This document is supplied on an "as is" basis with no warranty and no support. Limitations of Liability In no event shall eEye Digital Security be liable for errors contained herein or for any direct, indirect, special, incidental or consequential damages (including lost profit or lost data) whether based on warranty, contract, tort, or any other legal theory in connection with the furnishing, performance, or use of this material.
Collateral Information ..............................1 Installation ..................................1 Installation Requirements ..............................1 Installing Retina from the CD-ROM..........................1 Opening the Installation Wizard with Run Dialog ......................7 Installing Retina from the Command Line ........................8 Uninstalling Retina...............................10 Uninstalling Retina from the Command Line.......................12 Retina Sessions................................13 Starting Retina................................13 Startup Message..............................13...
Viewing Previous Jobs from a DSN ..........................60 Auto Update...................................61 What is Auto Update..............................61 Manual Update ................................62 License Management..............................65 Running Retina for the First Time ..........................65 Migrating Retina to a New Machine ..........................65 Terminating a License ..............................66 Retina Audit Wizard ..............................67 Using the Plugins Wizard.............................79 Using Retina From the Command Line ........................80...
Page 5
Table of Contents Retina Users Manual Glossary..................................82...
Introduction Preface The Retina Network Security Scanner is designed to work in conjunction with your existing systems, networks, security packages, databases, and user interfaces. This enables you to proactively guard against intrusion by regularly testing the integrity of your network to uncover and fix potential security weaknesses.
• Internet connection Installing Retina from the CD-ROM If you meet the system requirements specified above, complete the following steps to install Retina from the provided CD-ROM. eEye recommends that you exit all Windows™ programs before you run the Retina Installation Wizard Insert the Retina CD into your workstation’s CD-ROM drive.
Page 8
Installation Retina Users Manual 2. Click Next >. The License Agreement window appears.
Page 9
Installation Retina Users Manual Review the End-User Software License Agreement. You must accept the license agreement to continue using the Retina Installation Wizard. 3. Click Yes. The Destination Folder window appears.
Page 10
Installation Retina Users Manual This window allows you to select the directory where the installation wizard will install the Retina files. 4. Do one of the following: • Accept the default destination folder: C:\Program Files\eEye Digital Security\Retina 5\. • Click Browse, and select a folder where you want the Retina files to be installed.
Page 11
Installation Retina Users Manual 6. Click Next >. The install program displays a progress bar and shows the files as the application copies them to your system.
Page 12
Installation Retina Users Manual Once Retina is completely installed, the following screen displays to confirm a successful installation.
Opening the Installation Wizard with Run Dialog Complete the following steps to open the Retina Installation Wizard from Windows™ Run Dialog rather than directly off the CD-ROM. eEye recommends that you exit all Windows™ programs before you run the Retina Installation Wizard.
5. Click OK. One of the following occurs: • If you entered the correct path for R e t i n a S e t u p . e x e , the Welcome window of the Retina Installation Wizard appears.
Page 15
• CREATEDESKTOPICON=”0” – Disables creation of a desktop icon for Retina. This option is enabled by default. Set to 0 to prevent creation of the icon. • CREATEQUICKLAUNCH=”0” – Disables creation of a quick launch icon for Retina. This option is enabled by default. Set to 0 to prevent creation of the icon.
Installation Retina Users Manual 6. Go to step 3 of Installing Retina from the CD-ROM for procedures on using the Retina Installation Wizard to install Retina. Uninstalling Retina Complete the following steps to remove Retina from your workstation using the Retina Uninstall Wizard. eEye recommends that you exit all Windows™...
Page 17
Windows™ displays a prompt to allow you to continue the uninstall of Retina. Select Yes to continue. 6. The uninstall displays a prompt asking if you would like to remove your Retina license from the machine. Select Yes to remove the license, or No to keep the license for later use on the same machine.
Uninstalling Retina from the Command Line Complete the following steps to remove Retina from your workstation using the Windows™ Installer from the command line. eEye recommends that you exit all Windows™ programs before you run the Windows™ Installer.
“WarningInfo.htm” in the Retina installation directory. This file will display in a text box when Retina starts. The user will have to click the OK button to start Retina or close the window to abort it. This text box is an HTML display control, so common HTML elements may be used to add text formatting.
Page 20
Other Places: appears below the Tasks shortcut bar at the middle left pane of the Retina Interface window. This displays the Retina tasks (except the task that is currently selected) that you can select and use such as Audit, Reports, Remediate, and Options.
Retina uses the status bar at the bottom of the window to display messages from the task Retina is currently processing. Tabs Pane The Tabs pane is the main window of the Retina Interface. It displays tabs you can select to use the features associated with each Retina task. You can select from the following tabs: Discover...
Retina Users Manual Using the Getting Started Wizard The Retina Getting Started Wizard provides a brief introduction to using the Retina Network Security Scanner to perform a vulnerability scan and analyze the results. Complete the following procedure to use the Retina Getting Started Wizard: 1.
Page 23
Installation Retina Users Manual 2. Click Next > on the Retina Getting Started Wizard. The Beginning a Scan window appears.
Page 24
The Scanning a Range of IP Addresses window appears. 5. Do one of the following from the Audit tab: • Enter an IP address for Retina to scan in the Address field, or complete the following procedure to enter a range of IP addresses.
Page 25
Installation Retina Users Manual 8. Click Next > on the Retina Getting Started Wizard. The Selecting Audit Groups window appears.
Page 26
Installation Retina Users Manual 9. Click Next > the Retina Getting Started Wizard. The Analyzing Scan Results window appears.
Page 27
Installation Retina Users Manual 10. Review the scan information for the selected IP address(es) that appears in the main Retina pane of the Audit tab. The General section displays information including the IP addresses, report date, domain name, and so on.
Page 28
Installation Retina Users Manual 14. Select the Reports tab on the Retina Interface if you want to create a report of your scan results. Then, click Generate. The report you created appears in the Results pane of the Retina Interface. Use the scroll box to move vertically through the report.
Page 29
Installation Retina Users Manual 16. Click Next > on the Retina Getting Started Wizard. The Additional Information window appears.
Page 30
Installation Retina Users Manual 17. Click Finish to exit the Retina Getting Started Wizard.
Accessing the Discover Tab Complete the following step to access the Discover tab: Click the Discover tab on the Retina Interface (unless it is already selected). The following example shows the Discover tab of the Retina Interface. The Discovery Tasks shortcut bar displays the following commands that you can select. Unavailable menu options...
The Select Targets options appear. 3. You may select a number of target types from the Target Type drop-down: • Single IP – Then enter the IP address or the name of the server that you want Retina to scan in the Address field.
Page 33
4. Click Options on the Actions pane. The Options choices appear. 5. Select any of the following network options you want Retina to perform. Also, deselect any of the following default network options that you do not want Retina to perform.
• Click Pause Discovery Scan on the Discovery Tasks shortcut bar or the Pause button if you want to pause the scan and the display results. • Click the Abort button to prevent Retina from displaying additional information. • You can also select Abort Discovery Scan from the Discovery Tasks shortcut bar.
Servers, as shown in the example below. 5. Click OK. Retina saves your new address group. 6. When you want to view the list of IP addresses for the new group you created, click the Audit tab and click Modify Address Groups.
Address Groups. Clearing Discovered Items Retina provides an option that allows you to quickly clear all of the scan results that appear in the Results table. You should always clear your results before you create a new scan. Complete the following step to clear your scan results: 1.
Page 37
Date Discovered column header and drag it to the top row of the Results table as shown in the following example. Retina sorts and displays your results by the column name you selected. In the example above the table has been sorted by operating system (OS).
Accessing the Audit Tab Complete the following step to access the Audit tab: 1. Click the Audit tab (unless it is already selected) from the Retina interface. 2. The following example shows the Audit tab of the Retina Interface. The Audit Tasks shortcut bar displays the following commands that you can select. Unavailable menu options appear...
2. Click Targets from the Actions pane (unless it is already selected). The Select Targets pane appears. 3. You may select a number of target types from the Target Type drop-down: • Single IP – Then enter the IP address or the name of the server that you want Retina to scan in the Address field.
Page 40
Session Data on page 60. 5. Enter the name you will use to identify the job in the Job Name field. If you do not enter a name, Retina will prompt you for one when you click scan (you may disable that popup when you see it). If you continue past the popup without naming the job it will be named “unknown.”...
Notes On Scanning Ranges: If you enter a range, address group, or CIDR block that exceeds your licensed IP limit, Retina will audit scan the range up to the number of addresses that you have licensed. If there are more responsive targets in the range Retina will provide machine information on these systems so that you know how many there are and what types of machines there are.
Page 42
The IPs displayed in the IP list can be sorted by vulnerability or IP. The list contains all of the IP addresses that responded during a scan. Also, Retina displays an image representing the highest risk level of the audits found on the specified system.
Complete the following steps to modify a Port group: 1. If you want to enter individual port numbers or groups of ports you want Retina to scan, click the Modify button next to the Select Port Groups box on the Audit tab on the Ports sub-tab.
• To prevent a host or range of hosts from being scanned check the Omit this entry checkbox before clicking Add. • To import Retina 4.x host file (.rti) click Import and select the file in the file selection window. Click Delete to remove an address group.
Audit Groups Complete the following steps to modify an audit group: 1. Select the Audit tab from the Retina Interface (unless it is already selected). 2. Select Modify Audit Groups on the shortcut bar. The Audit Groups dialog box appears.
Hint: To keep track of what audits are updated or added in a Retina update, create a new audit group called New, unselect all audits in the group and then check the box. The next time Retina updates you can scroll down the list to see what is checked.
Page 47
Using the Audit Tab Retina Users Manual If you intend to also utilize other credentials, insure that the account used for Retina’s logon has access to the Windows registry. Note: While operating Retina in this manner presents no problem for the software, you should include this information when reporting problems to eEye®...
Username edit box, to enter a domain user ID enter the name of the domain, a backslash and the user ID i.e.: Corporate\Administrator, otherwise Retina will use the entered credentials as a local user on the target systems; the corresponding password into both the Password and the Confirm Password edit boxes. And finally enter a...
Page 49
Using the Audit Tab Retina Users Manual 5. Then select Add. You may enter a number of credentials here, by repeating steps 4 and 5. 6. To remove a stored credential, highlight the desired user name in the Username list box.
Accessing the Remediate Tab Complete the following step to access the Remediate tab: Click the Remediate tab from the Retina interface (unless it is already selected). The Remediate Tasks shortcut bar displays the following commands that you can select. Unavailable menu options appear dimmed.
• View in Web Browser Generating a Remediation Report 1. Select the Remediate tab from the Retina Interface (unless it is already selected). 2. Select the Filter tab on the Configuration section of the main window. 3. Select the report grouping, machine, and vulnerability sorting options by using the Group Report By, Sort Machines By, and Sort Vulnerabilities By drop down boxes.
Using the Remediate Tab Retina Users Manual Printing a Remediation Report To print a report, click either the Print Report button from the shortcut bar or the printer icon on the toolbar and follow the prompts. Editing a Remediation Report in Microsoft Word™...
Retina Users Manual Using the Report Tab Retina reports provide detailed information gathered by the scanner and organized into sections, including General, Audits, Machine, Ports, Services, Shares, and Users. The report, in its printable form, can be viewed by pressing the Reports button on the toolbar.
• View in Web Browser Generating a Report 1. Select the Report tab from the Retina Interface (unless it is already selected). 2. To select what sections to include in the report click on the Sections tab of the Configuration pane and check the sections you want in the report.
Using the Report Tab Retina Users Manual Printing a Report To print a report, click either Print Report on the shortcut bar or the printer icon in the toolbar, and follow the prompts. Saving a Report You can save a Report in HTML format for future use. To save a Report, in the top line menu, go to File->Save...
Scheduling Scan Jobs Retina Users Manual Scheduling Scan Jobs The Scheduler works the same for Discover scans and Audit scans. The only exception is that there can be only one Discover scan scheduled (named Discover) at any time. To get to the Scheduler click the Schedule button in either the Discover or the Audit tab.
Page 57
Scheduling Scan Jobs Retina Users Manual E. Select OK. To run the scan on a daily basis: A. Select Daily in the Frequency drop-down. B. Select the Start Time. C. Select OK. To run the scan on a weekly basis: A.
The Scan Jobs pane is available in the Audit, Remediate and Discover tabs. It consists of three sub-tabs: Active The Active tab lists jobs and their status. Jobs started from the Retina interface, the Retina command line utility or sent from a REM Events server will display here.
Page 59
Using the Scan Jobs Pane Retina Users Manual The user can also Rescan a job in the Completed tab by selecting the job in the list and clicking the Rescan button. The listed job will not be overwritten, but a new job with the same settings will be started.
Completing Scan File Procedures Retina automatically saves scans under either a generated name or using the name you entered when you started the audit scan (see Starting an Audit Scan on page 33). This section describes how to open, and delete scan files.
Retina Users Manual Options Customizing Retina You can customize Retina to meet your specific needs by using the Options Dialog, located by selecting Tools > Options. General Options You will see the Options dialog open to the General tab. This tab controls: •...
Central Policy The Enable Central Policy checkbox allows Retina to download audit files from a single REM server. The location of the REM server must be entered in the Central Policy URI text box. Check for new policies every… determines how often Retina will request updates from the REM server.
HTTP or other network protocol timeouts. They typically show up on target machines as dropped connections for other services. Though it can show up in the Retina logs in such areas as known services not being found or known open ports not being identified.
These settings are used to allow Retina to compensate for network latency. If you find that pings are not returning in time for Retina to detect them, adjust the Ping Timeout upward. If Retina doesn’t seem to be getting complete data from devices, or you are scanning hosts with services that are under heavy load, adjust the Data Timeout upward.
Retina scan results. The target database must be configured to support Retina tables. Viewing Previous Jobs from a DSN Once you have assigned a DSN to Retina, you can then use it to store scan data. By default, Retina always displays the most recent scan results when a DSN is selected.
What is Auto Update Using an Internet connection, Auto Update allows you to easily keep up with the latest Retina improvements available from eEye Digital Security. Once you have selected the Auto Update feature, Retina will update itself with the necessary files—you do not have to deal with any messy file downloads that must be manually installed.
If you would rather not be questioned about this activity each time, put a checkmark in the box next to Do not confirm this confirm this action again in the future. 2. Select Yes. The list of Sync-It supported products will be presented. If there is not already a checkmark by Retina, select it from the list.
Page 69
Manual Update Retina Users Manual 3. Select Next >. The Downloading window displays progress bars relating to the download and install of the updates.
Page 70
Manual Update Retina Users Manual 4. Select Next >. The Update Summary window appears, allowing you to review the status of the updates performed. Highlighting a product from the list allows you to see the details of the update.
Running Retina for the First Time When you run Retina for the first time, you will see the registration screen, which prompts you for a serial number. To obtain the serial number, you will first need to go to the licensing generation part of Retina’s Web site. After purchasing Retina you should have received an email containing a username and password to use to gain access to the licensing generation part of Retina’s Web site.
Retina Audit Wizard Retina Users Manual Terminating a License To terminate your Retina license, follow the steps in Uninstalling Retina (page 10) and when prompted delete the Retina license select Yes.
Retina uses to search a computer for particular security vulnerabilities. To use the Retina Audit Wizard to create a custom audit, follow the following steps. 1. Start the Retina Audit Wizard, by either selecting the Audits Wizard… from the Tools drop-down menu or by starting the Audits Wizard.exe in the Retina 5\Tools directory.
Page 74
Retina Users Manual The information you can set here is: • Audit Name – The name to give to the audit report on the Retina Interface when the audit has successfully identified a vulnerability. • Category – The category under which the audited vulnerability can be classified. The following categories are available in Retina.
Page 75
Retina Audit Wizard Retina Users Manual Registry – This category is for checks that just check Registry for the existence of a value that can be used to identify a vulnerability. Remote Access – The remote access category contains audits for security holes in remote access agents.
Page 76
Retina Audit Wizard Retina Users Manual Provide information describing how to eliminate the security hole from the system being scanned. This information can describe where to get a patch or how to change a configuration setting 3. Next you should see the Audit Type screen. After you have selected the type click Next> to continue creating the audit.
Page 77
Retina Audit Wizard Retina Users Manual 4. The next screen is the Audit Details screen and is different for each type of audit selected. Each screen is detailed below. After you have set the audit details, click the Next> button to continue audit creation.
Page 78
Retina Audit Wizard Retina Users Manual Registry Select Path, Key, or Value for the type of registry entry you will be checking. Then select does not exist or exists to test for the absence or presence of this registry item. Select the parent Hive to be searched, HKEY_CLASSES_ROOT, HKEY_CURRENT_USER, HKEY_LOCAL_MACHINE, HKEY_USERS, or HKEY_CURRENT_CONFIG.
Page 79
Retina Audit Wizard Retina Users Manual Service Pack/Hotfix If you are creating an audit to check only for Internet Information Server patches then check the Perform this audit only if IIS is installed checkbox. To check for a service pack level, select the Check to make sure service pack radio button and then fill in the service pack number in the corresponding edit box.
Page 80
Retina Audit Wizard Retina Users Manual Check File To check a file version, enter the full pathname of the file in the Check if the File Version of edit box; then select equal to, greater than, less than, greater than or equal to, or less than or equal to in the drop-down selection box;...
Page 81
Retina Audit Wizard Retina Users Manual Remote Check Remote checks are used to check for packages on non-Windows® devices. To check for a package installed on a system, enter the regular expression that will match the desired package (packages) in the Package edit box and check the Alert when matched checkbox.
Page 82
Retina Audit Wizard Retina Users Manual The Affected Operating System, Operating System drop-down box is currently only Custom. Enter the regular expression to match the desired OS in the Version String edit box. 5. The Vulnerability Details screen comes up next. If you have BugTraq® or CVE numbers for the audit enter them in the Bugtraq ID or CVE-ID edit boxes.
Page 83
Retina Audit Wizard Retina Users Manual 6. The final screen will display.
Page 84
Retina Audit Wizard Retina Users Manual At this point you can click Finish to save the audit in the audits.XML file or click Cancel to abort audit creation.
Retina Users Manual Using Retina From the Command Line In Retina 5 there are now two command line interfaces. Retina.exe can still be used from the command line with the noted changes; and the Retina RPC client can be implemented as listed.
Page 87
StartScan <scan name> This starts <scan name>, where <scan name> is the name of a scan request file in $RETINA\Jobs\ScanRequests. Scan requests have xml extensions. If <scan name> is already scheduled no action is taken. If <scan name> is an immediate job, it will be queued.
Page 88
Glossary Retina Users Manual Glossary Acceptable Use Policy: Many networks have policies in place that restrict how a network can be used. Access Control List: Most network security systems operate by allowing selective use of services. An Access Control List is the usual means by which access to, and denial of, services is controlled. It is simply a list of the services available, each with a list of the hosts permitted to use the service.
Page 89
Glossary Retina Users Manual ARP: Address Resolution Protocol. Used to dynamically discover the low-level physical network hardware address that corresponds to the high level IP address for a given host. ARP is limited to physical network systems that support broadcast packets that can be heard by all hosts on the network. It is defined in RFC 826.
Page 90
Glossary Retina Users Manual Checksum: A computed value that is dependent upon the contents of a packet. This value is sent along with the packet when it is transmitted. The receiving system computes a new checksum based upon the received data, and compares this value with the one sent with the packet.
Page 91
Glossary Retina Users Manual Daisy Chain: A local networking topology in which a single cable runs to multiple workstations. This tends to be less expensive than the alternative "star" topology, but it is also less robust. A break anywhere along the "chain" disables the entire chain.
Page 92
Glossary Retina Users Manual Electronic Frontier Foundation (EFF): A foundation established to address social and legal issues arising from the impact on society of the increasingly pervasive use of computers as a means of communication and information distribution. Electronic Mail (email): A system whereby a computer user can exchange messages with other computer users (or groups of users) via a communications network.
Page 93
Glossary Retina Users Manual Fully Qualified Domain Name (FQDN): The full domain name of a system, rather than just its hostname. For example, "brick" is a hostname and "brick.eeye.com" is an FQDN. Gateway: The original Internet term for what is now called router or more precisely, IP router. In modern usage, the terms "gateway"...
Page 94
Glossary Retina Users Manual The Internet uses the Internet protocol suite. To be on the Internet you must have IP connectivity—i.e., be able to Telnet to, or ping, other systems. Networks with only e-mail connectivity are not actually classified as being on the Internet.
Page 95
Glossary Retina Users Manual Kerberos: Kerberos is the security system of MIT's Project Athena. It is based on symmetric key cryptography. See also: Encryption. LAN: See: Local Area Network Layer: Communication networks for computers can be organized as a set of more or less independent protocols, each in a different layer (also called level).
Page 96
Glossary Retina Users Manual MDF: Main Distribution Frame. The main "telecommunications closet" in a building. Metropolitan Area Network (MAN): A data network intended to serve an area approximating that of a large city. Such networks are being implemented by innovative techniques, such as running fiber cables through subway tunnels.
Page 97
Glossary Retina Users Manual Attached to that are mid-level networks, and attached to the midlevels are campus and local networks. NSFNET also has connections out of the U.S. to Canada, Mexico, Europe, and the Pacific Rim. The NSFNET is part of the Internet.
Page 98
Glossary Retina Users Manual Octet: An octet is 8 bits. This term is used in networking, rather than byte, because some systems have bytes that are not 8 bits long. Open Shortest-Path First Interior Gateway Protocol (OSPF): A link state, as opposed to distance vector, routing protocol.
Page 99
Glossary Retina Users Manual PING: Packet Internet Groper. A program used to test reach ability of destinations by sending them an ICMP echo request and waiting for a reply. Point Of Presence (POP): A site where there exists a collection of telecommunications equipment, usually digital leased lines and multi-protocol routers.
Page 100
Glossary Retina Users Manual RBOC: Regional Bell Operating Company Reassembly: The IP process in which a previously fragmented packet is reassembled before being passed to the transport layer. See also: Fragmentation. Remote Procedure Call (RPC): An easy and popular paradigm for implementing the client-server model of distributed computing.
Page 101
Glossary Retina Users Manual SNA: Systems Network Architecture. A proprietary networking architecture used by IBM and IBM-compatible mainframe computers. SNMP: Simple Network Management Protocol. The Internet standard protocol, defined in STD 15, RFC 1157, developed to manage nodes on an IP network. It is currently possible to manage wiring hubs, toasters, jukeboxes, and so on.
Page 102
Glossary Retina Users Manual TN3270: A variant of the Telnet program that allows users to attach to IBM mainframes and use the mainframe as if they had a 3270 or similar terminal. Token Ring: A token ring is a type of LAN with nodes wired into a ring. Each node constantly passes a control message (token) on to the next;...
Page 103
Glossary Retina Users Manual Virtual Circuit: A network service that provides connection-oriented service regardless of the underlying network structure. See also: Connection-Oriented. Virus: A program that replicates itself on computer systems by incorporating itself into other programs that are shared among computer systems.
Need help?
Do you have a question about the Retina and is the answer not in the manual?
Questions and answers