Offline update Nessus Vulnerability Scanner 3.x plugins

Nessus vulnerability scanner is a tool which can discover and analyze vulnerabilities in the system so that IT staff can fix that holes and hence the system becomes more secure. Before scanning the system, it is necessary to update Nessus’s plugins to make sure that it’s up-to-date and will able to detect the latest vulnerabilities. If you have a disconnected network from the Internet, you need to update the Nessus’s plugins manually.

This article will show you how to offline update Nessus 3.2.1′s plugins with free subscription on Windows. With free subscription, you can only get plugins that delayed 7 days. Otherwise, you need to purchase for the latest plugins. If you have disconnected network from the Internet, I think using free plugins would be sufficient.

Sections

  1. Register at Nessus for activation code
  2. Download plugins
  3. Extract and build plugins on Nessus 3.2.1

Step-by-step to offline update Nessus

Register at Nessus for activation code

  1. Navigate to www.nessus.org. Click on ‘Plugins’.
    Open web browser to 'www.nessus.org'
  2. Click on ‘Obtain an activation code’.
    Obtain an activation code
  3. Scroll down to the bottom of the page, click ‘Register’ on the FREE subscription.
    Register on Free subscription
  4. Click ‘I accept’ to accept the agreement.
    Accept the agreement
  5. Enter your e-mail address and click register. Nessus will send an activation code to this e-mail.
    Enter your e-mail address
  6. Now e-mail has been sent with the activation code.
    The activation code has been sent
  7. Check your e-mail and you should see the activation code.
    Check your e-mail to see the activation code

Back to top

Download plugins

  1. To download the plugins, you need an activation code and challenge code. You already have an activation code. Now you need to find a challenge code.
  2. Install Nessus 3.2.1 to get a challenge code.
  3. When finishes the installation. Open Product Registration to see the challenge code. Open Start -> Programs -> Tenable Network Security -> Nessus -> Product Registration.
  4. On Product Registration, you’ll see the challenge code. This will be used with the activation code to download Nessus’s plugins.
    Open Product Registration
  5. Navigate to plugins.nessus.org/offline.php. Copy the challenge code to the first line and the activation code that you received from an e-mail to the second line. Click submit.
    Note: You can only use your activation code once. If you need to download again, you have to register again (you can use the same e-mail).
  6. Click on the link ‘http://….’ to download the plugins.
    Download the plugin

Back to top

Extract and build plugins on Nessus 3.2.1

  1. Extract the downloaded file (.tar.gz) to C:\Program Files\Tenable\Nessus\plugins\scripts. You have to extract .tar.gz to .tar first and then extract the file again to that directory. It will ask to overwrite the existing files, select Yes to All.
    Note: To extract the file, you can use tools like WinZip, WinRar, 7Zip, etc.
    Extract the file
  2. Waiting until the extraction is finished.
    Extract the file
  3. Once finishes, run this file C:\Program Files\Tenable\Nessus\build.exe by double-click the file.
    Build the plugins
  4. Waiting the program rebuilds plugins. When finishes, the window will disappear.
    Build the plugins
  5. Now Nessus is up-to-date and should be ready to scan the system.
  6. Nessus is now up-to-date

Back to top

Summary

This article is show how to update plugins on Nessus 3.x on Windows which was already documented at Nessus.org. But I want to summarize with illustration to make it simple and easy to follow guide.

4 Responses to “Offline update Nessus Vulnerability Scanner 3.x plugins”

  1. Shaun

    This was such an informative, relevant answer. It was exactly what I was looking for. I’m so happy to know I’ll be getting something out of you posts.

  2. Biloy R. Lasala

    In the Philippines they say “maraming salamat” which means Thank you so much for the shared information

  3. rfquinn

    Thanks! I’ve been looking for awhile on how to do an offline plug-in install. Hopefully this will work with version 4.2.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>