Security Basics mailing list archives

Re: Anti-Virus on web facing servers??


From: "Joe Osborn" <joe () codejock com>
Date: Fri, 9 Jul 2004 14:51:05 -0500

Hey Dan,
They should absolutely be running Antivirus.  At the very least when an infected file is found, you should be 
quarantining the files.  You do not have to delete them.  Whether they are public facing or not, it should always be 
scanned.  That is just prudent.  Your situation is more obvious because they are accepting files via FTP.  If someone 
uploads a virus laden file and the directory has execute permissions or whatnot, you could have a real problem on your 
hands.

Joe Osborn
Codejock Software


---------- Original Message ----------------------------------
From: "Dan Tesch" <dan.tesch () comcast net>
Reply-To: "Dan Tesch" <dan.tesch () comcast net>
Date:  Fri, 9 Jul 2004 09:32:50 -0500

Hello, I just started with a company that has three
web facing W2K servers running IIS & SQL.

My question; they are patched and behind a firewall
but have no Anti-Virus running - can I get some feedback
on whether these boxes should be running AV??

They are on a network at a COLO just by themselves
ie: no desktops but get FTP uploads regularly for
content.

Thanks

---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


 




________________________________________________________________
Sent via the WebMail system at mail.codejock.com


 
                   

---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: