0:13
hello everyone Welcome to Johnny's
0:15
Nessac YouTube channel Uh in this video
0:19
I'm going to use Tina Nesses to show you
0:23
how to execute a compliance scan to your
0:28
database Previously I had a few videos
0:31
talk about how to install tin and how to
0:35
execute vulnerability scanning web
0:38
application scanning I was using tin
0:41
nesters essential version Unfortunately
0:45
essential version has some limitation It
0:48
doesn't support compliance check The
0:51
compliance check is something to check
0:54
your system configuration against those
0:57
popular standard such as CIS benchmarks
1:02
PCI ITO HIPPA tinuses is well known as
1:09
their vulnerability scanning capability
1:12
but actually compliance scanning is one
1:15
of the most important features as well
1:18
The reason why is even your system
1:21
doesn't have any vulnerabilities it
1:24
doesn't mean your system is configured
1:27
properly A compliance check will tell
1:29
you how your system has been configured
1:32
comparing to those popular standard I'm
1:36
going to use Ness's expert version which
1:41
does support compliance check to show
1:44
you how we can configure this kind of
1:48
scanning how easy it is to configure it
1:51
If you don't have NES professional
1:54
version or next version you may look at
1:57
one of my old videos to figure out how
2:00
you can get one to install on your
2:03
virtual machine and then play with it
2:06
For now let's jump into the
2:08
configuration and let me show you how we
2:11
can create a compliance check against
2:21
As a demo I'm going to use one of my
2:25
virtual machines in the cloud to install
2:28
my SQL database It's going to be one
2:31
line of Docker command to bring this
2:34
MySQL docker up and running Then we can
2:38
use Tinderable Nessus to do compliance
2:41
check Here is the public IP I already
2:50
internet So as you can see this allow
2:53
any my SQL inbound So this inbound rule
2:56
going to allow our necess scanner to
3:00
scan it from anywhere on port
3:03
3306 I already sshed in for us to bring
3:08
up our MySQL docker Just one line
3:11
command I already have Docker installed
3:14
If you haven't installed Docker
3:16
previously just using a command to
3:19
install Docker.io I'm going to paste
3:22
this command in So our Docker going to
3:25
run it on port 306 The Docker name is
3:28
test dash MySQL and the root password is
3:33
the one for us going to login If you
3:35
want to use in different account then
3:38
you have to follow Tinder's guidance to
3:42
grant proper permission for that account
3:45
to execute the scan and we're going to
3:48
use in my SQL 8.2 to this version since
3:52
I already installed it before this time
3:55
I don't have to pull the image that's
3:57
how simple you can get your my SQL
4:05
testing as mentioned before I'm going to
4:08
use tin nexus expert this version to
4:13
configure compliance scan and execute a
4:17
compliance scan to our MySQL database
4:20
this So this is the one I did before and
4:24
you can see total 55 compliance check
4:29
and there's only quite a few of them
4:32
passed most of them failed or has a
4:35
warning sign to achieve this of course
4:38
we need to have connection from your
4:42
tinable neess's system to the myql
4:44
database we're going to use my SQL shell
4:48
to verify that before before we can
4:50
start it So we want to make sure we can
4:52
connect to our database from our nesters
4:55
So we're going to use command
4:59
connect and then we're going to put the
5:04
IP It will going to ask you the password
5:07
of course if everything goes well you
5:10
have opened firewall port on your
5:14
network security group If you have bring
5:17
your docker up and then the port is
5:21
3306 then you should be able to see this
5:24
message save password that's the
5:27
confirmation you have connection so you
5:30
to save it just enter then by default it
5:35
will not saving your password but you
5:38
confirmation server version 8.2
5:41
to my SQL community server That's
5:46
important for us to do all the check
5:48
Since we verify the connection now we
5:50
can start to configure
5:55
it To configure a compliance scan is the
6:00
same as you do the vulnerability scan
6:02
Just create a new scan You should be
6:04
able to see this policy compliance
6:06
auditing scan You also can do cloud
6:11
infrastructure scanning audit scanning
6:14
compliance audit scanning Of course PCI
6:17
also included You can do internal PCI or
6:22
you can do external PCI quarterly scan
6:25
Those are PCI requirement For today's
6:28
scan we just do pol compliance
6:31
auditing We're going to do test my SQL
6:36
compliance check So we're going to save
6:38
it in the compliance folder and the
6:41
target is our MySQL DB's public IP since
6:46
we put into the cloud No other changes
6:50
tab But you do need to configure
6:53
credentials Keep that in mind Whenever
6:56
you do compliance scanning it has to be
6:59
authentication scan and it has to be
7:01
certain privileged scanning as well
7:04
So there's a categories since we are
7:07
database we can choose database and then
7:10
here we can choose different type of
7:13
database here you can do DB2 or O or O
7:16
or Oracle but we're going to do my SQL
7:19
So authentication type is password since
7:22
we are going to using loot and
7:25
password This is important to put right
7:30
credential in If you don't want to use
7:32
your loot account then you have to grant
7:36
your normal account this select
7:40
permission I'm going to use loot account
7:43
for this setting to make things simple
7:47
easy The second thing is
7:52
compliance You can search my
7:56
SQL compliance There's quite a
8:01
building MySQL compliance audit file for
8:06
you to select You also can upload a
8:09
custom MySQL DB audit file If you
8:12
couldn't find your right version
8:15
probably you need to download it We are
8:18
using 8.0 If you couldn't find 8.0
8:21
material from this list you need to go
8:25
tinable audit portal to download my SQL
8:30
file So here you will find all pre-built
8:34
my SQL audit file for 8.4 8.0 So we are
8:39
using my SQL community edition So we are
8:44
not using enterprise edition So that's
8:46
important and also there's two level So
8:50
this is the one we're going to download
8:52
says 8.0 community database L1 version
8:55
1.1 is L1 and we also have L2 as well So
9:02
search this is L1 We're going to search
9:08
L2 So as you can see there's a community
9:11
database L2 and L1 both are here So we
9:14
can download those and then import them
9:17
into our nest system So we do upload and
9:22
we add file So I already download both
9:26
of them So I can add both of them
9:29
in open You can do save
9:40
SQL Just add another one
9:43
You can addit multiple one here Upload
9:49
file We have level two We just add level
9:56
save Now you finish the
10:04
configuration Here is our last step We
10:07
just need to launch the scan There's a
10:11
launch button at the end
10:15
So this going to launch test my SQL
10:18
compliance check You can click in to see
10:21
the process Now it shows
10:25
running Based on my previous testing it
10:28
only take two three minutes to finish
10:31
one compliance check for my SQL database
10:34
If your network connection is good So I
10:37
will come back to show you the result
10:42
In 3 minutes the scan has been completed
10:48
348 That's our host So the compliance
10:52
result we have 20 failed 21 warning and
10:59
passed Better than the one we did before
11:03
But still it's quite a lot failed here
11:08
You can click in to see the solution
11:14
output Based on this result you can pass
11:17
a report to your database admin for land
11:20
to check to see if there's anything they
11:23
can change to make this configuration to
11:27
be more compliant to the standard which
11:31
your company is following So that's
11:34
pretty much everything for this video I
11:36
hope you enjoyed it If you do please
11:39
give me a thumb up and also subscribe my
11:43
channel See you in my next video