server security audit

Hello everyone,

I'm trying to see my my server is secure or not.
I would like to know what tools do you guys use to audit your security audit on your FreeBSD boxes?
Ideally I would like something that will have an report at the end so I know what to fix.

Could you also tell me what professional services you used that doesn't cost the earth.

Thank you all in advance.

Fred
 
The most advanced IMHO is Nessus. But you need a computer to install it and run it. It takes some sort of technical knowledge to tune, etc. But works.
 
atmosx said:
The most advanced IMHO is Nessus. But you need a computer to install it and run it. It takes some sort of technical knowledge to tune, etc. But works.

Thank you i'll look into it :)
 
The "problem" with security/vulnerability scanners like Nessus is that it requires someone knowledgeable to interpret the scan results. Don't blindly accept anything these applications might throw at you. You also want to be careful with the types of scan you run with them. Some can actually crash the machine you're testing.
 
SirDice said:
The "problem" with security/vulnerability scanners like Nessus is that it requires someone knowledgeable to interpret the scan results. Don't blindly accept anything these applications might throw at you. You also want to be careful with the types of scan you run with them. Some can actually crash the machine you're testing.
Thank you
 
Back
Top