标签: OpenVAS

  • 使用 Docker 部署 Greenbone Community Edition(GCE):打造你的本地漏洞扫描平台

    一、GCE 简介

    Greenbone Community Edition(GCE) 是由 Greenbone Networks 维护的开源安全漏洞扫描解决方案,基于知名的 OpenVAS(Open Vulnerability Assessment System) 项目构建。它包括:

    • GSA(Greenbone Security Assistant):图形化 Web 管理界面;
    • GVMD:扫描调度与管理守护进程;
    • OpenVAS Scanner:扫描引擎;
    • Greenbone Community Feed:开源漏洞数据库(每日更新);
    • GVM-Tools:命令行工具,支持远程自动化控制。

    GCE 是企业级 Greenbone GSM 产品的免费替代方案,非常适合中小企业、个人研究人员、DevSecOps 团队部署。

    二、安装Docker

    $ curl -fsSL https://get.docker.com -o get-docker.sh
    $ sudo sh get-docker.sh

    三、部署Greenbone Community Edition(GCE)

    1. 保存 docker-compose.yml 文件
    2. 运行以下命令启动服务:
    docker compose up -d
    1. 容器启动后,访问 Web 管理界面:
    http://<服务器IP>:9392
    登录默认管理员账户/密码:admin

    首次启动可能需要等待几分钟,用于加载漏洞数据库、初始化服务。

    name: greenbone-community-edition
    
    services:
      vulnerability-tests:
        image: registry.community.greenbone.net/community/vulnerability-tests
        environment:
          FEED_RELEASE: "24.10"
        volumes:
          - vt_data_vol:/mnt
    
      notus-data:
        image: registry.community.greenbone.net/community/notus-data
        volumes:
          - notus_data_vol:/mnt
    
      scap-data:
        image: registry.community.greenbone.net/community/scap-data
        volumes:
          - scap_data_vol:/mnt
    
      cert-bund-data:
        image: registry.community.greenbone.net/community/cert-bund-data
        volumes:
          - cert_data_vol:/mnt
    
      dfn-cert-data:
        image: registry.community.greenbone.net/community/dfn-cert-data
        volumes:
          - cert_data_vol:/mnt
        depends_on:
          - cert-bund-data
    
      data-objects:
        image: registry.community.greenbone.net/community/data-objects
        environment:
          FEED_RELEASE: "24.10"
        volumes:
          - data_objects_vol:/mnt
    
      report-formats:
        image: registry.community.greenbone.net/community/report-formats
        environment:
          FEED_RELEASE: "24.10"
        volumes:
          - data_objects_vol:/mnt
        depends_on:
          - data-objects
    
      gpg-data:
        image: registry.community.greenbone.net/community/gpg-data
        volumes:
          - gpg_data_vol:/mnt
    
      redis-server:
        image: registry.community.greenbone.net/community/redis-server
        restart: on-failure
        volumes:
          - redis_socket_vol:/run/redis/
    
      pg-gvm:
        image: registry.community.greenbone.net/community/pg-gvm:stable
        restart: on-failure
        volumes:
          - psql_data_vol:/var/lib/postgresql
          - psql_socket_vol:/var/run/postgresql
    
      gvmd:
        image: registry.community.greenbone.net/community/gvmd:stable
        restart: on-failure
        volumes:
          - gvmd_data_vol:/var/lib/gvm
          - scap_data_vol:/var/lib/gvm/scap-data/
          - cert_data_vol:/var/lib/gvm/cert-data
          - data_objects_vol:/var/lib/gvm/data-objects/gvmd
          - vt_data_vol:/var/lib/openvas/plugins
          - psql_data_vol:/var/lib/postgresql
          - gvmd_socket_vol:/run/gvmd
          - ospd_openvas_socket_vol:/run/ospd
          - psql_socket_vol:/var/run/postgresql
        depends_on:
          pg-gvm:
            condition: service_started
          scap-data:
            condition: service_completed_successfully
          cert-bund-data:
            condition: service_completed_successfully
          dfn-cert-data:
            condition: service_completed_successfully
          data-objects:
            condition: service_completed_successfully
          report-formats:
            condition: service_completed_successfully
    
      gsa:
        image: registry.community.greenbone.net/community/gsa:stable
        restart: on-failure
        ports:
          - 9392:80
        volumes:
          - gvmd_socket_vol:/run/gvmd
        depends_on:
          - gvmd
      # Sets log level of openvas to the set LOG_LEVEL within the env
      # and changes log output to /var/log/openvas instead /var/log/gvm
      # to reduce likelyhood of unwanted log interferences
      configure-openvas:
        image: registry.community.greenbone.net/community/openvas-scanner:stable
        volumes:
          - openvas_data_vol:/mnt
          - openvas_log_data_vol:/var/log/openvas
        command:
          - /bin/sh
          - -c
          - |
            printf "table_driven_lsc = yes\nopenvasd_server = http://openvasd:80\n" > /mnt/openvas.conf
            sed "s/127/128/" /etc/openvas/openvas_log.conf | sed 's/gvm/openvas/' > /mnt/openvas_log.conf
            chmod 644 /mnt/openvas.conf
            chmod 644 /mnt/openvas_log.conf
            touch /var/log/openvas/openvas.log
            chmod 666 /var/log/openvas/openvas.log
    
      # shows logs of openvas
      openvas:
        image: registry.community.greenbone.net/community/openvas-scanner:stable
        restart: on-failure
        volumes:
          - openvas_data_vol:/etc/openvas
          - openvas_log_data_vol:/var/log/openvas
        command:
          - /bin/sh
          - -c
          - |
            cat /etc/openvas/openvas.conf
            tail -f /var/log/openvas/openvas.log
        depends_on:
          configure-openvas:
            condition: service_completed_successfully
    
      openvasd:
        image: registry.community.greenbone.net/community/openvas-scanner:stable
        restart: on-failure
        environment:
          # `service_notus` is set to disable everything but notus,
          # if you want to utilize openvasd directly, remove `OPENVASD_MODE`
          OPENVASD_MODE: service_notus
          GNUPGHOME: /etc/openvas/gnupg
          LISTENING: 0.0.0.0:80
        volumes:
          - openvas_data_vol:/etc/openvas
          - openvas_log_data_vol:/var/log/openvas
          - gpg_data_vol:/etc/openvas/gnupg
          - notus_data_vol:/var/lib/notus
        # enable port forwarding when you want to use the http api from your host machine
        # ports:
        #   - 127.0.0.1:3000:80
        depends_on:
          vulnerability-tests:
            condition: service_completed_successfully
          configure-openvas:
            condition: service_completed_successfully
          gpg-data:
            condition: service_completed_successfully
        networks:
          default:
            aliases:
              - openvasd
    
      ospd-openvas:
        image: registry.community.greenbone.net/community/ospd-openvas:stable
        restart: on-failure
        hostname: ospd-openvas.local
        cap_add:
          - NET_ADMIN # for capturing packages in promiscuous mode
          - NET_RAW # for raw sockets e.g. used for the boreas alive detection
        security_opt:
          - seccomp=unconfined
          - apparmor=unconfined
        command:
          [
            "ospd-openvas",
            "-f",
            "--config",
            "/etc/gvm/ospd-openvas.conf",
            "--notus-feed-dir",
            "/var/lib/notus/advisories",
            "-m",
            "666",
          ]
        volumes:
          - gpg_data_vol:/etc/openvas/gnupg
          - vt_data_vol:/var/lib/openvas/plugins
          - notus_data_vol:/var/lib/notus
          - ospd_openvas_socket_vol:/run/ospd
          - redis_socket_vol:/run/redis/
          - openvas_data_vol:/etc/openvas/
          - openvas_log_data_vol:/var/log/openvas
        depends_on:
          redis-server:
            condition: service_started
          gpg-data:
            condition: service_completed_successfully
          vulnerability-tests:
            condition: service_completed_successfully
          configure-openvas:
            condition: service_completed_successfully
    
      gvm-tools:
        image: registry.community.greenbone.net/community/gvm-tools
        volumes:
          - gvmd_socket_vol:/run/gvmd
          - ospd_openvas_socket_vol:/run/ospd
        depends_on:
          - gvmd
          - ospd-openvas
    
    volumes:
      gpg_data_vol:
      scap_data_vol:
      cert_data_vol:
      data_objects_vol:
      gvmd_data_vol:
      psql_data_vol:
      vt_data_vol:
      notus_data_vol:
      psql_socket_vol:
      gvmd_socket_vol:
      ospd_openvas_socket_vol:
      redis_socket_vol:
      openvas_data_vol:
      openvas_log_data_vol: