Educause Security Discussion mailing list archives

Vulnerability Scanning Problem


From: "Logan, Kimberly (loganks)" <LOGANKS () UCMAIL UC EDU>
Date: Mon, 11 Dec 2006 15:55:09 -0500

Hi Everyone,

 

Sorry if this has already been discussed, but....

 

The University of Cincinnati is using Rapid7's NeXpose as our OS level
vulnerability scanner.  Last week, we scanned 57 IP addresses and only
got returns on 14.  We believe the reason is that Microsoft SP2
installed the firewall with ICMP blocked.  We don't necessarily want to
have it unblocked for all devices, but we need to be able to scan our
devices on all subnets.  Has anyone experienced this problem and have
you been able to find any workarounds without opening things up?

 

Thanks,

 

Kim

 

Kim Logan

Information Security Officer

University of Cincinnati

(513)556-9070

kim.logan () uc edu

 


Current thread: