|
=====================================================================================================" y7 t0 b' ^9 W; `6 j
注: 关于“Vulnerability Checks”分页中的各种漏洞扫描测试类型的解释如下: n& p: h- N f+ O3 M1 i) N
“Use IDS Evasion”----起用反IDS检测功能* V' S; q- G( s0 f8 w0 p
“Try to identify effective security checks to run”----尝试鉴别对方正在运行的安全防御系统; K6 S) d, P* t5 @8 E) I5 X
“Include Denial-of-Service checks”----包括拒绝服务攻击测试$ @8 i! @1 l8 g- d& @
“Try to identify remote password files”----尝试鉴别远程的密码文件
$ r! x* e6 B2 R. b5 {1 S “Detect server misconfiguration”----测试服务器的错误配置问题
+ x) G8 U8 h5 l, @$ V" S W3 U “Common HTTP Security Test”----普通HTTP安全测试
7 j0 L7 d ~- |8 F+ V “Optimize Security Checks”----优化测试类型(默认所有特殊测试类型全选)
7 O% J5 M/ f# y% y( Q+ O" ] “IIS CGI Decode Test”----IIS CGI解码测试0 l6 T" @ C# ^# y3 P) @
“General CGI Security Test”----普通CGI安全测试4 Z( d/ f& J5 `7 L7 g# x; d
“IIS Extended Unicode Test”----IIS附加Unicde转换测试3 R4 c- j+ C. R$ _! n3 i/ U7 k0 E
“NCSA Security Test”----NCSA安全测试
0 V [9 O6 k' ^6 }% x! ~* _ “IIS File Parsing Test”----IIS系统文件分解测试
9 I9 h/ y8 Z/ N “ColdFusion Security Test”----ColdFusion系统安全测试( D; b' m8 t/ V7 u+ ^5 F
“FrontPage Security Test”----FrontPage管理安全测试# c% I# {+ a/ o/ f8 |
“Cisco HTTP Security Test”----思科系统HTTP管理平台的安全测试" m: Y$ G) y* f1 P0 e9 q3 s" I
“FrontPage CGI Security Test”----FrontPage CGI安全测试% t& r. c0 n% w k
“WinCGI Security Test”----WinCGI安全测试* l! U0 ?8 Z+ |: c) h
“Domino Security Test”----Domino系统安全测试- d) b8 ^: C! k( ~3 j7 K
“Server-side language Security Test”----Server-side语言安全测试" J$ J/ \5 t, ]% Q7 Z4 X
“Unset All Checks”按钮----不使用所有特殊扫描测试类型, @; Q9 B: g' `$ |# r( Q& U1 H
=====================================================================================================- G0 k- ^: Z# T5 I% |. }
最后回到“Scanner”分页,点击其右下方的“Scan Method”下拉菜单按钮,在弹出的菜单中选择需要作的扫描测试的基本类型。8 Z7 r% V5 @1 h. X& a" Q( s
|