top of page

Scanning and Exploiting Vulnerabilities with Nessus

In this article, I will walk you through the process of setting up Nessus, scan and exploit a target on Proving Grounds Play with it.


What is Nessus?

Nessus is a vulnerability scanner that can scan and asses the complete attack surface of a target. With Nessus, you can scan a network for potential vulnerabilities, and even automatically exploit these discovered vulnerabilities. It supports different type of scans like Host Scan, Basic Network Scan, Malware Scan, Active Directory Scan, etc. It is a great tool for enumerating a target network and discovering potential ways to gain access.


Setting up Nessus

Nessus can be installed on Windows, Linux, Mac, Docker and even on a Raspberry Pi!. I prefer using it with Kasm Workspaces, which is a docker container streaming platform that lets me access and manage my docker apps from my web browser!

You can install Kasm Workspaces on your Linux machine with four simple commands by following the official installation guide here.

If you'd like to install Nessus on your machine directly (without Docker or Kasm), you can follow the installation guide here.


If you're setting up Nessus on Kasm, you need to edit some minor configurations. Go to Admin -> Workspaces and edit the Nessus image. For the "Docker Exec Config", use this configuration:

{"first_launch": { "cmd": "bash -c 'sudo apt-get update -y && sudo apt-get install -y openvpn  && sudo apt-get install -y iputils-ping'"}}

For "Docker Run Config Override", use this configuration:

{"user":"root","cap_add":["NET_ADMIN"],"devices":["dev/net/tun","/dev/net/tun"],"privileged":true}

These configurations will enable you to use OpenVPN within the Nessus container spawned in Kasm.


On the first launch of Nessus, you need to register for Nessus Essentials to be able to use it for free.

ree

You will then need to submit your name and email to receive an activation code.

ree

Once the registration process is complete, Nessus will download all the plugins and compile them. This is going to take a lot of time - it took me 2 hours! So be patient, I guess.


Once the plugins are downloaded and compiled, you will be able to start scanning.



Scan and Exploit

We will perform our first scan on a machine called "Sumo" from Proving Grounds Play, which is a free platform offered by Offsec to practice hacking. Once you signup on Proving Grounds Play, you can download your universal VPN pack to be able to connect to the PG Play's network and scan the target.


To connect using OpenVPN, use the following command:

sudo openvpn universal.ovpn
ree


Now, create a new "Basic Network Scan" on Nessus, set the target to the IP address of the "Sumo" machine on PG Play.

ree

Once the scan is complete, you can see that Nessus was able to find multiple vulnerabilities of different severities.

ree

We'll focus on the "GNU Bash Environment Variable Handling Code Injection (Shellshock)" vulnerability that Nessus identified.

ree

Upon opening the report, you can see that Nessus was actually able to exploit this vulnerability. The report also clearly states the exact malicious request that Nessus sent in order to exploit the vulnerability.

ree

Let's try to replicate this request to see if the exploit is actually working.

I asked ChatGPT to give me a CURL one-liner command based on the HTTP request.

ree
ree

Upon running this CURL command, I got a response from the target that proves that the exploit worked. The response contains the output of the command injected in the request.

ree

Using this exploit, one can inject and run arbitrary commands on the target and even get reverse shell access on the target by doing so.


So just like that, with Nessus, we were able to scan a target, find potential vulnerabilities and even get a detailed report on how to exploit one of these vulnerabilities.

 
 
 

75 Comments


Luxury You Can Afford: Discover Rates for Udaipur Escorts

Do you want to be with a gorgeous girl? Do you wish to rub your lips close? If yes, you've come to the right place. Jeshika is a renowned Escort Services in Udaipur committed to ensuring customers feel comfortable by satisfying their wishes. If you're an entrepreneur or an ordinary businessman We have a wide range of models, from those who have been featured in films and television shows to normal ones, all of them in your price range.

We are the top option for clients with discerning tastes due to our experience in the field of escort. Our basic, silver as well as platinum packages are made to meet your…

Like

Get Warm Welcome By Jaipur Call Girls For Desired Fantasies

Warm welcome to all who are searching for true fantasies. Jaipur is the most beautiful and most stunning place where you can you can spend time with your loved ones. It is famous for its luxurious restaurant and hotels as well as its contemporary design. Jaipur Airport is very accessible to many travellers. If you're seeking to spend a wonderful time with a plethora of top quality Jaipur call girls. We offer the most suitable option for those who love sexually erotica. Our services are just a phone call away to bring one of our call girls to your bedroom. We are always mindful of the friendship and requirements of…

Like

Why Hiring a Web Development Company in USA Is a Smart Business Move

In today’s digital-first world, a powerful online presence is not optional — it’s essential. Your website is the face of your brand, the primary conversion tool, and often, the first impression customers get of your business. That’s why hiring a Web Development Company in USA isn’t just smart — it’s strategic.

From cutting-edge designs to performance-driven development, partnering with a professional web development company ensures you stay ahead of the competition, scale efficiently, and adopt the latest web development technologies.

Let’s dive into why working with an experienced USA-based company like Techno Derivation can transform your business outcomes.


 1. Access to World-Class Talent & Infrastructure

The USA…


Like

Escorts In Bhopal Escorts Rs 3500 Cash Payment Free Delivery

Welcoming to Bhopal Escorts. Please check out the Bhopal Call girls' gallery, if you are looking for a gorgeous girl with an attractive personality. If your search ends here. are at the right place. We have erotic Call girls models available in Bhopal. All of our Bhopal Call Girl are available for in-call and outcall. You can expect that the quality of our Bhopal Escorts, they meet gentlemen that are respectful and polite who are in need of the girl. Additionally, all images are 100% authentic and true that are of Bhopal call girls. So that when the time comes to meet the girl you want to call they will…

Like

Welcome To The Top Escort Service in Indore

Are you in search of an elite escort in Indore that can satisfy all your fantasies and desires? You should look no further than Indore Escorts! With our stunning team of and professional escorts we will provide you with an unforgettable experience that will have you begging to us for more.

Welcoming you to Indore Escorts, the most popular escort service in Indore providing discreet, professional service for discerning customers. If you're in search of stunning independent escorts or VIP call girls, or a model of your dreams We offer a broad selection of options that are customized to meet your requirements.

If you've noticed that your life isn't providing you with…

Like

© 2019 Tech Raj. Designed by Teja Swaroop

  • YouTube
  • Facebook Page
  • Twitter
bottom of page