mmm, most ppl over the net use scanners - Secuirty Scanner(PortScan,Audits,more) - there are lots of Windows Based Scanners - Like: X-Scan(Ports,CGI,CISCO,more,.. ) - he is fast but dont realy give full information about the bug - like how to fix,or how to use it for you own good(hacking the system\getting information\etc.), so what i Suggest is you'll start with a good scanner with a User-Friendly interface - itt called: Shadow Security Scanner - its a good scanner that Run port scan,find security holes,tell you how to use them,and how to fix - you can download it from here:
http://mirror1.safety-lab.com/SSS.exe .
Enjoy.