Educause Security Discussion mailing list archives

Re: Distributed Vulnerability Scanning


From: Warren Raquel <wraquel () UIUC EDU>
Date: Tue, 23 Aug 2005 13:26:00 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Connie,
~  We are currently in the process of releasing a scanning tool to our
campus using Purdue's Vulnerability Scanning Cluster tool. It was rather
trivial to modify it for use within our environment. The cluster can
easily be distributed among a single system to however many you want to
distribute the scans. It uses Nessus to perform the scans while the
frontend uses a mix of php and either perl or python for the back end to
run scheduled scans. With this our admins have the ability to do quick
one-time scans or recurring scans as needed. If you would like more info
feel free to contact me off-list.

- -Warren

Sadler, Connie wrote:
|
|
| Does anyone use a commercial scanner ? something like Tenable? The
| software would allow us to set up accounts and delegate rights for some
| of our system administrators to run their own scans. The management
| console would allow us to review results from all of the scans. Does
| anyone use a commercial appliance and if not, does anyone have a
| home-grown Nessus interface that makes using Nessus in a distributed
| environment easier?
|
|
|
| Thanks?
|
|
|
| Connie J. Sadler, CM, CISSP, CISM, GIAC GSLC
| Director, IT Security, Brown University
| Box 1885, Providence, RI 02912
| Connie_Sadler () Brown edu
| Office: 401-863-7266
| PGP Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x91E38EFB
| <blocked::http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x91E38EFB>
| PGP Fingerprint: DA5F ED84 06D7 1635 4BC7  560D 9A07 80BA 91E3 8EFB
|

- --
Warren Raquel
Security Officer, Security Services and Information Privacy
Campus Information Technologies and Educational Services (CITES)
University of Illinois Urbana-Champaign
PGP/GPG: F88E 960B 6193 A3ED 0BB2  45C7 7DF9 57DB 6DCF 34C1

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (MingW32)

iD8DBQFDC2o4fflX223PNMERAhl0AKCUH8nwEq0Cf1BQt68S/i/fJmBLsgCfSq1o
32idYI+bGcUuREEbdKQG/D4=
=vb8g
-----END PGP SIGNATURE-----

Current thread: