Educause Security Discussion mailing list archives

Checking for old web browsers and media plugins


From: Bob Bayn <bob.bayn () USU EDU>
Date: Wed, 18 Feb 2009 12:25:05 -0700

We've seen some drive-by compromises here lately.  We run weekly Nessus scans every week against all of our active IPs 
but those scans don't discover things like old web browsers or missing updates on various media plugins.  We are 
wondering if it would be productive to put some detection and reporting of obsolete browser or media plugins into some 
of our commonly used local web pages (access to our CMS or ERP) so we can encourage some updating before the drive-by 
events happen.  Is anybody doing this or considering it?


Bob Bayn     (435)797-2396     Security Team coordinator
"IT will NEVER ask for your password via email, honest!"
Office of Information Technology at Utah State University

Current thread: