Jump to content

Howdy, 

 

I'm doing a piece of coursework on Risk Analysis and I have been looking for a good library of common vulnerabilities that is easy to use and links vulnerabilities to specific pieces of software and hardware. I'm not sure if such a library exists, but I will take anything that helps.

If you want to reply back to me or someone else USE THE QUOTE BUTTON!                                                      
Pascal laptops guide

Link to comment
https://linustechtips.com/topic/912400-good-vulnerability-libraries/
Share on other sites

Link to post
Share on other sites

Look up CVEs, there are a lot of published vulnerabilities there by various vendors.

https://cve.mitre.org/cve/

Current Network Layout:

Current Build Log/PC:

Storage Server Setup:

 

Prior Build Log/PC:

Link to post
Share on other sites

There's also a CWE (common weakness enumeration) database.

https://cwe.mitre.org/

 

CWE, CCE, CPE, CWE, CVSS, XCCDF, OVAL and etc all falls under the SCAP (Security Content Automation Protocol).  You should get familiar with it for your study.

 

If you want a VM with pre-exist vulnerabilities to play with, you can start with OWASP Broken Web Applications Project.

https://www.owasp.org/index.php/OWASP_Broken_Web_Applications_Project

 

Some free scanners to scan for vulnerability includes:

Nessus Home - https://www.tenable.com/products/nessus-home

OpenVAS - http://www.openvas.org/

OpenSCAP - https://www.open-scap.org/

Nexpose - https://www.rapid7.com/products/nexpose/

Retina Community - https://www.beyondtrust.com/products/retina-network-community/

 

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×