Educause Security Discussion mailing list archives

Re: Vulnerability Scanner Recommendations


From: mccalluq <mccalluq () LCC EDU>
Date: Thu, 15 Nov 2012 15:22:01 -0500

 <D73A0F3F722D0B41BBCAFE6915926FC7E5678B () RPITSEXMS2 its uncc edu>
 <2C17E27E26DEE641AEECF7583B3CAB1A1E7868A6 () evcspmbx2 ads northwestern edu>
X-Mailer: Oracle Connector for Outlook 10.1.3.0.11 110130 (12.0.6550)
X-Accept-Language: en-us, en
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary=-------245534d3245534d3


This is a multi-part message in MIME format

---------245534d3245534d3
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable

Tenable internal, Qualys external.

 =


 =


Thanks,

Quentin L. McCallum, CISSP

Information Security Analyst

Lansing Community College

517-267-5014

 =


From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY@LIS=
TSERV.EDUCAUSE.EDU] On Behalf Of Roger A Safian
Sent: Thursday, November 15, 2012 2:20 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Vulnerability Scanner Recommendations

 =


+1

 =


From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY@LIS=
TSERV.EDUCAUSE.EDU] On Behalf Of Sigmon, Aaron
Sent: Thursday, November 15, 2012 10:57 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Vulnerability Scanner Recommendations

 =


QualysGuard

 =


http://www.qualys.com/

 =


Thanks,

 =


Aaron Sigmon | Sr. Information Security Engineer

UNC Charlotte | Information and Technology Services

9201 University City Blvd. | Charlotte, NC 28223

bsigmo15 () uncc edu | http://www.uncc.edu

---------------------------------------------------------------------------=
----------

If you are not the intended recipient of this transmission or a person resp=
onsible for delivering it to the intended recipient, any disclosure, copyin=
g, distribution, or other use of any of the information in this transmissio=
n is strictly prohibited.  If you have received this transmission in error,=
 please notify me immediately by email or by telephone at 704.687.1289.  Th=
ank you. =


 =


From: Greg Schmalhofer <Greg.Schmalhofer () MILLERSVILLE EDU>
Reply-To: The EDUCAUSE Security Constituent Group Listserv <SECURITY@LISTSE=
RV.EDUCAUSE.EDU>
Date: Thursday, November 15, 2012 11:21 AM
To: "SECURITY () LISTSERV EDUCAUSE EDU" <SECURITY () LISTSERV EDUCAUSE EDU>
Subject: [SECURITY] Vulnerability Scanner Recommendations

 =


Educause security group,

 =


Can anyone recommend a particular vulnerability scanner software, product, =
appliance, or service that you are using at your campus? This is a need at =
our campus and I am trying to review the different options available for a =
small campus. Thanks for any help, insight, or feedback you can provide.

 =


Thanks,

Greg Schmalhofer

 =


Millersville University

Information Security Coordinator

Millersville, PA =



---------245534d3245534d3
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:x=3D"urn:schemas-microsoft-com:office:excel" xmlns:p=3D"urn:schemas-m=
icrosoft-com:office:powerpoint" xmlns:a=3D"urn:schemas-microsoft-com:office=
:access" xmlns:dt=3D"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" xmlns:s=3D"=
uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" xmlns:rs=3D"urn:schemas-microsof=
t-com:rowset" xmlns:z=3D"#RowsetSchema" xmlns:b=3D"urn:schemas-microsoft-co=
m:office:publisher" xmlns:ss=3D"urn:schemas-microsoft-com:office:spreadshee=
t" xmlns:c=3D"urn:schemas-microsoft-com:office:component:spreadsheet" xmlns=
:odc=3D"urn:schemas-microsoft-com:office:odc" xmlns:oa=3D"urn:schemas-micro=
soft-com:office:activation" xmlns:html=3D"http://www.w3.org/TR/REC-html40"; =
xmlns:q=3D"http://schemas.xmlsoap.org/soap/envelope/"; xmlns:rtc=3D"http://m=
icrosoft.com/officenet/conferencing" xmlns:D=3D"DAV:" xmlns:Repl=3D"http://=
schemas.microsoft.com/repl/" xmlns:mt=3D"http://schemas.microsoft.com/share=
point/soap/meetings/" xmlns:x2=3D"http://schemas.microsoft.com/office/excel=
/2003/xml" xmlns:ppda=3D"http://www.passport.com/NameSpace.xsd"; xmlns:ois=3D=
"http://schemas.microsoft.com/sharepoint/soap/ois/"; xmlns:dir=3D"http://sch=
emas.microsoft.com/sharepoint/soap/directory/" xmlns:ds=3D"http://www.w3.or=
g/2000/09/xmldsig#" xmlns:dsp=3D"http://schemas.microsoft.com/sharepoint/ds=
p" xmlns:udc=3D"http://schemas.microsoft.com/data/udc"; xmlns:xsd=3D"http://=
www.w3.org/2001/XMLSchema" xmlns:sub=3D"http://schemas.microsoft.com/sharep=
oint/soap/2002/1/alerts/" xmlns:ec=3D"http://www.w3.org/2001/04/xmlenc#"; xm=
lns:sp=3D"http://schemas.microsoft.com/sharepoint/"; xmlns:sps=3D"http://sch=
emas.microsoft.com/sharepoint/soap/" xmlns:xsi=3D"http://www.w3.org/2001/XM=
LSchema-instance" xmlns:udcs=3D"http://schemas.microsoft.com/data/udc/soap"=
 xmlns:udcxf=3D"http://schemas.microsoft.com/data/udc/xmlfile"; xmlns:udcp2p=
=3D"http://schemas.microsoft.com/data/udc/parttopart"; xmlns:wf=3D"http://sc=
hemas.microsoft.com/sharepoint/soap/workflow/" xmlns:dsss=3D"http://schemas=
.microsoft.com/office/2006/digsig-setup" xmlns:dssi=3D"http://schemas.micro=
soft.com/office/2006/digsig" xmlns:mdssi=3D"http://schemas.openxmlformats.o=
rg/package/2006/digital-signature" xmlns:mver=3D"http://schemas.openxmlform=
ats.org/markup-compatibility/2006" xmlns:m=3D"http://schemas.microsoft.com/=
office/2004/12/omml" xmlns:mrels=3D"http://schemas.openxmlformats.org/packa=
ge/2006/relationships" xmlns:spwp=3D"http://microsoft.com/sharepoint/webpar=
tpages" xmlns:ex12t=3D"http://schemas.microsoft.com/exchange/services/2006/=
types" xmlns:ex12m=3D"http://schemas.microsoft.com/exchange/services/2006/m=
essages" xmlns:pptsl=3D"http://schemas.microsoft.com/sharepoint/soap/SlideL=
ibrary/" xmlns:spsl=3D"http://microsoft.com/webservices/SharePointPortalSer=
ver/PublishedLinksService" xmlns:Z=3D"urn:schemas-microsoft-com:" xmlns:st=3D=
"&#1;" xmlns=3D"http://www.w3.org/TR/REC-html40";><head><META HTTP-EQUIV=3D"=
Content-Type" CONTENT=3D"text/html; charset=3Dus-ascii"><meta name=3DGenera=
tor content=3D"Microsoft Word 12 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p
        {mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Balloon Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
        {mso-style-name:"Balloon Text Char";
        mso-style-priority:99;
        mso-style-link:"Balloon Text";
        font-family:"Tahoma","sans-serif";}
span.apple-style-span
        {mso-style-name:apple-style-span;}
span.EmailStyle21
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.EmailStyle22
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.EmailStyle23
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue vli=
nk=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span style=3D'c=
olor:#1F497D'>Tenable internal, Qualys external.<o:p></o:p></span></p><p cl=
ass=3DMsoNormal><span style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><=
div><p class=3DMsoNormal style=3D'text-autospace:none'><span style=3D'color=
:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal style=3D'text-au=
tospace:none'><span style=3D'color:#1F497D'>Thanks,<o:p></o:p></span></p><p=
 class=3DMsoNormal style=3D'text-autospace:none'><span style=3D'color:#1F49=
7D'>Quentin L. McCallum, CISSP<o:p></o:p></span></p><p class=3DMsoNormal st=
yle=3D'text-autospace:none'><span style=3D'color:#1F497D'>Information Secur=
ity Analyst<o:p></o:p></span></p><p class=3DMsoNormal style=3D'text-autospa=
ce:none'><span style=3D'color:#1F497D'>Lansing Community College<o:p></o:p>=
</span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>517-267-5014<=
/span><span style=3D'color:#1F497D'><o:p></o:p></span></p></div><p class=3D=
MsoNormal><span style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><d=
iv style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0i=
n 0in'><p class=3DMsoNormal><b><span style=3D'font-size:10.0pt;font-family:=
"Tahoma","sans-serif"'>From:</span></b><span style=3D'font-size:10.0pt;font=
-family:"Tahoma","sans-serif"'> The EDUCAUSE Security Constituent Group Lis=
tserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] <b>On Behalf Of </b>Roger A S=
afian<br><b>Sent:</b> Thursday, November 15, 2012 2:20 PM<br><b>To:</b> SEC=
URITY () LISTSERV EDUCAUSE EDU<br><b>Subject:</b> Re: [SECURITY] Vulnerability=
 Scanner Recommendations<o:p></o:p></span></p></div></div><p class=3DMsoNor=
mal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal><span style=3D'color:#1F497D'=
+1<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'=
<o:p>&nbsp;</o:p></span></p><div style=3D'border:none;border-left:solid bl=
ue 1.5pt;padding:0in 0in 0in 4.0pt'><div><div style=3D'border:none;border-t=
op:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><=
span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</sp=
an></b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> =
The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY@LISTSERV.=
EDUCAUSE.EDU] <b>On Behalf Of </b>Sigmon, Aaron<br><b>Sent:</b> Thursday, N=
ovember 15, 2012 10:57 AM<br><b>To:</b> SECURITY () LISTSERV EDUCAUSE EDU<br><=
b>Subject:</b> Re: [SECURITY] Vulnerability Scanner Recommendations<o:p></o=
:p></span></p></div></div><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><d=
iv><div><p class=3DMsoNormal><span style=3D'font-size:10.5pt;color:black'>Q=
ualysGuard<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span style=
=3D'font-size:10.5pt;color:black'><o:p>&nbsp;</o:p></span></p></div><div><p=
 class=3DMsoNormal><span style=3D'font-size:10.5pt;color:black'><a href=3D"=
http://www.qualys.com";>http://www.qualys.com</a>/<o:p></o:p></span></p></di=
v><div><p class=3DMsoNormal><span style=3D'font-size:10.5pt;color:black'><o=
:p>&nbsp;</o:p></span></p></div><div><div><div><div><p class=3DMsoNormal><s=
pan style=3D'font-size:10.5pt;color:black'>Thanks,<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:10.5pt;color:black'>&nbsp;<o:p><=
/o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:10.5pt;color:=
black'>Aaron Sigmon | Sr. Information Security Engineer<o:p></o:p></span></=
p><p class=3DMsoNormal><span style=3D'font-size:10.5pt;color:black'>UNC Cha=
rlotte | Information and Technology Services<o:p></o:p></span></p><p class=3D=
MsoNormal><span style=3D'font-size:10.5pt;color:black'>9201 University City=
 Blvd. | Charlotte, NC 28223<o:p></o:p></span></p><p class=3DMsoNormal><spa=
n style=3D'font-size:10.5pt;color:black'><a href=3D"mailto:bsigmo15 () uncc ed=
u">bsigmo15 () uncc edu</a> | <a href=3D"http://www.uncc.edu";>http://www.uncc.=
edu</a><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:=
10.5pt;color:black'>-------------------------------------------------------=
------------------------------<o:p></o:p></span></p><p class=3DMsoNormal><s=
pan class=3Dapple-style-span><span style=3D'font-size:9.0pt;color:black'>If=
 you are not the intended recipient of this transmission or a person respon=
sible for delivering it to the intended recipient, any disclosure, copying,=
 distribution, or other use of any of the information in this transmission =
is strictly prohibited. &nbsp;If you have received this transmission in err=
or, please notify me immediately by email or by telephone at 704.687.1289. =
&nbsp;Thank you.&nbsp;</span></span><span style=3D'font-size:12.0pt;font-fa=
mily:"Times New Roman","serif";color:black'><o:p></o:p></span></p></div></d=
iv></div></div></div></div><div><p class=3DMsoNormal><span style=3D'font-si=
ze:10.5pt;color:black'><o:p>&nbsp;</o:p></span></p></div><div style=3D'bord=
er:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3D=
MsoNormal><b><span style=3D'color:black'>From: </span></b><span style=3D'co=
lor:black'>Greg Schmalhofer &lt;<a href=3D"mailto:Greg.Schmalhofer@MILLERSV=
ILLE.EDU">Greg.Schmalhofer () MILLERSVILLE EDU</a>&gt;<br><b>Reply-To: </b>The=
 EDUCAUSE Security Constituent Group Listserv &lt;<a href=3D"mailto:SECURIT=
Y () LISTSERV EDUCAUSE EDU">SECURITY () LISTSERV EDUCAUSE EDU</a>&gt;<br><b>Date:=
 </b>Thursday, November 15, 2012 11:21 AM<br><b>To: </b>&quot;<a href=3D"ma=
ilto:SECURITY () LISTSERV EDUCAUSE EDU">SECURITY () LISTSERV EDUCAUSE EDU</a>&quo=
t; &lt;<a href=3D"mailto:SECURITY () LISTSERV EDUCAUSE EDU">SECURITY@LISTSERV.=
EDUCAUSE.EDU</a>&gt;<br><b>Subject: </b>[SECURITY] Vulnerability Scanner Re=
commendations<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span st=
yle=3D'font-size:10.5pt;color:black'><o:p>&nbsp;</o:p></span></p></div><div=
<div><p class=3DMsoNormal><span style=3D'color:black'>Educause security gr=
oup,<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:black'>=
&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:black=
'>Can anyone recommend a particular vulnerability scanner software, product=
, appliance, or service that you are using at your campus? This is a need a=
t our campus and I am trying to review the different options available for =
a small campus. Thanks for any help, insight, or feedback you can provide.<=
o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:black'>&nbsp=
;<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:black'>Tha=
nks,<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:black'>=
Greg Schmalhofer<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'c=
olor:black'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D=
'color:black'>Millersville University<o:p></o:p></span></p><p class=3DMsoNo=
rmal><span style=3D'color:black'>Information Security Coordinator<o:p></o:p=
</span></p><p class=3DMsoNormal><span style=3D'color:black'>Millersville, =
PA <o:p></o:p></span></p></div></div></div></div></body></html>

---------245534d3245534d3--


Current thread: