this post was submitted on 20 Apr 2024
70 points (98.6% liked)

Selfhosted

39435 readers
2 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 1 year ago
MODERATORS
 

Anyone have any good external pen testing tools that you've used on your self hosted setup? Mine is pretty secure overall but I would like to be able to scan the WAN for vulnerabilities or misconfigurations just to make sure I haven't missed anything.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 21 points 6 months ago (2 children)

Check out openvas.

https://github.com/greenbone/openvas-scanner

I use Nessus professionally, they are somewhat similar. I can't decide which one has the worse user interface.

[–] [email protected] 6 points 6 months ago (1 children)

Plus 1 to openvas. UI is indeed horrendous though.

Be careful running high load tests against sensitive devices. I once ran it against a PoE switch I used for my cameras and it did something so crazy that it required me not to only power cycle the switch, but to disconnect all the cameras first and then power cycle. Was super confusing and felt like it found a way to short the device lol. Scared the hell out of me.

That being said, I've found many many things to improve on my devices thanks to openvas.

[–] [email protected] 4 points 6 months ago

I had a colleague at work years ago who did his Master's thesis on network scanning. He ran a PoC in the company's network and had all the printers print hundreds of pages.

We learned that printers suck and that we should always know our payloads and targets 😁

[–] [email protected] 3 points 6 months ago

Another +1 to openvas. Specifically, I have had much luck with this Dockerized version: https://github.com/immauss/openvas