installation steps
Mainly introduce the installation process of GVM-10 on CentOS 7 64-bit system, and perform various operations under the root account.
View operating system version
cat /etc/redhat-release
Steps:
vi /etc/selinux/config
Change parameters:
SELINUX=disabled
Update:
yum -y update
Restart:
reboot
Installation dependencies:
yum install -y wget bzip2 texlive net-tools alien gnutls-utils
Add warehouse:
wget -q -O - https://www.atomicorp.com/installers/atomic | sh
or
wget -q -O – https://www6.atomicorp.com/installers/atomic | sh
installation:
yum install gvm -y
Edit the file:
vi /etc/redis.conf
Change setting:
unixsocket /tmp/redis.sock
unixsocketperm 700
Restart redis:
systemctl enable redis && systemctl restart redis
Start openvas initial environment configuration:
openvas-setup
Note: The time is a bit long. There may be several interactive operations during the execution of this step. After the execution is completed, the administrator account used by the system defaults to admin and its password settings. Blank passwords are not allowed. Set the password as required in this step. OK, wait a moment!
Need to restart after installation
reboot
Process inspection, normally there should be three Active: active (running)
Process check:
systemctl status gvmd # manage
systemctl status openvas-scanner # scanne
systemctl status gsad # web ui
Examples are as follows:
● gvmd.service - OpenVAS Manage
Loaded: loaded (/usr/lib/systemd/system/gvmd.service; disabled; vendor preset: disabled)
Active: active (running) since Wed 2019-10-30 03:44:57 CST; 10s ago
Process: 10835 ExecStart=/usr/sbin/gvmd $OPTIONS (code=exited, status=0/SUCCESS)
Main PID: 10836 (gvmd)
CGroup: /system.slice/gvmd.service
├─10836 gvmd: Waiting for incoming connections
├─10858 gvmd: Reloading NVTs
└─10859 gvmd: Syncing SCAP
Oct 30 03:44:57 VM_0_17_centos systemd1: Starting OpenVAS Manager...
Oct 30 03:44:57 VM_0_17_centos systemd1: Started OpenVAS Manager.
● openvas-scanner.service - OpenVAS Scanne
Loaded: loaded (/usr/lib/systemd/system/openvas-scanner.service; disabled; vendor preset: disabled)
Active: active (running) since Wed 2019-10-30 03:44:30 CST; 47s ago
Process: 10771 ExecStart=/usr/sbin/openvassd $SCANNER_SOCKET $SCANNER_MODE $SCANNER_GROUP $SCANNER_OWNER (code=exited, status=0/SUCCESS)
Main PID: 10772 (openvassd)
CGroup: /system.slice/openvas-scanner.service
├─10772/usr/sbin/openvassd
├─10773 openvassd: Waiting for incoming connections
└─10774 openvassd: Reloaded 25350of53156NVTs(47%/ ETA:00:50)
Oct 30 03:44:30 VM_0_17_centos systemd1: Starting OpenVAS Scanner...
Oct 30 03:44:30 VM_0_17_centos systemd1: Started OpenVAS Scanner.
● gsad.service - Greenbone Security Assistant (OpenVAS)
Loaded: loaded (/usr/lib/systemd/system/gsad.service; enabled; vendor preset: disabled)
Active: active (running) since Wed 2019-10-30 03:38:10 CST; 7min ago
Process: 1248 ExecStart=/usr/sbin/gsad $OPTIONS (code=exited, status=0/SUCCESS)
Main PID: 1356 (gsad)
CGroup: /system.slice/gsad.service
├─1356/usr/sbin/gsad
└─1357/usr/sbin/gsad
Access login:
Enter https://192.168.1.1 in the browser (the IP here is the host ip where you deploy OpenVAS), enter the account admin, or set the user name and password, the login is successful! Now gsad after installing openvas by default will listen to port 443, you can also try to visit https://192.168.1.1:9392
If there is no response, the port can be checked:
View TCP port
netstat -ntlp
If port 443 is open and monitored, you need to set the firewall port to let it go
Firewall release port: (If the system is closed by default, it can be opened by this command)
firewall-cmd --permanent --add-port=443/tcp
firewall-cmd --reload
firewall-cmd --list-port
Some other operations
User operation:
Add user
sudo gvmd --create-user=unicorn
The system generates a password by default:
User created with password '6sds652f-f43f-49e8-bc9d-a5s89d483'.
Modify user password:
gvmd --user=unicorn --new-password=unicorn2019
The added user can be deleted by the following command
gvmd --delete-user=unicorn
Library update:
greenbone-nvt-sync
greenbone-scapdata-sync
greenbone-certdata-sync
Process check:
systemctl status gvmd # manage
systemctl status openvas-scanner # scanne
systemctl status gsad # web ui
Enable boot service:
systemctl enable openvas-scanne
systemctl enable gvmd
systemctl enable gsad
Restart OpenVAS:
systemctl restart gvmd
systemctl restart openvas-scanne
systemctl restart gsad
WEB management to modify the port:
command
gsad --http-only --listen=0.0.0.0 -p 5555
or
echo 'OPTIONS="--listen=0.0.0.0 --port=5555"' > /etc/sysconfig/gsad
systemctl start gsad
Service file directory
/lib/systemd/system/gvmd.service
/lib/systemd/system/gsad.service
/lib/systemd/system/openvas-scanner.service
The report cannot be downloaded in PDF format. The download is 0K and cannot be opened.
First, install other texlive packages for CentOS 7.
sudo yum -y install texlive-collection-fontsrecommended texlive-collection-latexrecommended texlive-changepage texlive-titlesec
Create a directory, download the comment.sty file, change the permissions for the newly downloaded file, and then use texhash to recreate the database. You can use the following command
mkdir -p /usr/share/texlive/texmf-local/tex/latex/comment
cd /usr/share/texlive/texmf-local/tex/latex/comment
wget http://mirrors.ctan.org/macros/latex /contrib/comment/comment.sty
chmod 644 comment.sty
texhash
The default library is automatically updated
Offline update
Just download the compressed package of the vulnerability library regularly and unzip it to the following directory:
/var/lib/openvas/plugins/
Recommended Posts