.0.0.1:6379          0.0.0.0:*               LISTEN      3602/redis-server 1

7.啟動scanner命令openvassd

scanner監聽9391端口,需要說明的是scanner啟動成功后,manager可以扮演客戶端的角色與scanner交互,對scanner進行控制,真正的客戶端如命令行cli、webui(gsa)只能與manager進行交互,不能越過manager操作scanner。

root@bob-Openvas:~# openvassd 

root@bob-Openvas:~# netstat -lanpt |grep 939

tcp        0      0 0.0.0.0:9391            0.0.0.0:*               LISTEN      3949/ ETA: 00:40)

8.安裝manager

openvas-manager-6.0.8.tar.gz

9.manager啟動后需要與scanner通信,scanner是服務端,manager是客戶端,在scanner的“配置與啟動”階段,我們已經為scanner生成了SSL相關的證書和私鑰文件,

說明manager可以進行服務端驗證,但是scanner也要求對manager進行客戶端驗證,所以也需要為mananger生成SSL相關的證書和私鑰文件。

10.下載scap feed.下載時間超級長,網速快的時候80分鐘,網速慢的時候可能就要一天

root@bob-Openvas:~# openvas-scapdata-sync

11.下載cert feed

root@bob-Openvas:~# openvas-certdata-sync

12.執行下面命令生成client證書和私鑰

root@bob-Openvas:~# openvas-mkcert-client -n -i

root@bob-Openvas:~# ls -l /usr/local/var/lib/openvas/private/CA

total 12

-rw------- 1 root root 3247  7月 30 16:59 cakey.pem

-rw------- 1 root root 3247  7月 30 20:08 clientkey.pem

-rw------- 1 root root 3247  7月 30 16:59 serverkey.pem

root@bob-Openvas:~# ls -l /usr/local/var/lib/openvas/CA

total 24

-rw-r--r-- 1 root root 2451  7月 30 16:59 cacert.pem

-rw------- 1 root root 7931  7月 30 20:08 clientcert.pem

-rw-r--r-- 1 root root 8229  7月 30 16:59 servercert.pem

######################################################################################################################

上述兩步也可以通過執行openvas-mkcert-client生成證書和私鑰:

root@bob-Openvas:~# openvas-mkcert-client 

然后將證書和私鑰從臨時目錄拷貝到相應目錄下

root@bob-Openvas:~# cp /tmp/openvas-mkcert-client.4501/key_om.pem /usr/local/var/lib/openvas/private/CA/clientkey.pem

root@bob-Openvas:~# cp /tmp/openvas-mkcert-client.4501/cert_om.pem /usr/local/var/lib/openvas/CA/clientcert.pem

######################################################################################################################

13.初始化數據庫。scanner openvassd 9391端口啟動,才能重建數據庫成功。否則報錯Rebuilding NVT cache... failed.

root@bob-Openvas:~# openvasmd --rebuild --progress -v

Rebuilding NVT cache... done.

root@bob-Openvas:~# openvasmd -p 9390 -a 127.0.0.1

root@bob-Openvas:~# netstat -lanpt |grep 939

tcp        0      0 127.0.0.1:9390          0.0.0.0:*               LISTEN      4836/openvasmd  

tcp        0      0 0.0.0.0:9391 

14.創建帳號bob

root@bob-Openvas:~# openvasmd --create-user=bob --role=Admin  

User created with password '23c65192-2fa7-4aab-aa8d-6c9df701314c'.

15.更改帳號bob的密碼

root@bob-Openvas:~# openvasmd --user=bob --new-password=XXXXXXX 

16.安裝cli,cli是一個命令行工具,作為客戶端的omp,它可以運行在windows或linux上

openvas-cli-1.4.4.tar.gz 

17.安裝gsad  

greenbone-security-assistant-6.0.10.tar.gz  

18.啟動gsad。通過設置IP地址為0.0.0.0使服務可以通過其他機器進行訪問

root@bob-Openvas:~# gsad --listen=0.0.0.0 -p 9392

root@bob-Openvas:~# netstat -lanpt |grep 939

tcp        0      0 127.0.0.1:9390          0.0.0.0:*               LISTEN      4836/openvasmd  

tcp        0      0 0.0.0.0:9391            0.0.0.0:*               LISTEN      3949/openvassd: Wai

tcp        0      0 0.0.0.0:9392            0.0.0.0:*               LISTEN      5580/gsad 

19.安裝nmap-5.51.tar.bz2

gsad日志報錯,掃描沒有任何結果。是因為nmap沒安裝

root@bob-Openvas:~# ./configure && make && make install

20.導出pdf格式報告需要安裝texlive-full

root@bob-Openvas:~# apt-get install texlive-full

21.下載腳本測試

root@bob-Openvas:~# wget https://svn.wald.intevation.org/svn/openvas/trunk/tools/openvas-check-setup --no-check-certificate

root@bob-Openvas:~# /root/openvas/openvas-check-setup --v8 --server

openvas-check-setup 2.3.3

  Test completeness and readiness of OpenVAS-8

  (add '--v6' or '--v7' or '--v9'

   if you want to check for another OpenVAS version)

  Please report us any non-detected problems and

  help us to improve this check routine:

  http://lists.wald.intevation.org/mailman/listinfo/openvas-discuss

  Send us the log-file (/tmp/openvas-check-setup.log) to help analyze the problem.

Step 1: Checking OpenVAS Scanner ... 

        OK: OpenVAS Scanner is present in version 5.0.5.

        OK: OpenVAS Scanner CA Certificate is present as /usr/local/var/lib/openvas/CA/cacert.pem.

        OK: redis-server is present in version v=2.8.4.

        OK: scanner (kb_location setting) is configured properly using the redis-server socket: /tmp/redis.sock

        OK: redis-server is running and listening on socket: /tmp/redis.sock.

        OK: redis-server configuration is OK and redis-server is running.

        OK: NVT collection in /usr/local/var/lib/openvas/plugins contains 38966 NVTs.

        WARNING: Signature checking of NVTs is not enabled in OpenVAS Scanner.

        SUGGEST: Enable signature checking (see http://www.openvas.org/trusted-nvts.html).

        OK: The NVT cache in /usr/local/var/cache/openvas contains 38966 files for 38966 NVTs.

Step 2: Checking OpenVAS Manager ... 

        OK: OpenVAS Manager is present in version 6.0.8.

        OK: OpenVAS Manager client certificate is present as /usr/local/var/lib/openvas/CA/clientcert.pem.

        OK: OpenVAS Manager database found in /usr/local/var/lib/openvas/mgr/tasks.db.

        OK: Access rights for the OpenVAS Manager database are correct.

        OK: sqlite3 found, extended checks of the OpenVAS Manager installation enabled.

        OK: OpenVAS Manager database is at revision 146.

        OK: OpenVAS Manager expects database at revision 146.

        OK: Database schema is up to date.

        OK: OpenVAS Manager database contains information about 38966 NVTs.

        OK: At least one user exists.

        OK: OpenVAS SCAP database found in /usr/local/var/lib/openvas/scap-data/scap.db.

        OK: OpenVAS CERT database found in /usr/local/var/lib/openvas/cert-data/cert.db.

        OK: xsltproc found.

Step 3: Checking user configuration ... 

        WARNING: Your password policy is empty.

        SUGGEST: Edit the /usr/local/etc/openvas/pwpolicy.conf file to set a password policy.

Step 4: Checking Greenbone Security Assistant (GSA) ... 

        OK: Greenbone Security Assistant is present in version 6.0.10.

Step 5: Checking OpenVAS CLI ... 

        OK: OpenVAS CLI version 1.4.4.

Step 6: Checking Greenbone Security Desktop (GSD) ... 

        SKIP: Skipping check for Greenbone Security Desktop.

Step 7: Checking if OpenVAS services are up and running ... 

        OK: netstat found, extended checks of the OpenVAS services enabled.

        OK: OpenVAS Scanner is running and listening on all interfaces.

        OK: OpenVAS Scanner is listening on port 9391, which is the default port.

        OK: OpenVAS Manager is running and listening on all interfaces.

        OK: OpenVAS Manager is listening on port 9390, which is the default port.

        OK: Greenbone Security Assistant is running and listening on all interfaces.

        OK: Greenbone Security Assistant is listening on port 9392, which is the default port.

Step 8: Checking nmap installation ...

        OK: nmap is present in version 5.51.

Step 10: Checking presence of optional tools ...

        OK: pdflatex found.

        OK: PDF generation successful. The PDF report format is likely to work.

        OK: ssh-keygen found, LSC credential generation for GNU/Linux targets is likely to work.

        OK: rpm found, LSC credential package generation for RPM based targets is likely to work.

        OK: alien found, LSC credential package generation for DEB based targets is likely to work.

        OK: nsis found, LSC credential package generation for Microsoft Windows targets is likely to work.

It seems like your OpenVAS-8 installation is OK.

If you think it is not OK, please report your observation

and help us to improve this check routine:

http://lists.wald.intevation.org/mailman/listinfo/openvas-discuss

Please attach the log-file (/tmp/openvas-check-setup.log) to help us analyze the problem.

22.web訪問openvas,ubuntu 14.04裝出來是英文界面

https://127.0.0.1:9392

ubuntu 14.04編譯安裝openvas 8

三、開機自啟動openvas腳本。因為是編譯安裝的,開機不會自啟動,寫了個小腳本

openvas開機自啟動

root@bob-Openvas:~# vim /home/bob/openvas_server_start.sh 

#!/bin/bash

 

/usr/local/sbin/openvassd 

/usr/local/sbin/openvasmd -p 9390 -a 127.0.0.1 

/usr/local/sbin/gsad --listen=0.0.0.0 -p 9392

四、安裝中遇到的問題以及解決辦法

問題1

root@bob-Openvas:~# /root/openvas/openvas-check-setup --v8 --server

ERROR: redis-server is not running or not listening on socket: /tmp/redis.sock

FIX: You should start the redis-server or configure it to listen on socket: /tmp/redis.sock

ERROR: The number of NVTs in the OpenVAS Manager database is too low.

FIX: Make sure OpenVAS Scanner is running with an up-to-date NVT collection and run 'openvasmd --rebuild'.

ERROR: No OpenVAS SCAP database found. (Tried: /usr/local/var/lib/openvas/scap-data/scap.db)

FIX: Run a SCAP synchronization script like openvas-scapdata-sync or greenbone-scapdata-sync.

問題2

測試rsync.openvas.org 873端口是不是通的,通了之后才能執行openvas-nvt-sync openvas-scapdata-sync  greenbone-scapdata-sync

root@bob-Openvas:~# telnet rsync.openvas.org rsync

Trying 78.47.251.61...

Connected to openvas-feed.intevation.org.

Escape character is '^]'.

問題3

如果rsync.openvas.org 873端口不通,可以離線安裝,在網上下載feed之后(直接到已經更新了資源的機器上拷貝對應的文件到自己機器上),拷貝到這些目錄即可

openvas插件庫下載,拷貝到下面目錄,重啟openvas

root@bob-Openvas:~# wget http://www.openvas.org/openvas-nvt-feed-current.tar.bz2

/usr/local/var/lib/openvas/plugins

/usr/local/var/lib/openvas/cert-data

/usr/local/var/lib/openvas/scap-data

問題4

openvas日志目錄

root@bob-Openvas:~# ls -lh /usr/local/var/log/openvas/

total 24K

-rw-r--r-- 1 root root 1.4K  7月 29 17:39 gsad.log

-rw------- 1 root root  15K  7月 30 13:10 openvasmd.log

-rw-r--r-- 1 root root  559  7月 30 13:22 openvassd.messages


文章名稱:ubuntu14.04編譯安裝openvas8
網頁網址:http://www.xueling.net.cn/article/joppjs.html

其他資訊

在線咨詢
服務熱線
服務熱線:028-86922220
TOP
主站蜘蛛池模板: 久久久6精品成人午夜51777 | 欧美特黄aaa | 黄色免费av | 无码成人午夜在线观看 | 欧美午夜精品久久久久久人妖 | av免费在线播放网站 | 亚洲欧美一区二区精品中文字幕 | 超碰在线进入 | 日本v片| 天堂久久久久 | 69精品人人槡人妻人人玩 | 久久视频这里有精品 | 噜噜噜综合亚洲 | 精品免费国产一区二区三区四区介绍 | 国语自产一区第二页欧美 | 久久se精品一区精品二区 | 噜噜噜噜私人影院 | 色综合色欲色综合色综合色乛 | 亚洲另类在线视频 | 国产孕妇视频在线播放 | 久久久一本精品99久久K精品66 | 国产精品日本一区二区在线播放 | www.黄色免费网站 | 日韩中文字幕a | 欧美videosdesexo吹潮 | 精品国产一区二区三区蜜殿 | 亚洲人成人一区二区三区 | 亚洲欧美清纯校园另类 | 国产妇女馒头高清泬20P多 | 国产视频在线观看免费 | 国产成人久久精品77777 | 免费观看av | 中文字幕国产区 | 她似遥上月短剧免费观看 | 精品国产天线2024 | 国产毛片久久久久久国产毛片 | 铠甲勇士全52集免费播放 | 午夜小片 | 亚洲另类视频 | 亚洲精品99久久久久久 | 亚洲人成色4444在线观看 |