The GFI LanGuard network scanner is a popular network and security tool for scanning and resolving security vulnerabilities. Today, there are tens of thousands of customers that use the product. Like any security scanner, the GFI LanGuard network scanner provides the capability for you to scan your ports and networks to identify and resolve security vulnerabilities. GFI LanGuard provides over 15,000 vulnerability assessments when your network and virtual environments are scanned. Once scanned, you can analyze your network security state and take action to secure the network before it is compromised.
These capabilities enable any organization to more quickly determine the risk of your current network configurations, and then reach a more secure state as quickly as possible. GFI LanGuard performs network scans based upon the use of published vulnerability databases. GFI LanGuard network scanner uses data from both OVAL and SANS Top 20.
GFI LanGuard network scanner also has an important network audit function. The software will retrieve hardware information on motherboards, memory, display adaptors, various processors, storage devices, printers, ports in use, and more. You can compare the data from this new scan to determine if any hardware was added or removed since the last scan. Perhaps more important, the GFI LanGuard network scanner can also report on shadow IT software installations (unauthorized software), provide the necessary alerts for your information technology (and possibly your governance and compliance teams). It is also possible to configure the system to automatically deinstall the offending applications.
As noted earlier, over 15,000 vulnerability assessments are made as networks are scanned. GFI LanGuard gives you the capability to perform multi-platform scans and network audit functions to understand how all the configured ports are set up. This includes Windows, Mac, Linux and more extended across all environments including Virtual Machines. The goal is to be able to identify and mitigate any vulnerabilities before a threat actor can do so.
The GFI LanGuard network scanner also easily creates custom vulnerability checks. The software includes a set-up wizard. There is also a scripting engine compatible with Python and VBScript. This comes with a script editor and debugger. GFI LanGuard also makes use of a graphical threat level indicator. This provides an easy-to-understand, weighted assessment of the vulnerability status of a scanned computer. It may also provide a link to a BugTraq ID or a Microsoft Knowledge Base ID.
GFI LanGuard can help you deploy service packs and patches throughout your networks. It provides you capabilities such as patch auto-download and patch rollback. Your network admin has the option to either to manually approve each patch or set all Microsoft updates as approved.
The GFI LanGuard network scanner will also identify detailed information about the hardware configuration of all the scanned machines on your network. This includes motherboard, processors, memory, storage devices, display adapters, and much more. You can now check whether any hardware was added or removed since your last scan.
Every year the SANS Institute compiles a list of the top 20 Internet security attack targets and details vulnerabilities that certain pieces of software should be patched for. But how do you know if your computer is at risk? Norton won't help you here; you aren't dealing with viruses. SANS recommends using a vulnerability scanner. As you are probably already thinking, I will be reviewing an application called LANguard Network Security Scanner that is a vulnerability scanner and much more.
My first impression of LANguard gave me an immediate sense of who the intended user should be - a professional IT guy, paranoid Internet user or run of the mill network admin. In a nutshell, LANguard is very powerful, sophisticated software that the general web populace won't be able to get their head around. Heck, I've scratched my head a few times digging through LANguard and I once had aspirations of pursuing CompTIA Network+ certification.
As the name implies, LANguard excels at large-scale vulnerability scanning - such as on a corporate LAN. It has options for scanning a range of computers, a list of computers as well as a domain or workgroup. However, network security scanning isn't the only thing it can do. LANguard also integrates patch management and network auditing. Once you've identified vulnerabilities on a local or networked computer, patching it is as easy as right-clicking.
GFi LANguard version 8.0 was released only a few weeks ago and boasts the ability to scan entire networks for over 15,000 vulnerabilities. As I mentioned earlier, LANguard is definitely geared towards computer/network experts in charge of keeping a network of computers healthy. If you fall into that category, I see no reason why you shouldn't check out LANguard. Hopefully, you'll be able to get your company to pay for it. LANguard isn't cheap with introductory pricing of 575 for a 32 IP license.
In a corporate environment, every computer connected to the network poses a security threat. As more and more computers get added into the network each day, the security risk associated with them only increases further. There is an imminent need to make sure that these computers are patched so they don't have any security holes which can be exploited by an attacker.
The burden of maintaining several tasks related to every system is huge, and verifying that every system is secure is very troublesome. This is where tools like GFI Languard come to the rescue. This article provides details about GFI Languard which can be used for network vulnerability assessments, patch management, security compliance and more.
Visit -security-vulnerability-scanner, click on free trial, provide the necessary information, and then download the setup. The trial key will be sent to the email address you provided, so make sure you use valid credentials. After downloading, double click the setup file to install, which is pretty simple and straight forward. Launch GFI Languard once it's done. The home screen looks like this:
Scanning profiles enable you to scan the target systems and look only for specific information based on the profile selected. For instance, a scanning profile you might choose for your DMZ may be different from the one you choose for the internal network. These profiles help your vulnerability program to focus on a specific area of interest, say open ports or security updates. This flexibility helps you to quickly identify your concerned area of interest and get the information.
The 'Remediation Center' allows you to fix the issues found during a network scan. It can be accessed under the Remediation tab. Software updates can be deployed with a single click by selecting the computer and the updates. Similarly, unauthorized applications can also be uninstalled by simply selecting them and clicking uninstall. The tool also automatically downloads patches and service packs, and it can also deploy these updates all over the network, as well as recall any patches that were deployed.
The Dashboard is an important section to know about, as it displays the data that has been gathered during the scan or audit process. It provides you information about the number of computers connected to the network, vulnerable systems, overall network vulnerability level, etc.
You can deploy the agents automatically on newly discovered computers or on selected computers. The main advantage of deploying agents on systems is it reduces the audit time and also helps preserve the network's bandwidth.
Identifies domains and workgroups present on a network, their underlying operating systems, and any other information which can be obtained through NETBIOS. You can use this tool to launch a security scan on the identified systems. To do this, just right click on any system and click scan. Similarly, this can be used to deploy custom patches and third party software on enumerated computers.
This tool identifies and reports weak SNMP community strings by performing a dictionary attack using the default values. However, you can edit the community strings file by using a text editor use other dictionary files to accomplish the same. This can be done by specifying the path to the dictionary file that you want to use from the tool options at the right side of the management console. SNMP activity is generally blocked at the firewall level so that internet users cannot SNMP scan your network. Unless this service is required, it is highly recommended to disable it.
This article is all about the network vulnerability scanner GFI Languard. We have seen how to use the tool to scan the network, monitor its activities, and remediate the vulnerabilities discovered. We have also discussed the other features which are available in this tool to make your network more secure.
Protecting the network and managing patches
Often times, one can face problems about security, patch management and network control: these operations, like many others, are usually carried out with the aim of several, different software thus making the job hard to organize in a centralized manner. GFI LanGuard perfectly fits in such a context so hard to keep up with: the three pillars of vulnerability management are contained within a single piece of software, an overall package that allows you to keep networks under control and guarantee their protection.
GFI LanGuard is a network security scanner and patch management system with optimal network mapping and in-depth risk analysis capabilities, all done before security breaches happen because of the lack of network patches.
GFI LanGuard can be installed on a Windows platform and, from the console, you can scan the whole network to find every connected devices like physical servers or VMs, notebooks, PCs, smartphones, printers and network gear like switches, routers and access points. Once the analysis is done, GFI LanGuard verifies any potential security issue.
760c119bf3