From 66566f6b1c4fe1d8a4d5d2c4fc093fe515910719 Mon Sep 17 00:00:00 2001 From: xer0dayz <1N3@hushmail.com> Date: Mon, 8 Aug 2022 13:30:05 -0700 Subject: [PATCH] Updated GVM 21.x Integration (markdown) --- GVM-21.x-Integration.md | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/GVM-21.x-Integration.md b/GVM-21.x-Integration.md index 0d41e14..4f47ffd 100644 --- a/GVM-21.x-Integration.md +++ b/GVM-21.x-Integration.md @@ -1,5 +1,8 @@ First, verify that GVM is running and configured properly by running ```gvm-start```. If no errors are displayed, ensure that you can login to the web UI at https://127.0.0.1:9390. If there are any errors displayed, Sn1per may not be able to communicate with GVM properly. Run ```gvm-check-setup``` to check your setup again. +Run the following command to update the permissions: +```sudo chmod 777 /var/run/gvm/gvmd.sock``` + **NOTE:** This integration requires GVM 21.x and a valid Sn1per Professional v10.0 or higher to work properly. To integrate GVM 21.x vulnerability scans into Sn1per Professional v10.0 or higher, create a copy of the default Sn1per configuration template (```cp -vf /sniper/conf/default /sniper/conf/gvm_vulnerability_scan.conf```) and enter the appropriate values for the following: @@ -16,6 +19,19 @@ OPENVAS_RUNAS_USER="kali" **NOTE:** You will need to specify a local (non-root) Linux account to initiate GVM 21.x scans using Sn1per by updating the "OPENVAS_RUNAS_USER" setting in your Sn1per configuration file. +To test your setup, run the following commands: +``` +su - $OPENVAS_RUNAS_USER # Where $OPENVAS_RUNAS_USER is the non-root Linux account you setup +gvm-cli socket --xml "" +``` + +This will prompt for your OpenVAS username and password. Once entered, it should display the following: +``` +Enter username: admin +Enter password for admin: +21.4 +``` + After the settings have been updated to match your environment, you can initiate an OpenVAS scan automatically by running a "normal" or "vulnscan" mode in Sn1per Professional and specifying the new configuration template you just created (ie. /sniper/conf/gvm_vulnerability_scan.conf). This can also be done from the command line by running the following: **Example Usage:**