VIIS

qbe89

see attached..

  • 3 years ago
  • 10
files (5)

UnitVI_WINPCAPInstructions.pdf

WINPCAP Instructions

For the Windows Operating System (OS), you need to first download the WINPCAP application. To

download the application, access the following link to navigate to the WINPCAP website.

Click on the Download for

WINPCAP icon.

Download your WINPCAP

application to your desktop.

Once you have downloaded WINPCAP to your desktop, proceed to the next step.

Double-click to begin the install.

Click the Next button.

Use the scroll bar to scroll down

the menu.

Click on the I Agree button

Click on the Install button, and

WINPCAP will begin install.

Click Finish to complete the

install.

You are now ready to download your Nessus application. Refer to the Nessus Instructions.

ASSESS.docx

This presentation will highlight your understanding of public key infrastructure (PKI) and Nessus vulnerabilities.

Requirements

Create an eight-slide PowerPoint presentation. Slide requirements are listed below.

· Slide 1: Include a title slide with the following heading: PKI and Nessus Vulnerability Scanning.

· Slide 2: Provide a PKI introduction slide, and explain cryptography and how PKI works.

· Slide 3: Explain how messages are sent using PKI (use graphics and text).

· Slide 4: Explain how messages are received using PKI (use graphics and text).

· Slide 5: Provide a Nessus introduction slide, explain how Nessus works.

· Slide 6: Include a screenshot of the Nessus hosts, and provide a brief overview of the host that you found.

· Slide 7: Provide a screenshot of the Nessus vulnerabilities, and provide a brief description of how many of each vulnerability severity and why you should be concerned about the critical and high severities.

· Slide 8: Include a reference slide.

PKI

Use the slide notes function to provide a full description of the slides, explaining PKI as if the individuals you will be briefing do not know anything about PKI.

You will use your textbook, the CSU Online Library, and external websites to complete the research for your PKI slides.

Vulnerability Scan Tool

Use the slide notes function to provide a full description of the slides, explaining hosts and vulnerabilities.

You will use a popular vulnerability scanning tool called Nessus that helps to identify those vulnerabilities that hackers seek out to exploit.

Before you start, for the Windows Operating System (OS), you must download the WINPCAP first and then the Nessus.

· Access the WINPCAP (Windows OS only) instructions.

· Access the Nessus instructions.

· Access the instructions for how to use Nessus.

· If you are using a Mac, access the Mac Installation video.

· The transcript for the Mac Installation video is also available.

Please adhere to APA Style if referring to citations and references for this assignment. APA formatting, however, is not necessary.

Course Textbook(s) Whitman, M. E., & Mattord, H. J. (2022). Principles of information security (7th ed.). Cengage Learning. https://online.vitalsource.com/#/books/9780357506561

UnitVI_NessusInstructions.pdf

Nessus Instructions

To install Nessus on Windows Operating System (OS) or Mac OS, access the following link to navigate to

the Tenable website.

For Windows OS, select either

64 or 32-bit. Depending on your

OS.

Only one selection for Mac OS.

This screen will show once you begin to download. Check the I agree box, and click the download

button.

Depending on your browser, click “Save as” to save the Nessus application on your desktop.

Check to make sure your Nessus is saved on your desktop. Then, go back to the website to register for

your activation key.

Click on the “Get an Activation Code” button.

Click on “Register Now” button.

Enter your name and email address, and click Register. Make sure your email is correct, as your

activation code will be emailed to you. Also, check your Spam folder in case your email did not show in

your Inbox.

This page will show once everything is successful. There is NO NEED to DOWNLOAD Nessus, as you have

downloaded it already.

Double click on the Nessus to begin install of the application.

Click the Next button.

Check the I accept radial

button, and click on the Next

button.

If you want to change the

destination for Nessus, please

do so now. If not, click the Next

button.

Click the Install button.

Wait for Nessus to finish

installing.

Click the Finish button after

installation.

UnitVI_UsingNessus.pdf

Using Nessus

This instruction provides a quick easy step on how to use your Nessus Vulnerability Scanner. If you have

not downloaded WINPCAP (for Windows OS only), refer to the WINPCAP Instructions. Then, download

the Nessus application (refer to the Nessus Instructions).

Once you have finished installing the Nessus application, the Nessus should automatically open in your

browser.

If not, look in your applications for the Tenable Network Security folder, and you will find the Nessus

Web Client. (Below is a Windows 10 screenshot; this may be different if you have another Windows OS

version or Mac OS):

Nessus Web Client

If you receive an error such as this one

displayed. Open your favorite browser.

Type the following URL: https://localhost8834/#/

If you get this message, click on the “More Information” button.

Click on the “Go on to the webpage (not recommended)” link.

Your browser will take you to the “Welcome to Nessus” screen.

You will be asked to setup an account.

Make sure the following Registration option is selected: “Nessus (Home, Professional or Manager).”

Go to your email, and enter the “Activation Code” sent to you from the Nessus website.

Click the “Continue” Button

Nessus will begin to initialize.

Input your username and password.

The Nessus will open to the My Scans menu screen.

At the upper right of the screen click on the “New Scan” button

Once you have clicked on the “New Scan” button you will be presented with different types of

applications to use. Click on the “Basic Network Scan”

Input a scan name of your choice. Input a description.

Enter Targets: In this case, enter the IP address of your computer. 192.168.xxx.xxx

Click Save.

Check the box next to My Computer or whatever name you provided for the Name.

Then, click on the “More” button.

Scroll down to “Launch,” and click “Launch” to begin the scan.

A message will pop up to confirm if you want to launch this scan. Click the “Launch” button.

Your scan is currently running with the date of your scan. Let your scan run for at least a minimum of 5

minutes. To stop click on the “More” button and select “Stop”.

Click the “Stop” button to verify that you want to stop the scan. Then, click on the “On Demand” ribbon.

You will see the total number of scans in the blue bar. You will see three tabs in the upper left hand of

the menu: Hosts, Vulnerabilities, and History. The current screen shows the Host tab.

Click on the “Vulnerabilities Tab,” and you will be taken to the vulnerabilities screen. Note the

Vulnerabilities Legend on the bottom right hand of your screen. These color codes provide the different

severity of the vulnerability.

If you click on any of the information buttons, you will be presented with additional information for each

vulnerability.

Above is a sample of what information is provided about the vulnerability scan.

Click on the “History” tab, and this will provide you with information about the history of the scan.

You have just successfully completed a scan using Nessus. To log out, go to your username located at

the upper right hand of the menu, and click on your account icon to log out.

For this assignment, you must provide three screenshots, one from each tab of the Hosts,

Vulnerabilities, and History. Also, provide a brief description of what you found for vulnerabilities,

identify how many of each severity, and explain why you should be concerned about the critical and

high severities.

UnitVIIS.pdf
This file is too large to display.View in new window