Page 1 of 1

openvas???

Posted: Wed Aug 26, 2009 8:24 pm
by DarkF@der
What is openvas ???

is it a security scanner?


do i have to install this to get better secured?

Re: openvas???

Posted: Thu Aug 27, 2009 8:24 am
by scott
It is the open source fork of Nessus (http://www.nessus.org), you can read more about it here: http://www.openvas.org

We'll be including it in an ASL module in the next few months. You can check it out now from the atomic repo, you'll find that this and/or nessus is what PCI DSS auditors are using to scan your systems for compliance. Its a great way to get ahead of those checks so nothing they tell you is a surprise, or on the other side you'll have the information you need to refute their findings.

Re: openvas???

Posted: Thu Aug 27, 2009 9:57 am
by biggles
I am pretty sure the URL to Tenable is http://www.tenablesecurity.com/ 8)

Re: openvas???

Posted: Thu Aug 27, 2009 11:15 am
by scott
No it really is Nessus.org, even though its not an open source project any more. I believe you can use it for personal use, but we (Atomicorp/ART) are not allowed to redistribute 3.0 and up since they changed the license. OpenVAS is based on the 2.2 series, and has gone through a considerable amount of growth in the last few years. Its GPL'd so there are no issues with sharing it.