|
=====================================================================================================
7 p/ W7 {+ V3 D注: 关于“Vulnerability Checks”分页中的各种漏洞扫描测试类型的解释如下:
) q g8 [& Z! }3 k# G; ]" h “Use IDS Evasion”----起用反IDS检测功能 Q8 B! K' V: K6 V' t' O; {
“Try to identify effective security checks to run”----尝试鉴别对方正在运行的安全防御系统- V& p; w$ l6 q8 @
“Include Denial-of-Service checks”----包括拒绝服务攻击测试
: e" w9 w6 [: q: |* \$ ? “Try to identify remote password files”----尝试鉴别远程的密码文件: m1 s5 h5 i. f& u" H; M R
“Detect server misconfiguration”----测试服务器的错误配置问题
5 R z( R: q8 o3 {& Q% N “Common HTTP Security Test”----普通HTTP安全测试3 t4 B, O! X c0 s3 m, F, V
“Optimize Security Checks”----优化测试类型(默认所有特殊测试类型全选)6 o8 h& J k) r, |* Y
“IIS CGI Decode Test”----IIS CGI解码测试
0 `. K% n# Z" j! E6 q9 o “General CGI Security Test”----普通CGI安全测试
4 k! B+ I8 g% i, l9 s3 ] “IIS Extended Unicode Test”----IIS附加Unicde转换测试% [- E$ s5 t' v6 p7 T {; j6 _
“NCSA Security Test”----NCSA安全测试/ _2 e1 L( e& e6 `# e* I
“IIS File Parsing Test”----IIS系统文件分解测试
$ l; ?5 {& h4 N N$ [ “ColdFusion Security Test”----ColdFusion系统安全测试
: q4 ~+ ]! y6 W3 w6 Q “FrontPage Security Test”----FrontPage管理安全测试
5 f8 b8 s$ L( [+ M* b* m/ V “Cisco HTTP Security Test”----思科系统HTTP管理平台的安全测试# a' p0 T7 L5 A9 C
“FrontPage CGI Security Test”----FrontPage CGI安全测试1 [7 h+ O8 l% W9 e4 i
“WinCGI Security Test”----WinCGI安全测试
/ _5 B6 C% Y( ] “Domino Security Test”----Domino系统安全测试
0 s2 m. P& n. M$ L7 g “Server-side language Security Test”----Server-side语言安全测试
9 x' K- X( F/ c& H- u4 W “Unset All Checks”按钮----不使用所有特殊扫描测试类型
( S1 z+ E: b- U @$ q=====================================================================================================' @0 C& u/ S, c' |; L i, g
最后回到“Scanner”分页,点击其右下方的“Scan Method”下拉菜单按钮,在弹出的菜单中选择需要作的扫描测试的基本类型。
! b% F" `1 S; m" [3 {. E |