Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

vulnerability assessment next step

Status
Not open for further replies.

nsglists

IS-IT--Management
Jul 20, 2006
57
0
0
US
I am sorry, this might be a dumb question. I have used a few VA tools like nessus, retina, etc for a couple of weeks now. They are great tools which provide great (sometimes very lengthy) info on open ports, running services, missing patches. Some other tools might provide more info, tips on dealing with issues, etc.
My question is how to deal with the report it generates. Nessus, for example generates a very lengthy report on each machine, possible threats and some remedies. It would say that TCP port 1027 is open on a server. After investigating it is found that it was popularly used for the ICKiller trojan. Now, I know for sure that there no Trojan on that server. So, how do I deal with this.??
In general, my question would be how do I deal with VA scan reports in general?? I can apply patches, close ports, stop services, after making sure that it is not needed.
But sometimes I am not even sure if that port is needed like TCP 1027. What do I do then??
Please advice.
Links/articles/howtos would be great as well.
Thanks.
 
First off Patches. All good and that but if its an internal machine with custom business critical apps on it why put an outlook express patch on it?

You have a public facing web server and a critical IIS flaw is found and patch is released should you apply it?

Look at each patch & server separately. If its safe I always install the patch but I know others prefer to wait and see with their critical business servers in case the patch changes functionality / braks something.

Secondly Ports.
If you want to know what a specific port number is then;
If you want to know what that actually means in english:
If you have specific questions on a port
:)
Also ports can have multiple uses and you can change the port an application uses ie http from 80 to 8080 or 1027 for that matter.

Services.
You will need to research this carefully and know what your doing. If you go into services and look at the properties you will see its dependencies. For MS services that your unsure of;
For any others you would need to check with the publisher.

Generaly:
Apply all patches ASAP
Stop&Disable All Unrequired Services
Block All unecessary ports

Most importantly of all read the report and use your judgement, thats why we get the big £££££ (ha ha ha ha ha ha ha ha ha [laughtears][laughtears][laughtears])

Iain
 
Thanks a bunch for both the specific pointers and the general advice. Abs pearls of wisdom... I thought.

Btw, Re, "thats why we get the big £££££"
--> not quite there yet. I should say that I am well on my way though!!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top