Objectives
In this lab, you will explore network vulnerability scanning tools and use them to perform a vulnerability scan on a target host.
- Perform network scans with Nmap
- Use Greenbone Vulnerability Management to perform a vulnerability scan
Background / Scenario
In this lab, you will use Nmap to enumerate a host computer that was creating unusual traffic on the network. Furthermore, you will use Nmap and Greenbone Vulnerability Management (GVM) to scan the system to identify potential vulnerabilities.
Required Resources
- Customized Kali VM
- Internet access
Instructions
Part 1: Run a Nmap Scan on a Target Computer
In this part, you will use Nmap and NSE scripts to uncover potential vulnerabilities in a target host.
Step 1: Start and login to the Kali virtual machine.
- Start and log into the Kali virtual machine.
- Start a terminal session. Expand the terminal window to a full screen. Use the ping command to determine if the computer with the address 10.6.6.23 or gravemind.vm is reachable over the network.
┌──(kali㉿Kali)-[~] └─$ ping -c5 10.6.6.23
The -c5 option tells the ping command to stop after five tries. In Linux, when a -c option is not specified the ping command will continue indefinitely until CTRL-C is issued.
Step 2: Identify open ports and services.
Review the results of a Nmap scan on the host with the IP address 10.6.6.23.
- Execute a ping scan of the target host using the nmap -sV command. Note the list of ports and applications that are discovered on the host.
┌──(kali㉿Kali)-[~] └─$ nmap -sV 10.6.6.23
- Identify the operating system running on the target computer using the nmap -O command.
┌──(kali㉿Kali)-[~] └─$ sudo nmap -O 10.6.6.23
Step 3: Use the Nmap Vulners script to scan for vulnerabilities.
The Vulners script displays known vulnerabilities and the corresponding CVE. The Vulners script uses the open port and software version information to search for common platform enumeration (CPE) names that relate to the identified service. It then makes a request to a remote server to find out if any known vulnerabilities exist for that CPE.
- Use the nmap –script command to launch the vulners script. The syntax for the command is nmap -sV --script vulners [--script-args mincvss=<arg_val>] <target> where the script argument mincvss restricts the output to only those CVEs that have a higher CVSS score than the one specified in the argument.
The vulnerabilities reported will be those with a CVE score equal to or higher than 7. The output of the command should look similar to what is shown below:
┌──(kali㉿Kali)-[~] └─$ nmap -sV --script vulners --script-args mincvss=7 10.6.6.23 Starting Nmap 7.94 ( https://nmap.org ) at 2025-07-10 17:50 UTC Nmap scan report for gravemind.vm (10.6.6.23) Host is up (0.00013s latency). Not shown: 994 closed tcp ports (conn-refused) PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 3.0.3 | vulners: | vsftpd 3.0.3: | CVE-2021-30047 7.5 https://vulners.com/cve/CVE-2021-30047 |_ CVE-2021-3618 7.4 https://vulners.com/cve/CVE-2021-3618 22/tcp open ssh OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0) | vulners: | cpe:/a:openbsd:openssh:7.9p1: | 5E6968B4-DBD6-57FA-BF6E-D9B2219DB27A 10.0 https://vulners.com/githubexploit/5E6968B4-DBD6-57FA-BF6E-D9B2219DB27A *EXPLOIT* | PACKETSTORM:173661 9.8 https://vulners.com/packetstorm/PACKETSTORM:173661 *EXPLOIT* | F0979183-AE88-53B4-86CF-3AF0523F3807 9.8 https://vulners.com/githubexploit/F0979183-AE88-53B4-86CF-3AF0523F3807 *EXPLOIT* | CVE-2023-38408 9.8 https://vulners.com/cve/CVE-2023-38408 | B8190CDB-3EB9-5631-9828-8064A1575B23 9.8 https://vulners.com/githubexploit/B8190CDB-3EB9-5631-9828-8064A1575B23 *EXPLOIT* | 8FC9C5AB-3968-5F3C-825E-E8DB5379A623 9.8 https://vulners.com/githubexploit/8FC9C5AB-3968-5F3C-825E-E8DB5379A623 *EXPLOIT* | 8AD01159-548E-546E-AA87-2DE89F3927EC 9.8 https://vulners.com/githubexploit/8AD01159-548E-546E-AA87-2DE89F3927EC *EXPLOIT* | 2227729D-6700-5C8F-8930-1EEAFD4B9FF0 9.8 https://vulners.com/githubexploit/2227729D-6700-5C8F-8930-1EEAFD4B9FF0 *EXPLOIT* | 0221525F-07F5-5790-912D-F4B9E2D1B587 9.8 https://vulners.com/githubexploit/0221525F-07F5-5790-912D-F4B9E2D1B587 *EXPLOIT* | CVE-2020-15778 7.8 https://vulners.com/cve/CVE-2020-15778 | CVE-2019-16905 7.8 https://vulners.com/cve/CVE-2019-16905 | C94132FD-1FA5-5342-B6EE-0DAF45EEFFE3 7.8 https://vulners.com/githubexploit/C94132FD-1FA5-5342-B6EE-0DAF45EEFFE3 *EXPLOIT* | 10213DBE-F683-58BB-B6D3-353173626207 7.8 https://vulners.com/githubexploit/10213DBE-F683-58BB-B6D3-353173626207 *EXPLOIT* | SSV:92579 7.5 https://vulners.com/seebug/SSV:92579 *EXPLOIT* | 1337DAY-ID-26576 7.5 https://vulners.com/zdt/1337DAY-ID-26576 *EXPLOIT* | CVE-2021-41617 7.0 https://vulners.com/cve/CVE-2021-41617 | PACKETSTORM:151227 0.0 https://vulners.com/packetstorm/PACKETSTORM:151227 *EXPLOIT* |_ PACKETSTORM:140261 0.0 https://vulners.com/packetstorm/PACKETSTORM:140261 *EXPLOIT* <output omitted> 139/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP) 445/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP) Service Info: Host: GRAVEMIND; OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 13.53 seconds
- Use the National Vulnerability Database at NIST to learn more about the identified vulnerability and how it can be exploited. https://nvd.nist.gov/vuln/search
Part 2: Use GVM to Scan for Vulnerabilities
GVM is part of the Open Source Vulnerability Management suite of products produced by Greenbone Networks GmbH. The GVM scanner is one of the most widely used open-source vulnerability scanners. Unlike Nmap, GVM uses a graphical user interface to initiate scans and report vulnerability scan results.
Step 1: Verify the GVM Product Installation.
Before beginning any scan, it is important to verify that GVM is correctly installed and that the files it uses to identify vulnerabilities are up-to-date.
- Verify the setup of the GVM service using the sudo gvm-check-setup command. This command verifies that the setup completed correctly and the necessary files are available. The verification will flag any issues that need fixing and will provide the commands to use to fix the issues.
┌──(kali㉿Kali)-[~] └─$ sudo gvm-check-setup
- If there are issues, execute the suggested command to fix the problem and then re-run the gvm-check-setup command. When all issues are addressed, the command outputs the string “It seems like your GVM [version] installation is OK.”.
- Just for this activity, stop the GVM service so you can observe the startup output.
┌──(kali㉿Kali)-[~] └─$ sudo gvm-stop
Step 2: Open the GVM Scanner GUI.
- Start the GVM scanner using the sudo gvm-start command. You can also access the gvm-start script using the Applications menu on the Kali desktop, Kali ->02-Vulnerability Analysis -> gvm start. It is possible that GVM may already be running as a result of the check setup process.
- A browser window will open with a security warning that can be ignored. If the browser does not automatically open, start your browser manually and navigate to https://127.0.0.1:9392. Click the Advanced button and scroll down and accept the risk on the warning screen to proceed.
- In the Greenbone Security Assistant login box, enter admin as the username and kali as the password.
- The GVM Scanner application GUI should open in the browser. Select Scans -> Tasks from the menu bar. At the upper left of the Tasks window appear three icons. Select the Task Wizard icon that looks like a magic wand. Choose Task Wizard from the dropdown menu.
The output of the command should be similar to what is shown below. At the end of the output, a message that the scanner is loading in Firefox will appear.
┌──(kali㉿Kali)-[~]
└─$ sudo gvm-start
[>] Please wait for the GVM services to start.
[>]
[>] You might need to refresh your browser once it opens.
[>]
[>] Web UI (Greenbone Security Assistant): https://127.0.0.1:9392
● gsad.service - Greenbone Security Assistant daemon (gsad)
Loaded: loaded (/lib/systemd/system/gsad.service; disabled; preset: disabled)
Active: active (running) since Thu 2025-07-10 06:35:13 UTC; 17ms ago
Docs: man:gsad(8)
https://www.greenbone.net
Main PID: 21754 (gsad)
Tasks: 1 (limit: 9432)
Memory: 1.3M
CPU: 7ms
CGroup: /system.slice/gsad.service
├─21754 /usr/sbin/gsad --foreground --listen 127.0.0.1 --port 9392
└─21756 /usr/sbin/gsad --foreground --listen 127.0.0.1 --port 9392
Jul 10 06:35:13 Kali systemd[1]: Starting gsad.service - Greenbone Security Assistant daemon (gsad)...
Jul 10 06:35:13 Kali systemd[1]: Started gsad.service - Greenbone Security Assistant daemon (gsad).
● gvmd.service - Greenbone Vulnerability Manager daemon (gvmd)
Loaded: loaded (/lib/systemd/system/gvmd.service; disabled; preset: disabled)
Active: active (running) since Thu 2025-07-10 06:35:08 UTC; 5s ago
Docs: man:gvmd(8)
Process: 21617 ExecStart=/usr/sbin/gvmd --osp-vt-update=/run/ospd/ospd.sock --listen-group=_gvm (code=exited, status=0/SUCCESS)
Main PID: 21622 (gvmd)
Tasks: 1 (limit: 9432)
Memory: 181.0M
CPU: 695ms
CGroup: /system.slice/gvmd.service
└─21622 "gvmd: gvmd: Wa" --osp-vt-update=/run/ospd/ospd.sock --listen-group=_gvm
Jul 10 06:35:06 Kali systemd[1]: Starting gvmd.service - Greenbone Vulnerability Manager daemon (gvmd)...
Jul 10 06:35:06 Kali systemd[1]: gvmd.service: Can't open PID file /run/gvmd/gvmd.pid (yet?) after start: No such file or directory
Jul 10 06:35:08 Kali systemd[1]: Started gvmd.service - Greenbone Vulnerability Manager daemon (gvmd).
● ospd-openvas.service - OSPd Wrapper for the OpenVAS Scanner (ospd-openvas)
Loaded: loaded (/lib/systemd/system/ospd-openvas.service; disabled; preset: disabled)
Active: active (running) since Thu 2025-07-10 06:35:06 UTC; 6s ago
Docs: man:ospd-openvas(8)
man:openvas(8)
Process: 21592 ExecStart=/usr/bin/ospd-openvas --config /etc/gvm/ospd-openvas.conf --log-config /etc/gvm/ospd-logging.conf (code=exited, status=0/SUCCESS)
Main PID: 21609 (ospd-openvas)
Tasks: 5 (limit: 9432)
Memory: 43.6M
CPU: 670ms
CGroup: /system.slice/ospd-openvas.service
├─21609 /usr/bin/python3 /usr/bin/ospd-openvas --config /etc/gvm/ospd-openvas.conf --log-config /etc/gvm/ospd-logging.conf
└─21612 /usr/bin/python3 /usr/bin/ospd-openvas --config /etc/gvm/ospd-openvas.conf --log-config /etc/gvm/ospd-logging.conf
Jul 10 06:35:05 Kali systemd[1]: Starting ospd-openvas.service - OSPd Wrapper for the OpenVAS Scanner (ospd-openvas)...
Jul 10 06:35:06 Kali systemd[1]: Started ospd-openvas.service - OSPd Wrapper for the OpenVAS Scanner (ospd-openvas).
[>] Opening Web UI (https://127.0.0.1:9392) in: 5... 4... 3... 2... 1...
Username: admin Password: kali
Step 3: Scan the Target Host for Vulnerabilities.
In this step, you will scan the same target computer for vulnerabilities that you did with the earlier Nmap scan.
- In the IP address or hostname box, enter the IP address 10.6.6.23 or gravemind.vm. Click the Start Scan button at the bottom of the screen. The scan will take a few minutes, so wait for it to complete. The status and percent complete are displayed on the screen. The scan will be finished when the status changes to Done.
- Click the number under the Reports column while the scanning is running for the associated scan.
- When the scan is complete, click the timestamp under the Date column to view the report detail.
- The CVEs associated with the vulnerabilities that were found on the host can be viewed by clicking the CVEs tab. Explore the other tabs.
- Download the report by clicking the Download Filtered Report button from the menu in the upper left of the report page. It has a downward-pointing arrow icon. In the settings box, choose to download the report in PDF format. After a brief delay, the PDF file should open in your browser.
- Click the other headers on the report and view the information provided. Compare this information with what you discovered in Part 1.
Step 4: Clean Up
When you are done with GVM services, use the following command to stop GVM.
┌──(kali㉿Kali)-[~] └─$ sudo gvm-stop