| |||||
| |||||
Search Irongeek.com:
Help Irongeek.com pay for bandwidth and research equipment: |
Back To MAN Pages From BackTrack 5 R1 Master List
The
OpenVAS Security Scanner
comes with its own user base which contains the list of who can
use the services of
openvassd,
and what restriction (or
rules)
each user has.
openvas-adduser
is a simple program which will add a user to the
openvassd
userbase.
The program is straightforward and asks for the following items:
Each rule fits on one line. A user can have an unlimited amount of
rules (and can even have no rule at all).
The syntax is:
Where
mask
is the CIDR netmask of the rule.
The
default
statement must be the last rule and defines the policy of the user.
The following rule set will allow the user to test 192.168.1.0/24,
192.168.3.0/24 and 172.22.0.0/16, but nothing else:
The following rule set will allow the user to test whatever he wants,
except the network 192.168.1.0/24:
The keyword
client_ip
has been defined, and is replaced at run time by the IP address
of the
openvassd
user. For instance, if you want your users to be able
to only be able to scan the system they come from, then you want
them to have the following ruleset:
If you set your TMPDIR variable to
/tmp,
then you are in trouble.
15 most recent posts on Irongeek.com:
|
If you would like to republish one of the articles from this site on your
webpage or print journal please contact IronGeek.
Copyright 2020, IronGeek
Louisville / Kentuckiana Information Security Enthusiast