Anyone have any good external pen testing tools that you’ve used on your self hosted setup? Mine is pretty secure overall but I would like to be able to scan the WAN for vulnerabilities or misconfigurations just to make sure I haven’t missed anything.

    • Mikelius@lemmy.ml
      link
      fedilink
      English
      arrow-up
      6
      ·
      3 months ago

      Plus 1 to openvas. UI is indeed horrendous though.

      Be careful running high load tests against sensitive devices. I once ran it against a PoE switch I used for my cameras and it did something so crazy that it required me not to only power cycle the switch, but to disconnect all the cameras first and then power cycle. Was super confusing and felt like it found a way to short the device lol. Scared the hell out of me.

      That being said, I’ve found many many things to improve on my devices thanks to openvas.

      • 0xD@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 months ago

        I had a colleague at work years ago who did his Master’s thesis on network scanning. He ran a PoC in the company’s network and had all the printers print hundreds of pages.

        We learned that printers suck and that we should always know our payloads and targets 😁

  • sv1sjp@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    3 months ago

    You can try to scan your server with vulnerability assessment tools such as Nessus (it is available as a docker container) or sn1per which is open source.

  • catloaf@lemm.ee
    link
    fedilink
    English
    arrow-up
    4
    ·
    3 months ago

    https://monitor.shodan.io/

    Not sure if there’s a free tier. Lifetime memberships go on sale for cheap at least once a year, though.

    Personally I’d run a free VM in the cloud and scan yourself with nessus, nmap, and such. Trying to scan yourself from inside doesn’t really work well for some reason. I assume it’s something to do with routing.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    2 months ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    IP Internet Protocol
    PoE Power over Ethernet
    VPN Virtual Private Network

    3 acronyms in this thread; the most compressed thread commented on today has 9 acronyms.

    [Thread #694 for this sub, first seen 21st Apr 2024, 07:15] [FAQ] [Full list] [Contact] [Source code]

  • bobs_monkey@lemm.ee
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    3 months ago

    Probably anything within the Kali Linux suite or any security-centric distribution. If possible, boot it up to a laptop hooked to a phone hotspot or any network outside your home network, route through a VPN, determine your WAN IP, and go to town.

    • 0xD@infosec.pub
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      edit-2
      3 months ago

      I’m a big fan of hashcat for this use case myself! I route it through WS, however. I like being on the bleeding edge.