chapter 5 - Security Assesment and Testing Flashcards
SCAP
Security
Content
Automation
Protocol
CVE
Common Vulnerabilities & Exposures
CVSS
Common
Vulnerability
Scoring
System
ASV
approved
scanning
vendor
NIST
national
institute
of
standards
and
technology
ASV
approved
scanning
vendor
SCAP (elements)
CPE
CCE
CVE
XCCDF
CVSS
OVAL
CPE
common
platform
enumeration
CCE
common
configuration
enumeration
XCCDF
extensible
configuration
checklist
description
format
OVAL
OPEN
VULNERABILITIES
AND
ASSESMENT
LANGUAGE
vulnerability scanners
web
app
ntw
WEB APP SCANNING
- SQL INJECTION
- CROSS-SITE SCRIPTING (XSS)
- CROSS-SITE REQUEST FORGERY (CSRF)
APP SCANNING
STATIC
DYNAMIC
INTERACTIVE
ntw vul. scanner
1 NESSUS
2 QUALYS (SaaS mgmt console - on premises+in the cloud)
3 RAPID7’ NEXPOSE
4 OPENVAS
XSS
cross-site scripting
CSRF
cross-site request forgery
web app scanners
NIKTO - open source
ARACHNI - open source
ACUNETIX - commercial
=========================
most orgs use web app scanning capabilities of traditional ntw vuln scanners:
NESSUS
QUALYS
NEXPOSE
ntw vuln scanners
NESSUS
QUALYS
RAPID7’s NEXPOSE
OPENVAS
CVSS SEVERITY RATING SCALE
0.0 NONE
0.1 - 3.9 LOW
4 - 6.9 MEDIUM
7 - 8.9 HIGH
9 - 10 CRITICAL
SOC
security
operations
center