Firewall Wizards mailing list archives
Re: Security Audit and Priorities
From: Paul Robertson <proberts () patriot net>
Date: Sun, 13 Jul 2003 01:11:36 -0400 (EDT)
On Sat, 12 Jul 2003, Paul Ammann wrote:
Hi I will be starting a new job in the next few weeks. I went to Netcraft and typed in the company's URL and was amazed by what I saw: the version of Linux, the version of Apache, the version of OpenSSL... literally everything about their web servers. I have a lot of experience with firewalls, but I'll profess my ignorance in other security areas. So, here are my two questions: 1. What is the best way to block Netcraft from obtain all this information. Are there Open Source solutions that would be better than commercial solutions?
Quick answer: Don't put Web servers on the Internet. Obscurity won't help you much, keep your servers up to date, especially if they're facing the real world, turn off all the stuff that's not strictly necessary, and then you won't have to worry too much about banners and/or fingerprinting. You can block Netcraft's spidering, but then what about former employee's resumes, technical support questions, etc? Well-managed systems have very small windows of vulnerability, and the more you can turn off, the smaller that window becomes.
2. The company has acknowledged they are lacking in security. What is the best method for doing a security audit?
Figure out what's exposed, make sure it's not anything that shouldn't be, and make sure it's up to date, then ensure that the security policy matches the needs and wishes of the organization and make sure that it's being correctly implemented. Paul ----------------------------------------------------------------------------- Paul D. Robertson "My statements in this message are personal opinions proberts () patriot net which may have no basis whatsoever in fact." probertson () trusecure com Director of Risk Assessment TruSecure Corporation _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Security Audit and Priorities Paul Ammann (Jul 12)
- Re: Security Audit and Priorities Paul Robertson (Jul 12)
- Re: Security Audit and Priorities Yannick Van Osselaer (Jul 13)
- Re: Security Audit and Priorities R. DuFresne (Jul 13)
- Re: Security Audit and Priorities Frank Knobbe (Jul 14)
- Re: Security Audit and Priorities ark (Jul 14)
- Re: Security Audit and Priorities Frank Knobbe (Jul 14)
- Re: Security Audit and Priorities ark (Jul 14)
- <Possible follow-ups>
- Re: Security Audit and Priorities lists (Jul 13)
- Re: Security Audit and Priorities Paul Ammann (Jul 14)
- Security Audit and Priorities Paul Ammann (Jul 13)
- Re: Security Audit and Priorities R. DuFresne (Jul 13)
- RE: Security Audit and Priorities Bob Wanamaker - Avant Systems, Inc. (Jul 14)
(Thread continues...)