Nessus (32 bit) offers a remote security scanner. It is designed to remotely audit a given network and determine whether it is vulnerable to hackers or other types of malicious attacks. Nessus will detect all used ports and physically test their security. It does not make its security assessment based on the version number of the remote services, but will exploit the vulnerability. Nessus features high-speed discovery, configuration auditing, asset profiling, sensitive data discovery, patch management integration, and vulnerability analysis of your security posture. Nessus scanners may be distributed throughout an entire enterprise, inside DMZs, and across physically separate networks.
Inexpensive and easy to use, if the product completes scans
Cons
Miercom issued Consumer Advisory "WARNING" 20July2010:
Tested with mutliple operating systems in our lab, product will cause frequent crashes of the host machine.
Frequent cyclic error spawning lauch of start menu.
Application freezes mid scan.
Summary
Install this product at your own risk.
Licensed version of the product is suspect as well.
Contact reviews@miercom.com for additional details and to learn if the provider corrected the problem.<br /><br /><span class='notifyMsg'> Updated </span>on Jul 20, 2010<p/>Working with vendor's technocial support this issue was resolved.
RJS
A solid option for a supported vulnerability scanner
Tisiphne
Pros
Fairly industry-standard tool, runs scans against many different platforms, vulnerabilities, and scan types. The free version remains useful for students and individuals.
Cons
Nmap NSE is quickly catching up in capacity as a 100% free alternative, although at time of writing, Nmap has no plans to provide paid support. Nessus is becoming quite pricey, but not from the perspective of fortune 1000 IT departments.
Summary
Nessus had more potential as an open-source application, but the developers had good reasons for making the business decisions that they made. It remains one of the most popular and reliable scanners available. It is not a replacement for an experienced pen-tester or appliance, but it does quite well at showing the user an overview of common vulnerabilities in a clear and concise manner.
Good solid product
hackertarget
Pros
Solid product with decent support from Tenable.
Good performance, testing servers for thousands of vulnerabilities in only a few minutes.
Easy to install - version 4 is even easier, giving even non-technical users access to vulnerability managment.
Cons
Full plugin feed now costs $1200 / year. For the professional feed.
Occasional false positives.
Summary
For many years Nessus was the leading vulnerability scanner as an open source product. This has not changed, it is still an excellent product. While an open source alternative exists in openVas, it is at present not as easy to install and get configured. Vulnerability assessment is a specialised field and getting the most out of these tools does require some background knowledge or research. However this tool is an option for those wanting to get an idea of the security of a system they run. Obvious security holes will be clearly marked as critical and able to be remediated.