首页 > 系统相关 >CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156

CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156

时间:2023-12-21 17:03:16浏览次数:43  
标签:opt rapid7 centos 156 -- nexpose 6.6 root Nexpose

Nexpose简单介绍

Nexpose 是 Rapid7 出品,一款著名的、极佳的商业漏洞扫描工具。

CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156_jar

  • 跟一般的扫描工具不同,Nexpose自身的功能非常强大,可以更新其漏洞数据库,以保证最新的漏洞被扫描到。
  • 漏洞扫描效率非常高,对于大型复杂网络,可优先考虑使用;
  • 可以给出哪些漏洞可以被 Metasploit Exploit,哪些漏洞在 Exploit-db 里面有 exploit 的方案。
  • 可以生成非常详细的,非常强大的 Report,涵盖了很多统计功能和漏洞的详细信息。

CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156_centos_02

(图片点击放大查看)

CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156_sql_03

(图片点击放大查看)

下面介绍在CentOS7下安装商业漏洞扫描工具Nexpose_6.6.156(Linux  pojie版)

建议CentOS7服务器分配的内存>=16GB

1、上传安装包后,给安装脚本执行权限,并进行安装

license.lic
Nexpose_6.6.156.0_Linux_installer.bin
nse.jar
nxshared.jar

CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156_centos_04

(图片点击放大查看)

CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156_centos_05

(图片点击放大查看)

chmod +x Nexpose_6.6.156.0_Linux_installer.bin 
./Nexpose_6.6.156.0_Linux_installer.bin -cs

2、复制pojie文件到/opt/rapid7/nexpose/shared/lib

cp nse.jar /opt/rapid7/nexpose/nse/lib 
cp nxshared.jar /opt/rapid7/nexpose/shared/lib

3、访问web界面https://IP:3780/

CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156_jar_06

(图片点击放大查看)

如果访问不了,需要检查服务是否已经启动,如果没有启动需要输入下面命令

systemctl start nexposeconsole

查看实时日志

tail -f /opt/rapid7/nexpose/nsc/logs/nsc.log

查看更新的实时日志

tail -f /opt/rapid7/nexpose/nsc/logs/update.log

4、防火墙放开3780 Web端口

firewall-cmd --permanent --znotallow=public --add-port=3780/tcp
firewall-cmd --reload

5、Web登录后修改语言

并导入许可证文件

CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156_centos_07

(图片点击放大查看)

CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156_sql_08

(图片点击放大查看)

CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156_sql_09

(图片点击放大查看)

6、扫描测试

CentOS7下安装著名商业漏洞扫描工具Nexpose_6.6.156_sql_10

(图片点击放大查看)

下面为安装过程

[root@centos ~]# cd /opt
[root@centos opt]# cat /etc/redhat-release 
CentOS Linux release 7.9.2009 (Core)
[root@centos opt]# getenforce 
Disabled
[root@centos opt]# ls -l
total 1388272
-rw-r--r-- 1 root root       4689 Jun 20 10:34 license.lic
-rw-r--r-- 1 root root 1416931948 Aug 18 06:23 Nexpose_6.6.156.0_Linux_installer.bin
-rw-r--r-- 1 root root     688881 Aug 18 07:01 nse.jar
-rw-r--r-- 1 root root    3953148 Aug 18 07:01 nxshared.jar
[root@centos opt]# chmod +x Nexpose_6.6.156.0_Linux_installer.bin
[root@centos opt]# ./Nexpose_6.6.156.0_Linux_installer.bin -c
Unpacking JRE ...
Starting Installer ...


********************************************************************************
Welcome to the Rapid7 Installation Wizard
********************************************************************************

Rapid7 Vulnerability Management reduces your organization's risk by
dynamically collecting data and analyzing risk across vulnerabilities,
configurations and controls from the endpoint to the cloud. Our
vulnerability management platform is engineered to enable IT security teams
to identify, assess and respond to critical change as it happens.

Rapid7 Inc
http://www.rapid7.com
[email protected]
+1.866.7RAPID7 (Toll Free)
+1.617.247.1717

Do you want to continue?
Yes [y, Enter], No [n]
y

Gathering system information....

Security Console with local Scan Engine
If you do not have a console installed yet, this option is recommended. The console manages scan engines and all administrative operations.

Scan Engine only
This distributed engine can start scanning after being paired with a Security Console.

Select only the set of components you want to install:
Security Console with local Scan Engine [1, Enter]
Scan Engine only [2]


Where should Rapid7 Vulnerability Management be installed?
[/opt/rapid7/nexpose]

The partition containing /opt/rapid7/nexpose does not meet
the recommended amount of free space to install the software.

56.35 GB was found, 80 GB is recommended.

The installation can continue, but insufficient drive space will impact
the long-term operation of software as your stored data increases.
Continue [c, Enter], Back [b]



********************************************************************************
The installer is comparing your system settings to required settings
********************************************************************************

Installation requirements
[Warn] - 7,808 MB RAM was detected. 8,192 MB RAM is recommended.
        See the list of supported versions.
        http://www.rapid7.com/products/nexpose/system-requirements

[Pass] - SELinux is not active.
[Pass] - Software is not running.
Ports and connectivity
Not checked.
[Pass] - Port 3780 is available.
[Warn] - The update server could not be accessed.

Minimum requirements met. Select "Yes" to continue, "No" to cancel installation.
Yes [y, Enter], No [n]
y
Database port
Enter the number for the port that the database will listen on:
[5432]


The port number is valid.


********************************************************************************
User Details: This information will be used for generating SSL certificates, and it will be included in requests to Technical Support. Only alphanumeric characters and spaces are allowed in the name fields.
********************************************************************************

First name:
[]
yuan   
Last name:
[]
fan
Company:
[]
IT


********************************************************************************
Credentials: Choose secure credentials and remember them. You will need them to perform configuration steps after completing the installation.
********************************************************************************

Credentials: Choose secure credentials and remember them. You will need them
to perform configuration steps after completing the installation.
User name:
[]
yuanfan

Password:


Confirm the password:


Require password reset upon login?
Yes [y], No [n, Enter]
n
WARNING: The provided password does not meet complexity suggestions.

It is strongly recommended that you choose a password which does not contain the username.
Fix [f, Enter], Ignore [i]
i


********************************************************************************
Confirm or change your installation selections
********************************************************************************



********************************************************************************
Additional Tasks Selection
********************************************************************************

You have selected the following installation location:
/opt/rapid7/nexpose

You have selected the following component(s) to install:
Security Console, Scan Engine

You have entered the following contact information:
yuan fan,  IT

You have created the following user name:
yuanfan

Select any additional installation tasks.
Initialize and start after installation?
Yes [y], No [n, Enter]




********************************************************************************
Extracting files...
********************************************************************************

Extracting files...
                                                                           


********************************************************************************
Installation is complete!
********************************************************************************

Installation is complete!

If you chose to start the Security Console as part of the installation, then it will be started upon installer completion.

Using the credentials you created during installation, log onto Nexpose at https://localhost:3780.


To start the service run: sudo systemctl start nexposeconsole.service


To start the service run: sudo systemctl start nexposeconsole.service
The Security Console is configured to automatically run at startup. See the
installation guide if you wish to modify start modes.

[Enter]

Finishing installation...
[root@centos opt]# cp nse.jar /opt/rapid7/nexpose/nse/lib && cp nxshared.jar /opt/rapid7/nexpose/shared/lib
cp: overwrite ‘/opt/rapid7/nexpose/nse/lib/nse.jar’? yes
cp: overwrite ‘/opt/rapid7/nexpose/shared/lib/nxshared.jar’? yes
[root@centos opt]# systemctl start nexposeconsole.service 
[root@centos opt]# systemctl status nexposeconsole.service 
● nexposeconsole.service - Security Console Service
   Loaded: loaded (/etc/systemd/system/nexposeconsole.service; enabled; vendor preset: disabled)
   Active: active (running) since Sun 2022-10-23 12:26:51 CST; 42s ago
  Process: 2343 ExecStart=/opt/rapid7/nexpose/nsc/nexposeconsole.rc start (code=exited, status=0/SUCCESS)
 Main PID: 2358 (nsc.sh)
   CGroup: /system.slice/nexposeconsole.service
           ├─2358 /bin/sh /opt/rapid7/nexpose/nsc/nsc.sh
           └─2572 ./.DLLCACHE/nexserv -className=com/rapid7/nexpose/nsc/NSC

Oct 23 12:26:40 centos.walkingcloud.cn systemd[1]: Starting Security Console Service...
Oct 23 12:26:41 centos.walkingcloud.cn nexposeconsole.rc[2343]: nohup: failed to run command ‘/usr/X11R6/bin/Xvfb’: No such file…rectory
Oct 23 12:26:51 centos.walkingcloud.cn nexposeconsole.rc[2343]: Starting NeXpose security console: [  OK  ]
Oct 23 12:26:51 centos.walkingcloud.cn systemd[1]: Started Security Console Service.
Oct 23 12:26:53 centos.walkingcloud.cn useradd[2634]: new group: name=nxpgsql, GID=1000
Oct 23 12:26:53 centos.walkingcloud.cn useradd[2634]: new user: name=nxpgsql, UID=1000, GID=1000, home=/opt/rapid7/nexpose/nsc/...n/bash
Oct 23 12:26:56 centos.walkingcloud.cn su[2667]: (to nxpgsql) root on none
Oct 23 12:26:56 centos.walkingcloud.cn su[2675]: (to nxpgsql) root on none
Oct 23 12:26:56 centos.walkingcloud.cn su[2684]: (to nxpgsql) root on none
Oct 23 12:26:57 centos.walkingcloud.cn su[2701]: (to nxpgsql) root on none
Hint: Some lines were ellipsized, use -l to show in full.
[root@centos opt]# firewall-cmd --permanent --znotallow=public --add-port=3780/tcp
success
[root@centos opt]# firewall-cmd --reload
success
[root@centos opt]# tail -f /opt/rapid7/nexpose/nsc/logs/update.log


标签:opt,rapid7,centos,156,--,nexpose,6.6,root,Nexpose
From: https://blog.51cto.com/u_64214/8925271

相关文章

  • 文心一言 VS 讯飞星火 VS chatgpt (156)-- 算法导论12.3 3题
    三、用go语言,对于给定的n个数的集合,可以通过先构造包含这些数据的一棵二叉搜索树(反复使用TREE-INSERT逐个插入这些数),然后按中序遍历输出这些数的方法,来对它们排序。这个排序算法的最坏情况运行时间和最好情况运行时间各是多少?文心一言:在Go语言中,使用二叉搜索树(BST)进行排序......
  • openGauss学习笔记-156 openGauss 数据库运维-备份与恢复-导出数据-使用gs_dump和gs_d
    openGauss学习笔记-156openGauss数据库运维-备份与恢复-导出数据-使用gs_dump和gs_dumpall命令导出数据-导出单个数据库-导出数据库156.1导出数据库openGauss支持使用gs_dump工具导出某个数据库级的内容,包含数据库的数据和所有对象定义。可根据需要自定义导出如下信息:导出......
  • Nexpose v6.6.230 for Linux & Windows - 漏洞扫描
    Nexposev6.6.230forLinux&Windows-漏洞扫描Rapid7VulnerabilityManagement,ReleaseDec07,2023请访问原文链接:https://sysin.org/blog/nexpose-6/,查看最新版。原创作品,转载请保留出处。作者主页:sysin.org您的本地漏洞扫描程序搜集通过实时覆盖整个网络,随......
  • 13、深度学习入门:P154、P155、P156、P157、P158、P159
    1、调整权重和偏置以便拟合训练数据的过程称为学习这句话指的是机器学习中模型训练的过程。在训练一个机器学习模型时,我们通常有一个训练数据集,其中包含输入和对应的期望输出。模型的目标是通过学习这些数据中的模式和规律,以便在未见过的数据上做出准确的预测或执行任务。模型学......
  • 6.6 Windows驱动开发:内核枚举Minifilter微过滤驱动
    Minifilter是一种文件过滤驱动,该驱动简称为微过滤驱动,相对于传统的sfilter文件过滤驱动来说,微过滤驱动编写时更简单,其不需要考虑底层RIP如何派发且无需要考虑兼容性问题,微过滤驱动使用过滤管理器FilterManager提供接口,由于提供了管理结构以及一系列管理API函数,所以枚举过滤驱动将......
  • 运营商网络性能测试-Y.1564
    前言在网络部署之后和业务开展之前,运营商迫切希望了解当前网络的性能状态,以便为商业规划和业务推广提供必要的基础数据支持。因此,高可靠性和高精确度的性能测试方法对于运营商评判网络性能的优劣,显得尤为重要,而RFC2544等传统测试标准已不足于鉴定当今的服务等级协议(SLA)。SLA是服......
  • Qt 6.6.1 修复了 400 多个 bug
    Qt6.6 于上个月正式发布,引入了QtGraphs、更强大的Wayland支持、各种渲染增强功能等等。Qt是一个跨平台的应用程序开发框架,广泛用于创建图形用户界面、嵌入式系统和移动应用等。Qt6是Qt的最新版本,于2022年12月发布,带来了许多新特性和改进,如更强大的QML语言、更......
  • Educational Codeforces Round 156 (Rated for Div. 2) ABCD
    EducationalCodeforcesRound156(RatedforDiv.2)ABCDA.SumofThree题意:给定正整数\(n\),判断是否存在正整数\(a\),\(b\),\(c\)满足:\(a+b+c=n\)。\(a\),\(b\),\(c\)均不是\(3\)的倍数。如存在,输出YES并构造一组方案,否则输出NO。思路:法一:我们分类讨论。根据......
  • [题解] CF1156E Special Segments of Permutation
    SpecialSegmentsofPermutation给你一个排列\(p\),求有多少个区间\([l,r]\)满足\(p_l+p_r=\max_{i\in[l,r]}p_i\)。\(n\le2\times10^5\)。按最大值分治,记当前的分治中心为\(mid\),分治区间为\([l,r]\)。然后需要计算跨分治中心的贡献。如果\(mid-l......
  • Linux 内核 6.6 版本莅临,带来诸多变化
    导读笔记本的支持得到了提升,服务器性能得到了改进,更多内容一一揭晓。又到了迎接 Linux 内核新版本发布的时刻!Linux内核6.6的发布,是一次大规模更新,针对各类笔记本、网络硬件、处理器等提供了大量全方位的改良。LinusTorvalds 表示:各种各样的修复散布各处,除了针......