on OK in the Security Alert pop-up, if it appears.

Module 03 - Scanning Networks


First, we need to create an admin user for the scanner. This user will have administrative control on the scanner; the admin has the ability to create/delete
users, stop ongoing scans, and change the scanner configuration.
Because the admin user can change the scanner configuration, the admin has the ability to execute commands on the remote host. Therefore, it should be
understood that the admin user has the same privileges as the *root* (or administrator) user on the remote host.

FIGURE 10.12: Nessus Initial Account Setup

18. In Plugin Feed Registration, you need to enter the activation code. To
obtain activation code, click the http://www.nessus.org/register/ link.
19. Click the Using Nessus at Home icon in Obtain an Activation Code

Tenable SecurityCenter, the
Activation Code and plugin
updates are managed from
SecurityCenter. Nessus needs
to be started to be able to
communicate with
SecurityCenter, which it will
normally not do without a
valid Activation Code and

TENABLE Network Security
Obtain an Activation Code
Using Nessus at Work?
Using Nessus at Home?
FIGURE 10.13: Nessus Obtaining Activation Code

20. In Nessus for Home accept the agreement by clicking the Agree button
as shown in the following figure.

Module 03 - Scanning Networks

Welcome to Nessus

Product Overview

N055ue b> Buwwct
Naasus ter Horn*
Why Upgrade to Nessus 6.7
Nessus Mobile App

Nessus Plugins
Sample Reports
Nessus FAQ

Deployment Options



Create Nessus Plugin List
Agreement and Distribution
Tenable
FIGURE 10.14: Nessus Subscription Agreement

21 Fill in the Register a HomeFeed section to obtain an activation code

S l f you do not
register your copy
of Nessus, you
will not receive
any new plugins
and will be unable
to start the
N essus server.
Note: The
Activation Code is
not case

and click Register.



TENABLE Network Security

Training


Certification

Resources

Tenable Products
Product Overview

Register a HomeFeed

Nessus Auditor Queries
Nessus Plugins
Sample Reports


T0 stay up to dah» with tlwi N 11tit>u1>pljgint you must tt‫;•־‬
em ai M td rn t to utilch an activation code wll be *ert Ye

email will not be

shared with any 3rd party.

Nessus FAQ
Mobile Devices FAQ
Deployment Options

Nessus Evaluation

Check to receive updates from Tenable


Register
FIGURE 10.15: Nessus Registering HomeFeed

22. The Thank You for Registering window appears for Tenable Nessus

Module 03 - Scanning Networks

TENABLE Network Security




Training & Certification



About Tenable


Tenable Products


Thank You for Registering!
Thank jrou tor reghletlag your ‫ ז‬eon bit‫ ׳‬Ni-viun HomeFeed An
em al eonraMng w a actlvafen rode hA» just b««n Mint to you
al tie email • M m you ptavWed

Product Overview
Nessus Auditor

cost to ctiirttabi• orqarization• I

Please note that »*• Tenable Ne-uut HomeFeed 11 available for
hoata u m oolr If you want to uaa Naasu* at your place of
business, you must outcKase the Nessus Proteaaowageed
Akemaiet. you n ay purchase a subscription to the Nessus
Porimolot S arnica and te a * in Mis cioudl Tha N a t t u i Ponawlci

Nessus Plugins

Service does not require any software download.


Foi more artonnafon on t w HomsFeed. Professional eed and
Nessus Perimeter Ser.ice. please visit our Discussions Forum.

Sample Reports

Tenable Charitable & Training
Organization Program
O rg a n iz a tio n P ro g ra m

Nessus FAQ
Mobile Devices FAQ
Deployment Options
Nessus Evaluation
Training

FIGURE 10.16: Nessus Registration Completed

23. Now log in to your email for the activation code provided at the time of
registration as shown in the following figure.


_ uSm9 Sma yanooco-n' ‫•״‬

1t»e Homefaea Activation Cooe
‫ י‬N M tut K i g i i i o i


Th■* )0ulw rejnlem j row N n w i k » * x
is valid for scanning

The Nessus HomeFeed subscription will keep your Nessus

If you use Nessus in a professional capacity you

The activation code is valid for use with one instance of Nessus and cannot be
shared.

FIGURE 10.17: Nessus Registration mail

24. Now enter the activation code received to your email ID and click Next.

Module 03 - Scanning Networks


Welcome to Nessus

Plugin Feed Registration
As information about new vulnerabilities is discovered and released into the public domain, Tenable's research staff designs programs ("plugins") that enable
Nessus to detect their presence. The plugins contain vulnerability information, the algorithm to test for the presence of the security issue, and a set of
remediation actions. To use Nessus, you need to subscribe to a "Plugin Feed". You can do so by visiting http://www.nessus.org/register/ to obtain an
Activation Code.
A c tiv a tio n C o d e.

IbsdJ Once the plugins liave
been downloaded and
compiled, the Nessus GUI
toUinitialize and the Nessus
server will start

To use Nessus at your workplace, pufdiaae a

commetGd Prgfcaatonalfccd

• To u m N c M u ti a t 10 a n o n ■com m ercial h o m e e n v iro n m e n t, yo u ca n g et 11 H o iim F e od for fre e
• Te n a b le Securltv C e n to r usore: E n ter 'S o a irlty C e n te r* in th e field b elow
• To p e rfo rm o fflin e plu g in u p d ates , e n te r 'o fflin e ' In th e field b elow
Activation Code

Please enter your Activation Code:

Optional Proxy Settings
< Prev

Next >

FIGURE 10.18: Nessus Applying Activation Code

25. The Registering window appears as shown in the following screenshot.



Registering...
Registering the scanner with Tenable...

FIGURE 10.19: Nessus Registering Activation Code

26. After successful registration click, Next: Download plugins > to
download Nessus plugins.
m Nessus server
configuration is managed via
the GUI The nessusdeonf
file is deprecated In addition,
proxy settings, subscription
feed registration, and offline
updates are managed via the

Welcome to Nessus


Wetcone to Nessus


Registering...
Successfully registered the scanner with Tenable.
Successfully created the user.

Next: Download plugins >


FIGURE 10.20: Nessus Downloading Plugins

27. Nessus will start fetching the plugins and it will install them, it will take
time to install plugins and initialization

Nessus is fetching the newest plugin set
Please wait...

FIGURE 10.21: Nessus fetching the newest plugin set

28. The Nessus Log In page appears. Enter the Username and Password
given at the time of registration and click Log In.

Module 03 - Scanning Networks

Network Scan


Q For the item SSH user
name, enter the name of the
account that is dedicated to
Nessus on each of the scan
target systems.




FIGURE 10.22: The Nessus Log In screen

29. The Nessus HomeFeed window appears. Click OK.

inn r m m i v a u u r a h m k M to Itw id T B tH il lr» n m r ■ ■ ] • tntima to
MMW uNM y i M W M u w may load 10 (*iMoaAon
Nessus responses.

w l oaiiUtanter any oust fton* oroigMtaAofii
M • to a PTOtoMknalFMd Subecrtpfcxi ha<•

(1998 - 2012) Tenable Network Security, Inc.


FIGURE 10.23: Nessus HomeFeed subscription

30. After you successfully log in, the Nessus Daemon window appears as
shown in the following screenshot.
m To add a new policy,
chck Policies ‫ ^־־‬Add Policy.

FIGURE 10.24: The Nessus main screen

31. If you have an Administrator Role, you can see the Users tab, which
lists all Users, their Roles, and their Last Logins.

